
Lead Application Security Engineer
Posted Aug 7

Posted Aug 7
This is a fully remote position, open to applicants in South Africa, +5 more countries.
• Conduct regular internal penetration testing and vulnerability assessments on Python/Django, FastAPI, and Java/Spring Boot services.
• Manage independent third-party penetration tests, including defining scope, evaluating findings, and facilitating remediation efforts.
• Detect multi-tenancy and authorization vulnerabilities.
• Collaborate with engineers on code reviews and threat modeling exercises.
• Take ownership of the internal security library.
• Manage SAST/DAST tools and oversee the security posture of dependencies.
• Secure the infrastructure layers of PostgreSQL, MongoDB, Kafka, and RabbitMQ.
• Establish secure SDLC guardrails and paved roads.
• Enforce least privilege principles across AWS IAM, Service Control Policies, EKS, RDS, and S3.
• Strengthen container and Kubernetes workloads and manage secrets handling.
• Implement cloud security controls and monitor for misconfigurations.
• Oversee the architecture and security of the Auth0 implementation.
• Extend internal authentication mechanisms to support SCIM provisioning.
• Implement OIDC federation with enterprise identity providers.
• Manage API security, covering authorization logic, token management, and multi-tenant failure scenarios.
• Establish guidelines for AI initiatives and regulate data flows to LLM prompts.
• Secure and optimize the model pipeline.
• Extensive hands-on application security expertise within an engineering setting, encompassing code reviews, threat modeling, and offensive testing.
• Proficiency in reading and evaluating Python and Java code.
• Familiarity with Django, FastAPI, Spring Boot, Kafka, RabbitMQ, PostgreSQL, and MongoDB.
• Strong experience with AWS security, particularly with IAM, Service Control Policies, EKS, RDS, and S3.
• Practical experience securing customer-facing identities using Auth0 or a similar platform.
• Working knowledge of SAML, OIDC, and API-based security frameworks.
• Capability to articulate security decisions in terms of risk management and business needs.
• Ability to create and sustain security tools and automation processes.
• Comfortable with REST APIs, webhooks, and Terraform or equivalent configuration-as-code tools.
• Experience in AI/LLM security is a plus.
• Exposure to fintech, payroll, or domains involving high-stakes personal data is advantageous.
• Experience in a globally distributed, remote-first organization is preferred.
• Familiarity with the EOR or global employment landscape is a plus.
• Proficiency in English is mandatory.
• 100% remote work — Enjoy the flexibility to work from anywhere, with PTO governed by local statutory regulations.
• No office required, ever.
• Up to 90 days of paid parental leave for new parents, with additional protections as mandated by local laws.
• Monthly wellbeing stipend for fitness activities, mental health support, or downtime.
• Join a startup environment with opportunities to influence decisions and accelerate your growth.
• Help build and scale from the ground up in a rapidly growing environment.
• Work for a market leader trusted by prominent companies like Microsoft and Mastercard.
• Experience a respectful, kind, diverse, and inclusive culture.
• Benefit from English proficiency support through clear communication and globally distributed collaboration.
Avnet
Teradyne
Intetics
New Charter Technologies
Get handpicked remote jobs straight to your inbox weekly.