Logo for Remofirst

Lead Security Engineer

Role overview

Qualifications

  • 5+ years of security engineering experience
  • Strong AWS security expertise (EKS, RDS, IAM, S3) with hands-on experience in Okta/Auth0, SAML/OIDC and SCIM
  • Proven track record leading SOC 2 Type II and ISO 27001 programs with collaboration with Risk & Compliance teams
  • Hands-on experience with secure SDLC, SAST/DAST, vulnerability management, and translating complex compliance requirements into engineering outcomes

Responsibilities

  • Own Identity and Access Management architecture and security for client-facing Auth0 deployments and internal authentication with SCIM provisioning, plus RBAC and MFA alignment
  • Harden AWS security posture across the ecosystem (least privilege, IAM policies, SCPs) and secure data stores (PostgreSQL) and messaging (Kafka); drive secure coding practices and code/secret scanning
  • Define and enforce AI security guardrails, including data privacy in LLM prompts and securing model pipelines against prompt injections and data leakage
  • Lead GRC efforts for SOC 2 Type II and ISO 27001, maintain risk registers, respond to security questionnaires, and automate compliance via tools like Thoropass Trust Center and policy as code

About the company

Remofirst logo

Remofirst

Human Resources Services

Global payroll & compliance for your remote team. All-in-one platform to hire anyone from anywhere with one click. Same-day onboarding. Available in 150+ countries

Company details

Company typeStartup
IndustryHuman Resources Services
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

As the first dedicated security hire at RemoFirst, you will be the architect of our trust layer. We are a fast-growing Series A company handling sensitive data, and we need a Lead Security Engineer who thrives at the intersection of deep technical implementation and strategic compliance. You won’t just be writing policies; you’ll be configuring our Auth0 tenants, hardening our AWS infrastructure, and ensuring our AI/LLM deployments are secure. You will own our SOC 2 and ISO 27001 programs from end-to-end, avoiding the "check-the-box" compliance and instead moving us toward a culture of continuous security. We run payroll in 185 countries, collect tons of PII, run KYC checks and combat both internal and external fraud. Compliance and Security are not an afterthought for our product, but an essential part of establishing trust with our clients.

Core Responsibilities:
  • 1. Identity & Access Management (The Core)
  • Customer Identity: Own the architecture and security of our Auth0 implementation for client-facing applications. You will be fine-tuning our internal authentication service to support SCIM provisioning and help set up the OIDC federation with our enterprise client’s IdPs.
  • Internal Identity: Manage and automate our Okta environment, ensuring seamless SSO, lifecycle management (onboarding/offboarding), and hardware-based MFA. Expect a fairly complex internal RBAC and the need to actually speak with the other functions within the organization to understand their ways of working and translate them into security controls
  • Cloud Identity: Enforce "Least Privilege" across our AWS ecosystem, managing complex AWS IAM policies and Service Control Policies (SCPs).

  • 2. Security Engineering & Pentesting
  • Offensive Security: Conduct regular internal pentests and vulnerability scans against our Python/Django and Java/Spring Boot services as well as coordinate with 3LOD pen testers
  • Secure SDLC: Work alongside devs to review code (e.g. implementation of the security library you’ve built), secure our Postgres databases, help engineers with thread modelling and harden our Kafka message streams. You will be the owner of our SAST/DAST and detect license misuse, outdated libraries, and help shape a non-invasive secure SDLC that developers love by building paved roads
  • AI Security: Define the guardrails for our AI initiatives, ensuring data privacy in LLM prompts and securing our model pipeline.

  • 3. Governance, Risk, and Compliance (GRC)
  • The Audit Lead: Take the wheel for our SOC 2 Type II and ISO 27001 certifications. You will be a key person in maintaining our internal risk register as well as helping our Front-line teams with inbound security questionnaires from large clients.
  • Automation: Utilize compliance automation tools to ensure we stay "audit-ready" every single day, not just once a year. You will own our “Trust Center” in Thoropass (our compliance platform)
  • Policy as Code: Help draft and implement pragmatic security policies that reflect how a modern startup actually works. We are talking about data residency, logging, audit trails, dealing with non-repudiation, etc.

  • Technical Requirements:
  • Familiarity with our core tech stack: Python/Java with Django, FastAPI & SpringBoot is at the heart of our services. We are using Kafka & RabbitMQ for interservice communications and PostgreSQL with some MongoDB on our persistence layer
  • Strong knowledge of Cloud Infrastructure: We use AWS with EKS, RDS as well the traditional IAM, S3, etc.
  • Internal & User-facing IAM: Comfortable with IAM - some experience with Okta and/or Auth0. Good understanding of protocols like SAML, OIDC, understanding of API-based security
  • Compliance: Familiarity with the SOC2 and ISO27001 audit cycle, comfortable with working with Risk & Compliance teams, both internal and external

  • Who You Are:
  • The Builder: You have 5+ years of experience in security engineering. You prefer an IDE to a spreadsheet.
  • The Auditor-Translator: You can explain complex ISO 27001 requirements to a software engineer in a way that makes sense to them.
  • The Pragmatist: You understand that "No" is not always the answer. You find ways to enable the business to move fast, safely.
  • Bonus points - An AI Enthusiast: You are keeping up with the OWASP Top 10 for LLMs and understand the risks of prompt injection and data leakage.
  • Apply once. Then go straight to the hiring manager.

    After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

    MR

    Marcus Rivera

    Chief Revenue Officer

    m.rivera@company.com
    linkedin.com/in/marcusrivera
    Unlocked after you apply
    ·

    Security Engineer Related jobs

    Other jobs at Remofirst

    Premium

    Reach out to the hiring manager directly.

    Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

    • Full match report with fit score and gaps
    • Career diagnostics on how recruiters read you
    • Curated company matches and warm intros
    • 48h early access to new roles

    Cancel anytime.