Lead Application Security Engineer
New
R
RemoFirstFintech EOR
South Africa. Romania. Poland. Spain. Portugal. UkraineFull-TimeLead
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Languages
- English
- Required Skills
- AWSPythonDjangoJavaKubernetesSpring BootFastAPI
Requirements
- Deep hands-on application security experience including code review, threat modeling, and offensive testing.
- Strong proficiency with Python (Django, FastAPI) and Java (Spring Boot).
- Working knowledge of message brokers (Kafka, RabbitMQ) and databases (PostgreSQL, MongoDB).
- Strong AWS security experience (IAM, SCPs, EKS, RDS, S3).
- Practical experience securing customer-facing identity (Auth0 or equivalent).
- Understanding of SAML, OIDC, and API-based security.
- Excellent communication skills with the ability to explain risk to non-security stakeholders.
- Proficiency in English is mandatory.
Responsibilities
- Run internal penetration tests and vulnerability scans against Python and Java services.
- Coordinate third-party pentests, scope engagements, and oversee remediation of findings.
- Work with engineers on code reviews and threat modeling to improve the security library.
- Manage SAST/DAST tooling and oversee dependency management and license compliance.
- Enforce AWS cloud security including IAM, SCPs, EKS, RDS, and S3.
- Own the architecture and security of Auth0 implementations and API authorization.
- Define and implement guardrails for AI/LLM initiatives and model pipeline security.
View Full Description & ApplyYou'll be redirected to the employer's site