CareerPlanSign in

Lead Application Security Engineer

Spain🌐 Remote💼 Full-time🗓 2026-08-07 → 2026-09-25

Core

Lead Application Security Engineer responsible for offensive security, secure SDLC, cloud security, customer-facing identity, and AI security within a global EOR platform.

Role type

Senior IC application security engineer (offensive + secure SDLC)

Builds

Secure Python/Django, FastAPI, and Java/Spring Boot services; AWS infrastructure; Auth0 identity architecture; AI/LLM guardrails

Domain

Fintech/Global Employment (EOR) + Cloud Security + AI Security

Deliverable

production ML models | product features | infrastructure

Required skills

Application security (code review, threat modelling, offensive testing), AWS security (IAM, SCPs, EKS, RDS, S3), Identity management (Auth0, SAML, OIDC), Multi-tenancy security, Secure SDLC tooling (SAST/DAST), Python, Java, Kafka, RabbitMQ, PostgreSQL, MongoDB

Preferred skills

Terraform, REST APIs, webhooks, AI/LLM security (prompt/data-flow risk, model pipeline), Fintech/payroll domain experience, Global distributed team experience

Technologies

Python, Django, FastAPI, Java, Spring Boot, Kafka, RabbitMQ, PostgreSQL, MongoDB, AWS, IAM, SCPs, EKS, RDS, S3, Auth0, Terraform

Responsibilities

Run internal penetration tests and vulnerability scans; Coordinate and manage third-party pentests; Work with engineers on code review and threat modelling; Own SAST/DAST tooling and dependency posture; Enforce least privilege across AWS ecosystem; Harden container and Kubernetes workloads; Own Auth0 architecture and API security; Define guardrails for AI initiatives

Seniority

Senior, hands-on IC

Sourced via workable · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.