الوصف الوظيفي
تغير RemoFirst طريقة التوظيف في العالم.
نحن صاحب عمل مسجل (Employer of Record) بتكلفة ميسورة ويعتمد على الذكاء الاصطناعي، حيث نجمع بين الوكلاء الأذكياء وفريق من الخبراء البشر لدعم التوظيف العالمي، وكشوف المرتبات، والموارد البشرية، مع ضمان الامتثال في أكثر من 185 دولة.
نحن نتشارك مع بعض أكثر الشركات الناشئة ابتكارًا في العالم وشركات Fortune 500 لدعم جميع احتياجات التوظيف العالمية لديها.
✨ منذ إطلاقنا في عام 2021، قمنا بـ: النمو إلى فريق قوي يضم أكثر من 200 شخص عبر أكثر من 40 دولة، وجمع أكثر من 39 مليون دولار بدعم من Octopus Ventures وQED Investors وMouro Capital وCounterpart Ventures، وحظينا بتمويل وثقة الشركات الناشئة والشركات سريعة النمو والشركات الرائدة في قائمة Fortune 500.
تشمل قائمة بعض عملائنا الرائعين HubSpot وPandaDoc وMastercard وMicrosoft. تم تصنيفنا كشركة رائدة في تقييم NelsonHall NEAT لخدمات Employer of Record (EOR) العالمية، وتم تقديرنا في قائمة أفضل أماكن العمل لـ Inc. وقائمة أفضل أماكن العمل للمبتكرين لـ Fast Company. نركز بشكل فائق على تقديم منصة عالمية المستوى وخدمة لا مثيل لها — وهذه مجرد البداية.
إذا كنت ترغب في مساعدتنا في قيادة هذا التغيير، فسنكون سعداء بتقدمك لطلب الوظيفة!
ما ستتولى مسؤوليته:
الأمن الهجومي: إجراء اختبارات اختراق داخلية منتظمة وفحوصات ثغرات أمنية ضد خدماتنا القائمة على Python/Django وFastAPI وJava/Spring Boot.
تنسيق اختبارات الاختراق المستقلة التي تجريها الأطراف الخارجية: تحديد نطاقها، وتقييم النتائج، وإلزام الفرق بالمعالجة بدلاً من مجرد حفظ التقرير.
اكتشاف أخطاء تعدد المستأجرين والتفويض الهامة في منصة يجب ألا تظهر فيها بيانات عميل ما في حساب عميل آخر أبداً.
أمان دورة حياة تطوير البرمجيات (Secure SDLC): العمل مباشرة مع المهندسين على مراجعة الكود ونمذجة التهديدات، وتولي مسؤولية التحديث المستمر لمكتبة الأمان الداخلية لدينا.
إدارة أدوات SAST/DAST وحالة التبعيات الخاصة بنا — المكتبات القديمة، وإساءة استخدام التراخيص، والقدرة على التمييز بين النتيجة العادية والخطر الحقيقي.
تأمين الطبقات التي تعمل عليها خدماتنا: تخزين PostgreSQL وMongoDB، وتدفقات Kafka وRabbitMQ.
بناء طرق آمنة وسلسة.
إن دورة حياة تطوير البرمجيات الآمنة التي يتجنبها المهندسون هي دورة فاشلة، لذا فإن الهدف هو توفير حواجز حماية يسعون لاستخدامها بدلاً من بوابة ينزعجون منها.
أمان السحابة: تطبيق مبدأ الحد الأدنى من الصلاحيات عبر منظومة AWS لدينا: سياسات IAM، وسياسات التحكم في الخدمة (SCPs)، وبنية EKS وRDS وS3 التحتية.
تحصين أحمال عمل الحاويات وKubernetes، وجعل إدارة الأسرار أمراً آمناً واعتيادياً.
مراقبة ما سبق وقياسه — يجب أن تكتشف التكوين الخاطئ من خلال تنبيه، وليس من خلال بلاغ من العميل.
إدارة الهوية المواجهة للعملاء: تولي بنية وأمان تطبيق Auth0 الخاص بنا للتطبيقات المواجهة للعملاء.
توسيع خدمة المصادقة الداخلية لدعم توفير SCIM، وإقامة اتحاد OIDC مع مزودي الهوية (IdPs) لعملائنا من المؤسسات — وهو ما يسهل بشكل متزايد إبرام الصفقات الكبيرة.
إدارة أمان واجهة برمجة التطبيقات (API): منطق التفويض، والتعامل مع الرموز المُمثلة (tokens)، وأنماط الفشل التي تظهر في الأنظمة متعددة المستأجرين.
أمان الذكاء الاصطناعي: تحديد حواجز الحماية لمبادرات الذكاء الاصطناعي لدينا — ما هي البيانات التي يمكن أن تصل إلى مطالبات نماذج اللغات الكبيرة (LLM)، وما لا يمكنه ذلك، وكيفية تطبيق ذلك.
تأمين خط أنابيب النماذج الخاص بنا.
هذا مجال حديث بالنسبة لنا، لذا ستعمل على تشكيله وتأسيسه بدلاً من مجرد ورثه.
كيف ستعمل: التواصل الواضح والتفكير الاستراتيجي — نعمل مع أشخاص من جميع أنحاء العالم، لذا يجب أن نتواصل بوضوح، ونتكيف بسرعة، وننقل المعلومات بطرق مختلفة حسب الجمهور.
إدارة الوقت — ستنحتاج إلى تنظيم يومك وتحديد أولويات مهامك بشكل جيد، حتى تتمكن من إنجاز كل شيء مع الحفاظ على توازن صحي بين العمل والحياة الشخصية.
التعاون — نحب العمل مع جميع أنواع الأشخاص في مختلف الأماكن.
رأي الجميع مهم عندما يتعلق الأمر بإنجاز العمل.
الاستقلالية والتمتع بالاستقلال الذاتي — نحن فريق مستقل بطبيعتنا.
ورغم أننا متصلون دائمًا، ستقتضي الحاجة استخدام مبادرتك الخاصة لحل المشكلات والعثور على الإجابات — ومعرفة متى تطلب المساعدة أو تتأكد من الحل.
التعاطف — ستسحتاج إلى مهارات تعامل ممتازة للتواصل مع نفسك ومع من حولك وتحفيزهم.
التعاطف عنصر أساسي لإدارة جميع أنواع المحادثات مع مختلف الجماهير.
التحفيز — نريد أن يكون فريقنا شغوفًا بمهمتنا ومندفعًا باستمرار لتقديم عمل رائع.
إتقان اللغة الإنجليزية أمر إلزامي.
لماذا يعد هذا الأمر مهمًا: بيئة الشركات الناشئة — RemoFirst هي شركة ناشئة في مراحلها الأولى حيث يكون لصوتك قيمة.
يمكنك التأثير على القرارات والنمو بسرعة.
البناء والتوسع من الصفر — خض تجربة النمو الفائق وساعدنا في بناء فريق عالمي المستوى يمكنه تحقيق رؤيتنا الطموحة.
العمل مع شركة رائدة في السوق — ساعد في توسيع منصة تثق بها الشركات الرائدة في السوق مثل Microsoft وMastercard وغيرها.
عمل عن بُعد بنسبة 100% — اعمل من أي مكان، مع إجازات مدفوعة الأجر تخضع للمتطلبات القانونية المحلية.
الثقافة — نحن نعتمد على الاحترام واللطف والحق في الخطأ.
نحن ندرك قيمة العمل الجاد والذكي، والتنوع والشمول جزء من حمضنا النووي.
مع نمونا، نرحب بمساهماتك لمساعدتنا في تشكيل ثقافتنا بشكل أكبر.
كيف ندعمك: إجازة الوالدية — إجازة والدية مدفوعة الأجر تصل إلى 90 يومًا للوالدين الجدد، مع حماية إضافية وفقًا للمتطلبات المحلية.
بدل الرفاهية — مخصص شهري للرفاهية للإنفاق على ما يدعمك، سواء كان ذلك اللياقة البدنية أو الصحة النفسية أو أوقات الراحة.
بيئة أولويتها العمل عن بُعد دائمًا — لا يلزم وجود مكتب أبدًا.
اعمل من المكان الذي تؤدي فيه أفضل أعمالك.
المتطلبات الأساسية: خبرة عملية عميقة في أمن التطبيقات داخل مؤسسة هندسية حقيقية: مراجعة الكود، ونمذجة التهديدات، والاختبار الهجومي للخدمات التي كنت مسؤولاً أيضاً عن الدفاع عنها.
الإلمام بالتقنيات المستخدمة لدينا.
تُعد Python وJava في قلب خدماتنا (Django وFastAPI وSpring Boot)، مع وجود Kafka وRabbitMQ بينها، وPostgreSQL بالإضافة إلى بعض MongoDB في البنية التحتية.
لا تحتاج لمعرفة كل ذلك، لكنك بحاجة لقراءة الكود الخاص بنا ومناقشة مهندسينا حول التفاصيل والمميزات التقنية.
أمان قوي في AWS — IAM وSCPs وEKS وRDS وS3 — ورؤية لما يعنيه مبدأ الحد الأدنى من الصلاحيات عندما يتعين تطبيقه عملياً مع فريق التطوير والتسليم.
خبرة عملية في تأمين الهويات المواجهة للعملاء: Auth0 أو ما يعادلها، بالإضافة إلى فهم عملي لـ SAML وOIDC والأمان القائم على واجهات برمجة التطبيقات (API).
تشرح قرارات الأمان من حيث المخاطر وااحتياجات العمل، ويمكنك رفض طلب ما دون أن تخسر الآخرين.
مهارات يُفضل وجودها: تكتب كودًا بمستوى بناء وصيانة الأدوات والأتمتة، وليس مجرد سكريبتات.
مرتاح في التعامل مع REST APIs وwebhooks وTerraform أو ما يماثلها لإدارة التكوين عبر الكود (config-as-code).
خبرة في أمان الذكاء الاصطناعي/نماذج اللغات الكبيرة (LLM): مخاطر المطالبات وتدفق البيانات، وأمان خط أنابيب النماذج، أو العمل وفقًا لإطار عمل ناشئ في هذا المجال.
خبرة سابقة في مجال التكنولوجيا المالية (fintech) أو كشوف المرتبات أو مجال آخر تزيد فيه حركة الأموال والبيانات الشخصية من مستوى المخاطر.
مارست هذا الدور في شركة موزعة عالميًا وتعتمد على العمل عن بُعد أولاً، حيث تكون إقامة البيانات والنطاق القضائي قيودًا حقيقية وليست مجرد نصوص في العروض التقديمية.
الإلمام بمجال Employer of Record (EOR) أو التوظيف العالمي.
قد لا تكون هذه الوظيفة مناسبة لك إذا: كنت تريد دورًا يقتصر على التصميم الهندسي (Architecture) حيث يبني شخص آخر المنظومة، أو دورًا هجوميًا محضًا تقوم فيه بتسليم النتائج والمضي قدمًا.
يتضمن هذا الدور كلا الجانبين — مكتشف الخلل والمساعد في إصلاحه.
Job description
RemoFirst is changing how the world hires.
We're an affordable, AI-native Employer of Record that combines intelligent agents with a team of human experts to support global hiring, payroll, and HR, while ensuring compliance in 185+ countries.
We partner with some of the world's most innovative startups and Fortune 500 companies to support all their global hiring needs.
✨ Since launching in 2021, we've: Grown to a strong team of 200+ people across 40+ countries Raised $39M+, backed by Octopus Ventures, QED Investors, Mouro Capital, and Counterpart Ventures Trusted by startups, fast-growing companies, and Fortune 500 industry leaders.
A few amazing customers include HubSpot, PandaDoc, Mastercard, Microsoft Named a Leader in the NelsonHall NEAT Evaluation for Global EOR Services Recognized on Inc.
's Best Workplaces list and Fast Company's Best Workplaces for Innovators We're hyper-focused on delivering a world-class platform and unparalleled service — and we're just getting started.
If you want to help us drive that change, we'd love for you to apply!
What you'll ownOffensive security Run regular internal penetration tests and vulnerability scans against our Python/Django, FastAPI and Java/Spring Boot services.
Coordinate our independent third-party pentests: scope them, judge the findings, and hold people to remediation instead of filing the report.
Find the multi-tenancy and authorisation bugs that matter in a platform where one customer's data must never surface in another's account.
Secure SDLC Work directly with engineers on code review and threat modelling, and own the ongoing life of our internal security library.
Own our SAST/DAST tooling and dependency posture — outdated libraries, license misuse, and the judgement to tell a finding from a real risk.
Secure the layers our services run on: PostgreSQL and MongoDB persistence, Kafka and RabbitMQ streams.
Build paved roads.
A secure SDLC engineers route around is a failed one, so the goal is guardrails they reach for rather than a gate they resent.
Cloud security Enforce least privilege across our AWS ecosystem: IAM policies, Service Control Policies, and the EKS, RDS and S3 estate underneath.
Harden our container and Kubernetes workloads, and make secrets handling boring.
Instrument the above — you should find out about a misconfiguration from an alert, not from a customer.
Customer-facing identity Own the architecture and security of our Auth0 implementation for client-facing applications.
Extend our internal authentication service to support SCIM provisioning, and stand up OIDC federation with our enterprise clients' IdPs — increasingly what unblocks large deals.
Own API security: authorisation logic, token handling, and the failure modes that show up in multi-tenant systems.
AI security Define the guardrails for our AI initiatives — what data can reach an LLM prompt, what can't, and how we enforce it.
Secure our model pipeline.
This is young for us, so you'd be shaping it rather than inheriting it.
How you'll work Clear communication and strategic thinking — We work with people all over the world, so we must communicate clearly, adapt quickly, and relay information in different ways depending on the audience.
Time management — You'll need to structure your day and prioritize your tasks well, so you can get everything done while maintaining a healthy work-life balance.
Collaboration — We love working with all kinds of people in all kinds of places.
Everyone's opinion matters when it comes to getting the job done.
Independence and autonomy — We're a naturally independent team.
While we're always connected, you'll need to use your own initiative to solve problems and find answers — and know when to reach out for help or to confirm a solution.
Empathy — You'll need excellent people skills to connect with and motivate yourself and those around you.
Empathy is key to navigating all kinds of conversations with different audiences.
Motivation — We want our team to be passionate about our mission and consistently driven to do great work.
English proficiency is a must.
Why this matters Startup environment — RemoFirst is an early-stage startup where your voice matters.
You can influence decisions and grow quickly.
Build & scale from scratch — Experience hyper-growth and help us build a world-class team that can achieve our ambitious vision.
Work for a market leader — Help scale a platform trusted by market-leading companies like Microsoft, Mastercard, and more.
100% remote work — Work from anywhere, with PTO regulated by local statutory requirements.
Culture — We lead with respect, kindness, and the right to fail.
We value hard, smart work, and diversity and inclusion are part of our DNA.
As we grow, we welcome your input to help shape our culture even further.
How we support you Parental leave — Up to 90 days paid parental leave for new parents, with additional protections as required locally.
Wellbeing stipend — A monthly wellbeing allowance to spend on what supports you, whether that's fitness, mental health, or downtime.
Remote-first, always — No office required, ever.
Work from wherever you do your best work.
Must have Deep hands-on application security in a real engineering organisation: code review, threat modelling, and offensive testing against services you were also responsible for defending.
Familiarity with our stack.
Python and Java are at the heart of our services (Django, FastAPI, Spring Boot), with Kafka and RabbitMQ between them and PostgreSQL plus some MongoDB underneath.
You don't need all of it, but you need to read our code and argue with our engineers on the merits.
Strong AWS security — IAM, SCPs, EKS, RDS, S3 — and a view on what least privilege looks like when it has to survive contact with a shipping team.
Practical experience securing customer-facing identity: Auth0 or equivalent, plus a working understanding of SAML, OIDC and API-based security.
You explain security decisions in terms of risk and business need, and you can say no to a request without making an enemy.
Nice to have You write code at the level of building and maintaining tooling and automation, not just scripts.
Comfortable with REST APIs, webhooks, and Terraform or similar for config-as-code.
AI/LLM security experience: prompt and data-flow risk, model pipeline security, or work against an emerging framework in the space.
Exposure to fintech, payroll or another domain where money movement and personal data raise the stakes.
You've done this in a globally distributed, remote-first company, where data residency and jurisdiction are real constraints rather than slideware.
Familiarity with the EOR or global employment space.
Probably not the right fit if You want an architecture role where someone else does the building, or a purely offensive role where you hand off findings and move on.
This role is both halves — you find it and you help fix it.