CareerScanCareerScan
JobsCompanies
BlogContact
For Employers
Sign InRegister Free
CareerScanCareerScan

India's verified job platform connecting candidates directly with employers. 100% free applications with instant ATS resume scoring.

Chennai, Bengaluru & Hyderabad
Jobs by location
Jobs in ChennaiJobs in BengaluruJobs in HyderabadJobs in PuneJobs in Mumbai
Popular roles
AR Caller JobsHealthcare Medical CodingReact / Full Stack DeveloperData & Power BI AnalystCustomer Support Executive
Top companies
TCS CareersCognizant JobsInfosys OpeningsApollo HospitalsOmega Healthcare
Career services
Free ATS Resume CheckerAI Resume Builder (Free)AI Job MatcherSalary Guide & BenchmarksJob Alerts on WhatsApp
© 2026 CareerScan India. All rights reserved.256-bit SSL encrypted & verified
Back to all jobs
  1. Home
  2. Jobs
  3. Lead Application Security Engineer
Remofirst
Remofirst

Lead Application Security Engineer

Estonia
₹270/mo
Full-time
Posted 3d ago
0 views
Actively Hiring Direct 1-Click Apply

Check Your Resume Match Score

Scan your resume against ATS criteria for this Lead Application Security Engineer role at Remofirst.

Apply for this position

Apply on Company Website
Notice a broken link or wrong info?

Job Description

RemoFirst is changing how the world hires.

We're an affordable, AI-native Employer of Record that combines intelligent agents with a team of human experts to support global hiring, payroll, and HR, while ensuring compliance in 185+ countries. We partner with some of the world's most innovative startups and Fortune 500 companies to support all their global hiring needs.

✨ Since launching in 2021, we've:

  • Grown to a strong team of 200+ people across 40+ countries
  • Raised $39M+, backed by Octopus Ventures, QED Investors, Mouro Capital, and Counterpart Ventures 
  • Trusted by startups, fast-growing companies, and Fortune 500 industry leaders. A few amazing customers include HubSpot, PandaDoc, Mastercard, Microsoft
  • Named a Leader in the NelsonHall NEAT Evaluation for Global EOR Services
  • Recognized on Inc.'s Best Workplaces list and Fast Company's Best Workplaces for Innovators
    We're hyper-focused on delivering a world-class platform and unparalleled service — and we're just getting started. If you want to help us drive that change, we'd love for you to apply!

What you'll own

Offensive security

  • Run regular internal penetration tests and vulnerability scans against our Python/Django, FastAPI and Java/Spring Boot services.
  • Coordinate our independent third-party pentests: scope them, judge the findings, and hold people to remediation instead of filing the report.
  • Find the multi-tenancy and authorisation bugs that matter in a platform where customer's data must never surface in another's account.

Secure SDLC

  • Work directly with engineers on code review and threat modelling, and own the life of our internal security library.
  • Own our SAST/DAST tooling and dependency posture — outdated libraries, license misuse, and the judgement to tell a finding from a real risk.
  • Secure the layers our services run on: PostgreSQL and MongoDB persistence, Kafka and RabbitMQ streams.
  • Build paved roads. A secure SDLC engineers route around is a failed, so the goal is guardrails they reach for rather than a gate they resent.

Cloud security

  • Enforce least privilege across our AWS ecosystem: IAM policies, Service Control Policies, and the EKS, RDS and S3 estate underneath.
  • Harden our container and Kubernetes workloads, and make secrets handling boring.
  • Instrument the above — you should find out about a misconfiguration from an alert, not from a customer.

Customer-facing identity

  • Own the architecture and security of our Auth0 implementation for client-facing applications.
  • Extend our internal authentication service to support SCIM provisioning, and stand up OIDC federation with our enterprise clients' IdPs — increasingly what unblocks large deals.
  • Own API security: authorisation logic, token handling, and the failure modes that show up in multi-tenant systems.

AI security

  • Define the guardrails for our AI initiatives — what data can reach an LLM prompt, what can't, and how we enforce it.
  • Secure our model pipeline. This is young for us, so you'd be shaping it rather than inheriting it.

Requirements

Must have

  • Deep hands-on application security in a real engineering organisation: code review, threat modelling, and offensive testing against services you were also responsible for defending.
  • Familiarity with our stack. Python and Java are at the heart of our services (Django, FastAPI, Spring Boot), with Kafka and RabbitMQ between them and PostgreSQL plus some MongoDB underneath. You don't need all of it, but you need to read our code and argue with our engineers on the merits.
  • Strong AWS security — IAM, SCPs, EKS, RDS, S3 — and a view on what least privilege looks like when it has to survive contact with a shipping team.
  • Practical experience securing customer-facing identity: Auth0 or equivalent, plus a working understanding of SAML, OIDC and API-based security.
  • You explain security decisions in terms of risk and business need, and you can say no to a request without making an enemy.

Nice to have

  • You write code at the level of building and maintaining tooling and automation, not just scripts. Comfortable with REST APIs, webhooks, and Terraform or similar for config-as-code.
  • AI/LLM security experience: prompt and data-flow risk, model pipeline security, or work against an emerging framework in the space.
  • Exposure to fintech, payroll or another domain where money movement and personal data raise the stakes.
  • You've done this in a globally distributed, remote-first company, where data residency and jurisdiction are real constraints rather than slideware.
  • Familiarity with the EOR or global employment space.

Probably not the right fit if

You want an architecture role where someone else does the building, or a purely offensive role where you hand off findings and move on. This role is both halves — you find it and you help fix it.

Benefits

💚 How you'll work

  • Clear communication and strategic thinking — We work with people all over the world, so we must communicate clearly, adapt quickly, and relay information in different ways depending on the audience.
  • Time management — You'll need to structure your day and prioritize your tasks well, so you can get everything done while maintaining a healthy work-life balance.
  • Collaboration — We love working with all kinds of people in all kinds of places. Everyone's opinion matters when it comes to getting the job done.
  • Independence and autonomy — We're a naturally independent team. While we're always connected, you'll need to use your own initiative to solve problems and find answers — and know when to reach out for help or to confirm a solution.
  • Empathy — You'll need excellent people skills to connect with and motivate yourself and those around you. Empathy is key to navigating all kinds of conversations with different audiences.
  • Motivation — We want our team to be passionate about our mission and consistently driven to do great work. English proficiency is a must.

💚 Why this matters

  • Startup environment — RemoFirst is an early-stage startup where your voice matters. You can influence decisions and grow quickly.
  • Build & scale from scratch — Experience hyper-growth and help us build a world-class team that can achieve our ambitious vision.
  • Work for a market leader — Help scale a platform trusted by market-leading companies like Microsoft, Mastercard, and more.
  • 100% remote work — Work from anywhere, with PTO regulated by local statutory requirements.
  • Culture — We lead with respect, kindness, and the right to fail. We value hard, smart work, and diversity and inclusion are part of our DNA. As we grow, we welcome your input to help shape our culture even further.

💚 How we support you

  • Parental leave — Up to 90 days paid parental leave for new parents, with additional protections as required locally.
  • Wellbeing stipend — A monthly wellbeing allowance to spend on what supports you, whether that's fitness, mental health, or downtime.
  • Remote-first, always — No office required, ever. Work from wherever you do your best work.

Key Requirements & Skills

  • Deep hands-on application security in a real engineering organisation: code review, threat modelling, and offensive testing against services you were also responsible for defending.
  • Familiarity with our stack. Python and Java are at the heart of our services (Django, FastAPI, Spring Boot), with Kafka and RabbitMQ between them and PostgreSQL plus some MongoDB underneath. You don't need all of it, but you need to read our code and argue with our engineers on the merits.
  • Strong AWS security — IAM, SCPs, EKS, RDS, S3 — and a view on what least privilege looks like when it has to survive contact with a shipping team.
  • Practical experience securing customer-facing identity: Auth0 or equivalent, plus a working understanding of SAML, OIDC and API-based security.
  • You explain security decisions in terms of risk and business need, and you can say no to a request without making an enemy.
  • You write code at the level of building and maintaining tooling and automation, not just scripts. Comfortable with REST APIs, webhooks, and Terraform or similar for config-as-code.
  • AI/LLM security experience: prompt and data-flow risk, model pipeline security, or work against an emerging framework in the space.
  • Exposure to fintech, payroll or another domain where money movement and personal data raise the stakes.
  • You've done this in a globally distributed, remote-first company, where data residency and jurisdiction are real constraints rather than slideware.
  • Familiarity with the EOR or global employment space.

Benefits & Perks

visioning, and stand up OIDC federation with our enterprise clients' IdPs — increasingly what unblocks large deals.

Frequently Asked Questions

How to apply for Lead Application Security Engineer at Remofirst?

Click the "Apply on Company Website" button on this page to submit your application directly on the employer's official portal.

What is the salary for this role?

The salary for this role is $39 per annum.

What experience is required?

This position is open to freshers and experienced candidates.

Is this position still open?

Yes, currently active and accepting applications.

ApplicationActively Hiring
Apply on Company Website
Broken link or expired?
Remofirst

Remofirst

About Us Book a demo Why RemoFirst? Product Employer of Record Employ talent anywhere without multiple entities. Employer of Record Employ talent anywhere without multiple entities. Global Payroll Run payroll in numerous international currencies. Global Payroll Run payroll in numerous international currencies. International Contractors Onboard and pay contractors in 150+ countries. International Contractors Onboard and pay contractors in 150+ countries. RemoHealth Provide global employees with health insurance. RemoHealth Provide global employees with health insurance. Visas & Work Permits

Visit Company Website

More jobs at Remofirst

Junior Talent Partner

Poland

Product Operations Manager

Brazil

Sales Development Representative

Colombia

Share this Opening

Job Alerts for security

Receive email alerts whenever new security roles in Estonia are posted.

Set Free Alert →

Similar Openings

Explore related active roles in security

View all
UrgentActively Hiring
Doppel
Product Security
Doppel Verified
7+ years
₹12.1L – ₹13.8L/mo
US Remote
securityFull-timeRemote
Posted 1d ago
Apply Now
UrgentActively Hiring
Immersivelabs
Solutions Consultant (Cyber Security) - Portugal
Immersivelabs Verified
2+ years
₹1,245/mo
Portugal
securityFull-time
Posted 1d ago
Apply Now
UrgentActively Hiring
Teciem
Job Role – IAM and PAM Security Lead
Teciem Verified
8+ years
Salary not disclosed
TCMi - Bengaluru
securityFull-time
Posted 1d ago
Apply Now

Lead Application Security Engineer

Remofirst · Estonia

Apply on Company Website