Lead Application Security Engineer
Tech Stack / Keywords
Firma i stanowisko
RemoFirst is an affordable, AI-native Employer of Record that combines intelligent agents with a team of human experts to support global hiring, payroll, and HR, while ensuring compliance in 185+ countries. The company has a strong team of over 200 people across more than 40 countries and is trusted by startups, fast-growing companies, and Fortune 500 industry leaders including HubSpot, PandaDoc, Mastercard, and Microsoft. Established in 2021, RemoFirst has raised over $39M in funding and has been recognized as a leader in global Employer of Record services as well as being featured on Inc.'s Best Workplaces list and Fast Company's Best Workplaces for Innovators.
Wymagania
- Hands-on experience in application security including code review, threat modelling, and offensive testing.
- Familiarity with the tech stack: Python, Java, Django, FastAPI, Spring Boot, Kafka, RabbitMQ, PostgreSQL, and MongoDB.
- Strong AWS security knowledge: IAM, SCPs, EKS, RDS, S3 and principles of least privilege.
- Experience securing customer-facing identity solutions such as Auth0, with understanding of SAML, OIDC, and API security.
- Ability to explain security decisions in terms of risk and business need and to say no tactfully.
Nice to have:
- Ability to write tooling and automation code beyond scripting; comfortable with REST APIs, webhooks, and Terraform or similar tools.
- Experience with AI/LLM security including prompt/data-flow risks and model pipeline security.
- Exposure to fintech, payroll, or domains with sensitive personal and financial data.
- Experience in globally distributed, remote-first companies respecting data residency and jurisdiction constraints.
- Familiarity with Employer of Record or global employment spaces.
Obowiązki
Offensive security:
- Run regular internal penetration tests and vulnerability scans against our Python/Django, FastAPI and Java/Spring Boot services.
- Coordinate independent third-party pentests: scope them, judge findings, and ensure remediation.
- Identify multi-tenancy and authorization bugs to prevent data leaks between customer accounts.
Secure SDLC:
- Collaborate with engineers on code review and threat modelling.
- Own the internal security library.
- Manage SAST/DAST tooling and dependency posture including license compliance.
- Secure persistence layers such as PostgreSQL and MongoDB, and message streams like Kafka and RabbitMQ.
- Build secure development guardrails that engineers prefer to use.
Cloud security:
- Enforce least privilege in AWS via IAM policies, Service Control Policies, and services like EKS, RDS, and S3.
- Harden container and Kubernetes workloads, and improve secrets management.
- Implement alerting for security misconfigurations.
Customer-facing identity:
- Own architecture and security of Auth0 implementation.
- Extend internal authentication to support SCIM provisioning and OIDC federation.
- Manage API security focusing on authorization and token handling.
AI security:
- Define security guardrails for AI initiatives involving LLM prompts.
- Secure the AI model pipeline and help shape this evolving area.
Benefity
- 100% remote work with PTO regulated by local statutory requirements.
- Up to 90 days paid parental leave for new parents with local protections.
- Monthly wellbeing stipend for fitness, mental health, or downtime.
- Early-stage startup environment allowing influence on decisions and rapid growth.
- Opportunity to build and scale a world-class security team.
- Work with market-leading clients including Microsoft and Mastercard.
- Supportive culture valuing respect, kindness, and diversity.
RemoFirst
5 aktywnych ofert