
RemoFirst is changing how the world hires. We're an affordable, AI-native Employer of Record that combines intelligent agents with a team of human experts to support global hiring, payroll, and HR, while ensuring compliance in 185+ countries.
What you'll own
Offensive security
- Run regular internal penetration tests and vulnerability scans against our Python/Django, FastAPI and Java/Spring Boot services.
- Coordinate our independent third-party pentests: scope them, judge the findings, and hold people to remediation instead of filing the report.
- Find the multi-tenancy and authorisation bugs that matter in a platform where one customer's data must never surface in another's account.
Secure SDLC
- Work directly with engineers on code review and threat modelling, and own the ongoing life of our internal security library.
- Own our SAST/DAST tooling and dependency posture — outdated libraries, license misuse, and the judgement to tell a finding from a real risk.
- Secure the layers our services run on: PostgreSQL and MongoDB persistence, Kafka and RabbitMQ streams.
- Build paved roads. A secure SDLC engineers route around is a failed one, so the goal is guardrails they reach for rather than a gate they resent.
Cloud security
- Enforce least privilege across our AWS ecosystem: IAM policies, Service Control Policies, and the EKS, RDS and S3 estate underneath.
- Harden our container and Kubernetes workloads, and make secrets handling boring.
- Instrument the above — you should find out about a misconfiguration from an alert, not from a customer.
Customer-facing identity
- Own the architecture and security of our Auth0 implementation for client-facing applications.
- Extend our internal authentication service to support SCIM provisioning, and stand up OIDC federation with our enterprise clients' IdPs — increasingly what unblocks large deals.
- Own API security: authorisation logic, token handling, and the failure modes that show up in multi-tenant systems.
AI security
- Define the guardrails for our AI initiatives — what data can reach an LLM prompt, what can't, and how we enforce it.
- Secure our model pipeline. This is young for us, so you'd be shaping it rather than inheriting it.
Requirements
Must have
- Deep hands-on application security in a real engineering organisation: code review, threat modelling, and offensive testing against services you were also responsible for defending.
- Familiarity with our stack. Python and Java are at the heart of our services (Django, FastAPI, Spring Boot), with Kafka and RabbitMQ between them and PostgreSQL plus some MongoDB underneath.
- Strong AWS security — IAM, SCPs, EKS, RDS, S3 — and a view on what least privilege looks like when it has to survive contact with a shipping team.
- Practical experience securing customer-facing identity: Auth0 or equivalent, plus a working understanding of SAML, OIDC and API-based security.
- Ability to explain security decisions in terms of risk and business need.
Nice to have
- Experience writing code for tooling and automation (REST APIs, webhooks, Terraform).
- AI/LLM security experience.
- Exposure to fintech, payroll, or money movement domains.
- Experience in a globally distributed, remote-first company.
- Familiarity with the EOR or global employment space.
Timezone overlap
UTC+0–+3
Culture
Async-friendly
Benefits
Open to
Europe
Sign in to track applications and earn points.