Remofirst

Remofirst

Remofirst: Simplifying global HR solutions with streamlined payroll, compliance, and remote hiring in 180+ countries.

Professional Services
11-50
Founded 2021

Description

  • Run internal penetration tests and vulnerability scans across Python/Django, FastAPI, and Java/Spring Boot services.
  • Coordinate third-party penetration tests, evaluate findings, and drive remediation.
  • Identify and address multi-tenancy, authorization, and API security vulnerabilities.
  • Partner with engineers on secure code reviews, threat modeling, and security library maintenance.
  • Own SAST, DAST, dependency, and license-management tooling and processes.
  • Secure PostgreSQL, MongoDB, Kafka, RabbitMQ, container, and Kubernetes environments.
  • Enforce least privilege across AWS IAM, SCPs, EKS, RDS, and S3, including secrets management and monitoring.
  • Own the security architecture of Auth0 and extend authentication services with SCIM and OIDC federation.
  • Define security guardrails for LLM data flows and model pipelines.
  • Build practical security automation and secure SDLC workflows that engineers adopt.

Requirements

  • Hands-on application security experience in an engineering organization, including code review, threat modeling, and offensive testing.
  • Ability to read and assess Python and Java code, with familiarity with Django, FastAPI, or Spring Boot.
  • Strong AWS security experience with IAM, SCPs, EKS, RDS, and S3.
  • Experience securing customer-facing identity systems such as Auth0, plus knowledge of SAML, OIDC, and API security.
  • Ability to communicate security decisions in terms of business risk and collaborate effectively with engineers.
  • Experience building security tooling and automation using REST APIs, webhooks, and Terraform or similar tools (preferred).
  • Experience with AI/LLM security, including prompt risks, data flows, or model pipeline security (preferred).
  • Experience in fintech, payroll, global employment, or another domain involving sensitive personal and financial data (preferred).
  • Experience working in a globally distributed, remote-first environment with data residency and jurisdictional constraints (preferred).
  • English proficiency and strong communication, collaboration, autonomy, empathy, and prioritization skills.

Benefits

  • 100% remote, remote-first work with no office requirement.
  • PTO regulated by local statutory requirements.
  • Up to 90 days of paid parental leave, with additional local protections.
  • Monthly wellbeing stipend for fitness, mental health, or downtime.
  • Startup environment with opportunities to influence decisions and grow quickly.
  • Respectful, inclusive culture that values autonomy, collaboration, and learning from failure.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Manager, Product Security

Tines 51-250 Construction & Engineering

Tines is seeking a Senior Manager, Product Security to lead and scale its product security program for cloud-native, AI-forward products while partnering with engineering and product leaders to manage risk and support growth.

AWS CI/CD DevSecOps Docker Kubernetes Penetration Testing Ruby Rust TypeScript
1 day, 11 hours ago

Application Security Engineer

Glean 11-50 Internet Software & Services

Glean is hiring a remote Application Security Engineer to lead vulnerability management and strengthen software supply-chain security across its Work AI platform.

AWS Burp Suite CI/CD Cybersecurity GCP Kubernetes Microservices
1 day, 11 hours ago

Application Security Engineer II

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring an Application Security Engineer to triage and validate vulnerability submissions for major clients, communicate with researchers and customers, and support incident response across diverse security programs.

Burp Suite Nmap
2 days, 11 hours ago

Off-Cycle Fall 2026 Cybersecurity Internship

Galaxy 251-1K Capital Markets

Galaxy Digital is seeking a remote Cybersecurity Intern for its Product Security team to improve secure engineering standards and develop resources that help software and production engineers apply them effectively.

C++ Cybersecurity Python Rust
4 days, 12 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers