Lead Application Security Engineer
You must be able to work from Poland — the posting restricts this role to applicants there.
RemoFirst is changing how the world hires.
We're an affordable, AI-native Employer of Record that combines intelligent agents with a team of human experts to support global hiring, payroll, and HR, while ensuring compliance in 185+ countries. We partner with some of the world's most innovative startups and Fortune 500 companies to support all their global hiring needs.
✨ Since launching in 2021, we've:
- Grown to a strong team of 200+ people across 40+ countries
- Raised $39M+, backed by Octopus Ventures, QED Investors, Mouro Capital, and Counterpart Ventures
- Trusted by startups, fast-growing companies, and Fortune 500 industry leaders. A few amazing customers include HubSpot, PandaDoc, Mastercard, Microsoft
- Named a Leader in the NelsonHall NEAT Evaluation for Global EOR Services
- Recognized on Inc.'s Best Workplaces list and Fast Company's Best Workplaces for Innovators
We're hyper-focused on delivering a world-class platform and unparalleled service — and we're just getting started. If you want to help us drive that change, we'd love for you to apply!
What you'll own
Offensive security
- Run regular internal penetration tests and vulnerability scans against our Python/Django, FastAPI and Java/Spring Boot services.
- Coordinate our independent third-party pentests: scope them, judge the findings, and hold people to remediation instead of filing the report.
- Find the multi-tenancy and authorisation bugs that matter in a platform where one customer's data must never surface in another's account.
Secure SDLC
- Work directly with engineers on code review and threat modelling, and own the ongoing life of our internal security library.
- Own our SAST/DAST tooling and dependency posture — outdated libraries, license misuse, and the judgement to tell a finding from a real risk.
- Secure the layers our services run on: PostgreSQL and MongoDB persistence, Kafka and RabbitMQ streams.
- Build paved roads. A secure SDLC engineers route around is a failed one, so the goal is guardrails they reach for rather than a gate they resent.
Cloud security
- Enforce least privilege across our AWS ecosystem: IAM policies, Service Control Policies, and the EKS, RDS and S3 estate underneath.
- Harden our container and Kubernetes workloads, and make secrets handling boring.
- Instrument the above — you should find out about a misconfiguration from an alert, not from a customer.
Customer-facing identity
- Own the architecture and security of our Auth0 implementation for client-facing applications.
- Extend our internal authentication service to support SCIM provisioning, and stand up OIDC federation with our enterprise clients' IdPs — increasingly what unblocks large deals.
- Own API security: authorisation logic, token handling, and the failure modes that show up in multi-tenant systems.
AI security
- Define the guardrails for our AI initiatives — what data can reach an LLM prompt, what can't, and how we enforce it.
- Secure our model pipeline. This is young for us, so you'd be shaping it rather than inheriting it.
Get remote engineering | full-time jobs like this by email
10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.
Similar for you
Get 10 hand-picked remote jobs like this one in your inbox every morning. One email a day, matched to what you browse. No spam, one-click unsubscribe.
No thanks — continue to the application ↗