08 ago
|
Payfit
|
Barcelona
About Pay FitDo you want to help shape what the future of work will look like and how it will best embrace our life's aspirations? If this sounds like a journey you want to embark on, we may have the right role for you! Pay Fit is an intuitive software-as-a-service payroll and HRIS solution designed specifically for SMBs. Since 2015, we have set ourselves a mission to simplify payroll for SMBs and enable employers and employees to grow together. We are a European company operating from three main countries (France, Spain, and the UK) where we support over 20,000 clients.LocationYou can work at this role from any location in France or Spain, with occasional visits to the Paris office.Position OverviewWe're looking for a Senior Application Security Engineer to join our Application Security team, part of the Engineering Platform tribe. You'll be the App Sec engineer closest to our product engineering teams, not the gatekeeper at the end of the pipeline, but the partner who helps developers ship secure software by default. You'll drive a meaningful shift-left across the SDLC, mentor the rest of the security team, and bring an offensive mindset to how we test our own applications, including how we leverage AI to pentest them.This is a senior individual contributor role with strong influence. You'll work alongside another Security Engineer and our Compliance Analysts, and partner daily with infrastructure, platform, and product engineering teams to keep Pay Fit secure as we scale across Europe.Your MissionShift Security Left Across the SDLCEmbed security into how Pay Fit builds software. Partner with product teams from design to deployment;
threat model new features, review architecture decisions, perform code reviews, and help developers internalize secure-by-default patterns. Make security a multiplier, not a bottleneck.Drive Offensive Testing of Our Applications, Including with AIRun internal application pentests with an attacker mindset and explore how AI can be used to scale and deepen our offensive testing, from automated reconnaissance to AI-assisted vulnerability discovery on our own codebase and APIs. Turn findings into concrete remediation plans and reusable detection patterns.Secure the SDLC in the Age of AIHelp define how Pay Fit builds software securely when AI is part of the toolchain, from AI-assisted code generation in developer workflows to agentic systems we operate internally. Contribute to guardrails, review patterns, and threat models for AI-augmented development and AI features in our product.Build and Operate App Sec ToolingDeploy and maintain security tooling across our CI/CD pipelines: SAST, SCA, container and image scanning,
secrets detection, and supply chain controls. Build automation in Type Script to scale security across our AWS and Kubernetes/EKS estate, integrating with our existing toolchain (Git Hub, Circle CI, Spacelift, Wiz, Datadog, Jira).Grow the Team and the Security CultureMentor the other members of the Security & Compliance team and raise the security bar across engineering. Lead awareness sessions, write standards, run training, and animate the security community at Pay Fit. Make others better. That's a core part of the job.Handle Vulnerabilities and IncidentsTriage Hacker One reports, follow up on findings with engineering teams, and contribute to incident response: investigation, coordination, and post-mortem. Identify systemic issues behind individual findings and drive durable fixes.What we are looking for5+ years of experience in security, with a strong Application Security focus and a background in software engineering or Dev OpsSolid cloud security knowledge, with a strong advantage for AWS (IAM, Secrets Manager, Organizations, Identity Center), and with the ability to design and review secure cloud-native architecturesHands‑on experience reviewing the security of applications across architecture, code, and infrastructure, with a risk-driven approachComfortable with application security fundamentals: authentication and authorization, encryption, integrity, logging, supply chainOffensive mindset: experience running application pentests, exploiting vulnerabilities, and translating findings into actionable remediationCoding skills in Type Script (for code review and building security tooling)Experience working in modern Saa S ecosystems: Ia C, Git Ops, Dev Sec Ops, CI/CD (Terraform, Git Hub, Circle CI, Helm, or equivalents)Strong communication skills: you can talk to developers as a peer, explain risk to non-security audiences, and influence without authorityA genuine taste for mentoring and growing othersProfessional English: written and spokenNice to HaveExperience in pentesting or securing AI/LLM-powered applications,
or using AI tooling for offensive securityWorking knowledge of Kubernetes security in production environmentsExperience with bug bounty programs (Hacker One or equivalent)Familiarity with security observability and detection tooling (SIEM, Datadog, Wiz, or similar)Exposure to compliance frameworks (ISO 27001, SOC 2, DORA);
useful given our team setupOur StackTechnical stack: Type Script, AWS, Kubernetes, Helm, TerraformCode & delivery: Git Hub, Circle CI, Argo CD, SpaceliftSecurity & observability: Wiz, Datadog, Hacker One, Burp SuiteProject management and knowledge: Jira, NotionCommunication: Slack, Gather, MeetWhy Join Pay FitReal impact: You'll directly shape how 20,000+ businesses across Europe trust us with their payroll and HR dataSenior IC role with reach: You influence engineering at large, not just the security teamPragmatic security: We care about real risk reduction, not theaterAI-forward security: A real mandate to explore AI in offensive security, not a buzzwordModern stack and modern practices: Cloud-native, Git Ops, Dev Sec Ops, and the autonomy to shape themAI-First Developer Experience: We fully support and fund the use of AI agents (Claude Code, Codex, Open Code, etc.) to automate routine tasks, accelerate refactoring, and minimize "toil," allowing you to stay in a state of deep flow.What We OfferFlexibility: Work away from our main offices, within France or abroad for a defined period. Further requirements may apply depending on the role and your overall experience.Learning & Development: Comprehensive learning platform, English language courses to improve business communication.Career Development: Opportunities for internal moves and choosing your growth direction.Health insurance: Henner Mutuelle Insurance (60% covered by Pay Fit, free coverage for children).Transportation: 50% of public transportation costs covered for those living within the Ile de France region, or assistance with sustainable als: Restaurant card with Swile (9€ per workday) covered at 60% by Pay Fit.A Work Council grant: Monthly allowance to be spent on culture, sports, personal services, etc., and a vacation bonus.Home office budget: Contribution in € per year to help you get set up in the best conditions. A Mac Book is the standard working tool.Parental support program: Salary maintenance during the first month of additional parental leave.Time off: 25 days of holidays + RTT days (depending on contract).Disability InclusionAll of our positions are open to any person living with a disability. To guarantee equal treatment and opportunities, we will take, based on individual needs, appropriate measures to adapt the work conditions of Pay Fiters with disabilities, and if needed also during the recruitment process. Please let us know what you need and we will do our best to accommodate!
📌 Senior Application Security Engineer (Barcelona)
🏢 Payfit
📍 Barcelona