Remofirst logo
Remofirst·

Lead Application Security Engineer - Remofirst

RemoFirst is changing how the world hires. We're an affordable, AI-native Employer of Record that combines intelligent agents with a team of human experts to support global hiring, payroll, and HR, while ensuring compliance in 185+ countries.

What you'll own

Offensive security

  • Run regular internal penetration tests and vulnerability scans against our Python/Django, FastAPI and Java/Spring Boot services.
  • Coordinate our independent third-party pentests: scope them, judge the findings, and hold people to remediation instead of filing the report.
  • Find the multi-tenancy and authorisation bugs that matter in a platform where one customer's data must never surface in another's account.

Secure SDLC

  • Work directly with engineers on code review and threat modelling, and own the ongoing life of our internal security library.
  • Own our SAST/DAST tooling and dependency posture — outdated libraries, license misuse, and the judgement to tell a finding from a real risk.
  • Secure the layers our services run on: PostgreSQL and MongoDB persistence, Kafka and RabbitMQ streams.
  • Build paved roads. A secure SDLC engineers route around is a failed one, so the goal is guardrails they reach for rather than a gate they resent.

Cloud security

  • Enforce least privilege across our AWS ecosystem: IAM policies, Service Control Policies, and the EKS, RDS and S3 estate underneath.
  • Harden our container and Kubernetes workloads, and make secrets handling boring.
  • Instrument the above — you should find out about a misconfiguration from an alert, not from a customer.

Customer-facing identity

  • Own the architecture and security of our Auth0 implementation for client-facing applications.
  • Extend our internal authentication service to support SCIM provisioning, and stand up OIDC federation with our enterprise clients' IdPs — increasingly what unblocks large deals.
  • Own API security: authorisation logic, token handling, and the failure modes that show up in multi-tenant systems.

AI security

  • Define the guardrails for our AI initiatives — what data can reach an LLM prompt, what can't, and how we enforce it.
  • Secure our model pipeline. This is young for us, so you'd be shaping it rather than inheriting it.

Requirements

Must have

  • Deep hands-on application security in a real engineering organisation: code review, threat modelling, and offensive testing against services you were also responsible for defending.
  • Familiarity with our stack. Python and Java are at the heart of our services (Django, FastAPI, Spring Boot), with Kafka and RabbitMQ between them and PostgreSQL plus some MongoDB underneath.
  • Strong AWS security — IAM, SCPs, EKS, RDS, S3 — and a view on what least privilege looks like when it has to survive contact with a shipping team.
  • Practical experience securing customer-facing identity: Auth0 or equivalent, plus a working understanding of SAML, OIDC and API-based security.
  • Ability to explain security decisions in terms of risk and business need.

Nice to have

  • Experience writing code for tooling and automation (REST APIs, webhooks, Terraform).
  • AI/LLM security experience.
  • Exposure to fintech, payroll, or money movement domains.
  • Experience in a globally distributed, remote-first company.
  • Familiarity with the EOR or global employment space.

Timezone overlap

UTC+0–+3

Culture

Async-friendly

Open to

Europe

Sign in to track applications and earn points.

More roles at Remofirst

Similar remote roles