Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Lead Application Security Engineer

Remofirst
CompanyRemofirst
CategoryEngineering
LocationRomania
RemoteRemote
EmploymentFull-time
LevelLead
SalaryNot stated by the employer
Posted7 Aug 2026
Last verified9 Aug 2026
SourceEmployer ATS (workable)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
RemoFirst is changing how the world hires. We're an affordable, AI-native Employer of Record that combines intelligent agents with a team of human experts to support global hiring, payroll, and HR, while ensuring compliance in 185+ countries. We partner with some of the world's most innovative startups and Fortune 500 companies to support all their global hiring needs. ✨ Since launching in 2021, we've: Grown to a strong team of 200+ people across 40+ countries Raised $39M+, backed by Octopus Ventures, QED Investors, Mouro Capital, and Counterpart Ventures  Trusted by startups, fast-growing companies, and Fortune 500 industry leaders. A few amazing customers include HubSpot, PandaDoc, Mastercard, Microsoft Named a Leader in the NelsonHall NEAT Evaluation for Global EOR Services Recognized on Inc.'s Best Workplaces list and Fast Company's Best Workplaces for Innovators We're hyper-focused on delivering a world-class platform and unparalleled service — and we're just getting started. If you want to help us drive that change, we'd love for you to apply! What you'll own Offensive security Run regular internal penetration tests and vulnerability scans against our Python/Django, FastAPI and Java/Spring Boot services. Coordinate our independent third-party pentests: scope them, judge the findings, and hold people to remediation instead of filing the report. Find the multi-tenancy and authorisation bugs that matter in a platform where one customer's data must never surface in another's account. Secure SDLC Work directly with engineers on code review and threat modelling, and own the ongoing life of our internal security library. Own our SAST/DAST tooling and dependency posture — outdated libraries, license misuse, and the judgement to tell a finding from a real risk. Secure the layers our services run on: PostgreSQL and MongoDB persistence, Kafka and RabbitMQ streams. Build paved roads. A secure SDLC engineers route around is a failed one, so the goal is guardrails they reach for rather than a gate they resent. Cloud security Enforce least privilege across our AWS ecosystem: IAM policies, Service Control Policies, and the EKS, RDS and S3 estate underneath. Harden our container and Kubernetes workloads, and make secrets handling boring. Instrument the above — you should find out about a misconfiguration from an alert, not from a customer. Customer-facing identity Own the architecture and security of our Auth0 implementation for client-facing applications. Extend our internal authentication service to support SCIM provisioning, and stand up OIDC federation with our enterprise clients' IdPs — increasingly what unblocks large deals. Own API security: authorisation logic, token handling, and the failure modes that show up in multi-tenant systems. AI security Define the guardrails for our AI initiatives — what data can reach an LLM prompt, what can't, and how we enforce it. Secure our model pipeline. This is young for us, so you'd be shaping it rather than inheriting it.