Lead Application Security Engineer
Core
Lead Application Security Engineer responsible for offensive security, secure SDLC, cloud security, customer-facing identity, and AI security within a global EOR platform.
Role type
Senior IC application security engineer (offensive + secure SDLC)
Builds
Secure Python/Django, FastAPI, and Java/Spring Boot services; AWS infrastructure; Auth0 identity architecture; AI/LLM guardrails
Domain
Fintech/Global Employment (EOR) + Cloud Security + AI Security
Deliverable
production ML models | product features | infrastructure
Required skills
Application security (code review, threat modelling, offensive testing), AWS security (IAM, SCPs, EKS, RDS, S3), Identity management (Auth0, SAML, OIDC), Multi-tenancy security, Secure SDLC tooling (SAST/DAST), Python, Java, Kafka, RabbitMQ, PostgreSQL, MongoDB
Preferred skills
Terraform, REST APIs, webhooks, AI/LLM security (prompt/data-flow risk, model pipeline), Fintech/payroll domain experience, Global distributed team experience
Technologies
Python, Django, FastAPI, Java, Spring Boot, Kafka, RabbitMQ, PostgreSQL, MongoDB, AWS, IAM, SCPs, EKS, RDS, S3, Auth0, Terraform
Responsibilities
Run internal penetration tests and vulnerability scans; Coordinate and manage third-party pentests; Work with engineers on code review and threat modelling; Own SAST/DAST tooling and dependency posture; Enforce least privilege across AWS ecosystem; Harden container and Kubernetes workloads; Own Auth0 architecture and API security; Define guardrails for AI initiatives
Seniority
Senior, hands-on IC
