Principal Application Security Engineer (Madrid)

Principal Application Security Engineer (Madrid)

23 ago
|
Remofirst
|
Madrid

23 ago

Remofirst

Madrid

We're an affordable, AI-native Employer of Record that combines intelligent agents with a team of human experts to support global hiring, payroll, and HR, while ensuring compliance in 185+ countries. We partner with some of the world's most innovative startups and Fortune 500 companies to support all their global hiring needs. Raised $39M+, backed by Octopus Ventures, QED Investors, Mouro Capital, and Counterpart Ventures A few amazing customers include HubSpot, PandaDoc, Mastercard, Microsoft Named a Leader in the NelsonHall NEAT Evaluation for General EOR Services Offensive security Run regular internal penetration tests and vulnerability scans against our Python/Django, FastAPI and Java/Spring Boot services.

Find the multi-tenancy and authorisation bugs that matter in a platform where one customer's data must never surface in another's account. Work directly with engineers on code review and threat modelling, and own the ongoing life of our internal security library.

Secure the layers our services run on: PostgreSQL and MongoDB persistence, Kafka and RabbitMQ streams. A secure SDLC engineers route around is a failed one, so the goal is guardrails they reach for rather than a gate they resent. Cloud security Enforce least privilege across our AWS ecosystem: IAM policies, Service Control Policies, and the EKS, RDS and S3 estate underneath.

Harden our container and Kubernetes workloads, and make secrets handling boring. Own the architecture and security of our Auth0 implementation for client-facing applications.

Own API security: authorisation logic, token handling, and the failure modes that show up in multi-tenant systems. AI security Define the guardrails for our AI initiatives — what data can reach an LLM prompt, what can't, and how we enforce it. This is young for us, so you'd be shaping it rather than inheriting it.





Deep hands-on application security in a real engineering organisation: code review, threat modelling, and offensive testing against services you were also responsible for defending. Python and Java are at the heart of our services (Django, FastAPI, Spring Boot), with Kafka and RabbitMQ between them and PostgreSQL plus some MongoDB underneath. You don't need all of it, but you need to read our code and argue with our engineers on the merits.

Strong AWS security — IAM, SCPs, EKS, RDS, S3 — and a view on what least privilege looks like when it has to survive contact with a shipping team. Auth0 or equivalent, plus a working understanding of SAML, OIDC and API-based security. You explain security decisions in terms of risk and business need, and you can say no to a request without making an enemy.

Comfortable with REST APIs, webhooks, and Terraform or similar for config-as-code.

AI/LLM security experience: prompt and data-flow risk, model pipeline security, or work against an emerging framework in the space. Exposure to fintech, payroll or another domain where money movement and personal data raise the stakes. You've done this in a globally distributed, remote-first company, where data residency and jurisdiction are real constraints rather than slideware.

Familiarity with the EOR or global employment space. This role is both halves — you find it and you help fix it. Everyone's opinion matters when it comes to getting the job done. English proficiency is a must.

Startup environment — RemoFirst is an early-stage startup where your voice matters. Work for a market leader — Help scale a platform trusted by market-leading companies like Microsoft, Mastercard, and more. ~100% remote work — Work from anywhere, with PTO regulated by local statutory requirements. ~ Remote-first, always — No office required, ever.

📌 Principal Application Security Engineer (Madrid)
🏢 Remofirst
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: principal application security engineer (madrid) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: principal application security engineer (madrid) / madrid