Padmi
RemoFirst logo
RemoFirst

Employer of Record (EOR) · Global Payroll

Lead Security Engineer

Remote · BGPosted 4 months ago
SecurityStaff+Full Time
Apply at RemoFirst

Opens the source posting on jobs.lever.co

Source description

About the role

View original
  1. Identity & Access Management (The Core)

Customer Identity: Own the architecture and security of our Auth0 implementation for client-facing applications. You will be fine-tuning our internal authentication service to support SCIM provisioning and help set up the OIDC federation with our enterprise client’s IdPs.

Internal Identity: Manage and automate our Okta environment, ensuring seamless SSO, lifecycle management (onboarding/offboarding), and hardware-based MFA. Expect a fairly complex internal RBAC and the need to actually speak with the other functions within the organization to understand their ways of working and translate them into security controls

Cloud Identity: Enforce "Least Privilege" across our AWS ecosystem , managing complex AWS IAM policies and Service Control Policies (SCPs).

  1. Security Engineering & Pentesting

Offensive Security: Conduct regular internal pentests and vulnerability scans against our Python/Django and Java/Spring Boot services as well as coordinate with 3LOD pen testers

Secure SDLC: Work alongside devs to review code (e.g. implementation of the security library you’ve built), secure our Postgres databases, help engineers with thread modelling and harden our Kafka message streams. You will be the owner of our SAST/DAST and detect license misuse, outdated libraries, and help shape a non-invasive secure SDLC that developers love by building paved roads

AI Security: Define the guardrails for our AI initiatives, ensuring data privacy in LLM prompts and securing our model pipeline.

  1. Governance, Risk, and Compliance (GRC)

The Audit Lead: Take the wheel for our SOC 2 Type II and ISO 27001 certifications. You will be a key person in maintaining our internal risk register as well as helping our Front-line teams with inbound security questionnaires from large clients.

Automation: Utilize compliance automation tools to ensure we stay "audit-ready" every single day, not just once a year. You will own our “Trust Center” in Thoropass (our compliance platform)

Policy as Code: Help draft and implement pragmatic security policies that reflect how a modern startup actually works. We are talking about data residency, logging, audit trails, dealing with non-repudiation, etc.

More at RemoFirst

Related open roles

View all roles