Remofirst

Remofirst

Remofirst: Simplifying global HR solutions with streamlined payroll, compliance, and remote hiring in 180+ countries.

Professional Services
11-50
Founded 2021

Description

  • Own the architecture and security of the customer-facing Auth0 implementation, including SCIM provisioning and OIDC federation with enterprise identity providers.
  • Manage and automate the internal Okta environment, including SSO, lifecycle management, hardware-based MFA, and complex RBAC.
  • Enforce least privilege across the AWS environment by managing IAM policies and service control policies.
  • Conduct internal pentests and vulnerability scans against Python/Django and Java/Spring Boot services and coordinate with third-party pen testers.
  • Review application code and help engineers build secure services, databases, and message streams across Postgres and Kafka.
  • Own SAST and DAST processes, including detection of license misuse and outdated libraries.
  • Define guardrails for AI initiatives, including prompt data privacy and model pipeline security.
  • Lead SOC 2 Type II and ISO 27001 efforts, maintain the risk register, and support security questionnaires from customers.
  • Use compliance automation tools and manage the Trust Center in Thoropass to keep the organization audit-ready.
  • Help draft and implement practical security policies covering data residency, logging, audit trails, and non-repudiation.

Requirements

  • 5+ years of experience in security engineering.
  • Experience with Python/Java environments, including Django, FastAPI, and Spring Boot.
  • Experience with Kafka, RabbitMQ, PostgreSQL, and some MongoDB.
  • Strong knowledge of AWS infrastructure, including EKS, RDS, IAM, and S3.
  • Familiarity with IAM tools such as Okta and/or Auth0.
  • Understanding of SAML, OIDC, and API-based security.
  • Familiarity with the SOC 2 and ISO 27001 audit cycle.
  • Comfortable working with internal and external Risk & Compliance teams.
  • Ability to explain ISO 27001 requirements to software engineers in practical terms.
  • Bonus: awareness of OWASP Top 10 for LLMs, including prompt injection and data leakage risks.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Security Engineer, Bug Bounty

Mozilla 251-1K Internet Software & Services

Mozilla is hiring a Security Engineer to own its web bug bounty program and help protect its products, users, and incident response efforts.

AWS Azure GCP Go Heroku JavaScript Python Rust
3 hours, 51 minutes ago

Senior Security Engineer, Bug Bounty

Mozilla 251-1K Internet Software & Services

Mozilla is hiring a Security Engineer to run and improve its web bug bounty program while helping protect products, respond to security incidents, and strengthen privacy and safety across the company’s web ecosystem.

AWS Azure GCP Go Heroku JavaScript Python Rust
3 hours, 51 minutes ago

Threat Response & Remediation Engineer

Zscaler 1K-5K Internet Software & Services

Zscaler is hiring a remote Threat Response & Remediation Engineer to investigate, contain, and fully remediate customer security incidents across endpoint, network, and identity environments.

CrowdStrike Cybersecurity Linux macOS
3 hours, 51 minutes ago

Senior Security Engineer, Bug Bounty

Mozilla 251-1K Internet Software & Services

Mozilla is hiring a Security Engineer to manage its web bug bounty program and help protect user privacy and safety across the company’s products and incident response work.

AWS Azure GCP Go Heroku JavaScript Python Rust
4 hours, 6 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers