Careers

Senior engineers, security-first work

Working with Granthinge

Granthinge is a small practice, and we intend to keep it one. When client work outgrows the bench, we bring in senior, US-based engineers on contract: people who have built API platforms, identity integrations, or security tooling and want to work at the sharp end of MCP.

The work is concrete. Designing tool surfaces, wiring OAuth 2.1 flows to enterprise identity providers, enforcing per-tenant scoping, writing audit pipelines and evidence packs, and attacking servers before a customer's security team does. You would work directly with the named lead on an engagement, in the client's repositories, under our review standards, with your own work demoed weekly.

We care about how you reason about identity and failure modes, not about certifications or a years-per-technology checklist. If you have shipped production authorization code and can explain a threat model in plain sentences, we want to hear from you.

Senior only

Engagements are led and staffed by senior engineers. There is no pyramid, and nobody learns the basics on a client's clock.

US based, remote first

Contract work across US time zones, remote by default, with travel only when a kickoff or a customer security meeting calls for it.

Real security work

Authorization, scoping, audit, and adversarial testing on production systems, not compliance paperwork.

Your name on it

You work directly with the client, demo your own work every week, and can stand behind it in their security review.

Senior MCP Engineer — Contract, Remote (US)

Remote

Design and build MCP servers and the authorization around them: OAuth 2.1, identity provider integration, per-user and per-tenant scoping, structured audit. Production TypeScript or Python, and comfort explaining design decisions to a client's security team. This is an open network role: engagements are hourly and project-based, and we draw on the network as client work requires.

Apply Online ▸

Senior Identity & Security Engineer — Contract, Remote (US)

Remote

OAuth 2.1, token exchange, and enterprise identity (Okta, Entra, Auth0, Cognito) applied to agent access: threat models, adversarial testing, evidence packs, and SIEM-ready audit. Suited to engineers who have run, or sat on the receiving end of, vendor security reviews. Open network role, contract, as engagements call for it.

Apply Online ▸

Join The Team. Apply Now.

Introduce yourself: a short note, a link to work we can read (code, writing, or a talk), and the identity or MCP work you have done. We read every application ourselves and reply to the ones that fit. No recruiters.