Lead Security Engineer

RemoFirst
RemoFirst

Requirements

Technical Requirements:

  • Familiarity with our core tech stack: Python/Java with Django, FastAPI & SpringBoot is at the heart of our services. We are using Kafka & RabbitMQ for interservice communications and PostgreSQL with some MongoDB on our persistence layer
  • Strong knowledge of Cloud Infrastructure: We use AWS with EKS, RDS as well the traditional IAM, S3, etc.
  • Internal & User-facing IAM: Comfortable with IAM - some experience with Okta and/or Auth0. Good understanding of protocols like SAML, OIDC, understanding of API-based security
  • Compliance: Familiarity with the SOC2 and ISO27001 audit cycle, comfortable with working with Risk & Compliance teams, both internal and external

Original Advert

RemoFirst is transforming the way businesses hire and manage global teams. Our mission is to enable Freedom of Work by providing an all-in-one global HR platform that simplifies hiring, compliance, payroll, and benefits management. We partner with some of the world's most innovative companies, including Fortune 500 businesses and leading startups.
We are a small but strong team of 200+ people (and growing) hyper-focused on delivering a world-class platform and unparalleled service with our industry-leading partnerships.

Core Responsibilities:

  • 1. Identity & Access Management (The Core)
  • Customer Identity: Own the architecture and security of our Auth0 implementation for client-facing applications. You will be fine-tuning our internal authentication service to support SCIM provisioning and help set up the OIDC federation with our enterprise client's IdPs.
  • Internal Identity: Manage and automate our Okta environment, ensuring seamless SSO, lifecycle management (onboarding/offboarding), and hardware-based MFA. Expect a fairly complex internal RBAC and the need to actually speak with the other functions within the organization to understand their ways of working and translate them into security controls
  • Cloud Identity: Enforce "Least Privilege" across our AWS ecosystem, managing complex AWS IAM policies and Service Control Policies (SCPs).
  • 2. Security Engineering & Pentesting
  • Offensive Security: Conduct regular internal pentests and vulnerability scans against our Python/Django and Java/Spring Boot services as well as coordinate with 3LOD pen testers
  • Secure SDLC: Work alongside devs to review code (e.g. implementation of the security library you've built), secure our Postgres databases, help engineers with thread modelling and harden our Kafka message streams. You will be the owner of our SAST/DAST and detect license misuse, outdated libraries, and help shape a non-invasive secure SDLC that developers love by building paved roads
  • AI Security: Define the guardrails for our AI initiatives, ensuring data privacy in LLM prompts and securing our model pipeline.
  • 3. Governance, Risk, and Compliance (GRC)
  • The Audit Lead: Take the wheel for our SOC 2 Type II and ISO 27001 certifications. You will be a key person in maintaining our internal risk register as well as helping our Front-line teams with inbound security questionnaires from large clients.
  • Automation: Utilize compliance automation tools to ensure we stay "audit-ready" every single day, not just once a year. You will own our "Trust Center" in Thoropass (our compliance platform)
  • Policy as Code: Help draft and implement pragmatic security policies that reflect how a modern startup actually works. We are talking about data residency, logging, audit trails, dealing with non-repudiation, etc.

Who You Are:

  • The Builder: You have 5+ years of experience in security engineering. You prefer an IDE to a spreadsheet.
  • The Auditor-Translator: You can explain complex ISO 27001 requirements to a software engineer in a way that makes sense to them.
  • The Pragmatist: You understand that "No" is not always the answer. You find ways to enable the business to move fast, safely.
  • Bonus points - An AI Enthusiast: You are keeping up with the OWASP Top 10 for LLMs and understand the risks of prompt injection and data leakage.

AI Engineer

Egypt / Ukraine / Poland / Portugal / Spain / Slovakia / Slovenia / UAE / Romania / South Africa / Tunisia / North Macedonia / Bulgaria
3d ago

Technical Recruiter

Spain / Romania / Hungary / Ukraine / South Africa / Portugal / United States / United Kingdom / Poland / UAE
1w ago

Account Executive

Spain / Portugal / Hungary / Poland / Romania / South Africa / Ukraine / North Macedonia / United Kingdom
2w ago

Finance Operations Specialist

Brazil / Colombia / Mexico / Argentina / Bolivia / Chile / Guatemala / Paraguay / Latin America / Uruguay / Peru / Dominican Republic
3w ago

Staff Backend Engineer

Bulgaria / Lithuania / Croatia / Serbia / Hungary / Romania / Slovakia / Slovenia / Estonia
1mo ago

Expansion Manager – Australia & New Zealand

India / Australia / New Zealand
1mo ago

Business Development Manager (Outbound & GTM Systems)

Spain / Portugal / Germany / Hungary / Poland / Romania / United Kingdom / United States
1mo ago

Talent Sourcer (6 months contract)

Spain / Romania / Hungary / Ukraine / South Africa / Portugal / Egypt / Estonia / North Macedonia / Serbia / Tunisia
1mo ago

Finance Accounts Receivable Manager

Poland / Colombia / Brazil / South Africa / Ukraine / Kazakhstan / Mexico / Romania / Argentina / Egypt
1mo ago

Hiring Success Manager - EMEA

Poland / Albania / Hungary / Greece / North Macedonia / Romania / Spain / Ukraine / Portugal / Egypt
2mo ago

Hiring Success Manager - AMER

Brazil / Argentina / Colombia / Peru / Mexico / Chile / Guatemala / Paraguay / Uruguay
2mo ago

Senior/Lead Back End Engineer

Egypt / Kazakhstan / Uzbekistan / Azerbaijan / Palestine / Armenia / Portugal
2mo ago

Software Engineer

Madrid, Spain
New

Software Development Engineer

Barcelona, Spain
New

AIT Engineer

Ciudad Real, Spain
New

Senior Digital Hardware Engineer

Madrid, Spain
New

Senior Space Systems Engineer

Málaga, Spain
New

Software Engineer - Python

Barcelona, Spain
New

Senior Systems Engineer

Barcelona, Spain
New

GNSS System engineer

Barcelona, Spain
New

MBSE Engineer

Madrid, Spain
New

Telecommunications Engineer - Waveform & Data Link Design

Madrid, Spain
New

Senior System Engineer

Madrid, Spain
New

RAMS Engineer - Space Systems - Torrejón de Ardoz (Hybrid)

Madrid, Spain
New

Application managed by RemoFirst