All Positions

We're hiring

Full Stack Security Engineer

Build web applications and test their security, using AI throughout your work.

Remote: work from anywhereFull-time3 to 8+ years experience

About VRG

VRG builds and secures software for legal firms, enterprise SaaS businesses and professional services. We use AI tools in our security assessments, web application development and automation work. Our engineers investigate issues beyond automated scan results and build software around client requirements.

We are a small team. Each engineer takes responsibility for delivering work and supporting it, with direct access to the people making project decisions.

The Role

We are looking for a Full Stack Security Engineer to build web applications and test their security. You will split your time between client security audits and developing internal and client-facing products with AI tools.

You will use AI tools throughout the job: to write and review code, triage vulnerabilities, draft audit reports, automate reconnaissance and assist penetration tests. You should already be using tools such as Claude Code, Cursor or Copilot to deliver work.

What You'll Do

Security Audit & Assessment

  • Conduct web application penetration tests, code reviews, and architecture assessments for client engagements across SaaS, legal tech, and enterprise platforms
  • Identify vulnerabilities across the full stack: front-end injection, API misconfigurations, broken auth, business logic flaws, insecure data handling, and cloud misconfigs
  • Write security audit reports that explain the findings and recommended fixes to technical and non-technical readers
  • Use and extend AI-powered tooling to automate reconnaissance, vulnerability triage, and report generation
  • Stay current with OWASP Top 10, CWE/CVE databases, emerging attack vectors, and AI-specific threats such as prompt injection, data poisoning, and model exfiltration

Full Stack Engineering

  • Design, build, and maintain secure web applications using modern frameworks (React, Next.js, Node.js/TypeScript, Python, or equivalent)
  • Own features end-to-end: database schema and API design through front-end UI to deployment and monitoring
  • Integrate LLM-based features, RAG pipelines, and agentic workflows into client-facing and internal products
  • Build and maintain CI/CD pipelines that include SAST, DAST, dependency auditing and secrets detection
  • Design AWS or GCP infrastructure with least-privilege IAM, network segmentation, encryption at rest and in transit, and audit logging

Using AI in engineering

  • Use AI coding assistants such as Claude Code, Cursor or Copilot in your daily development work
  • Build and improve internal AI tooling that accelerates audit workflows: automated recon agents, vulnerability classifiers, report drafters
  • Evaluate and harden AI/LLM-powered systems for clients, including testing for prompt injection, data leakage, and access control bypass
  • Document and improve our methods for using AI in security assessments

What We're Looking For

Must-Haves

  • 3 to 8+ years of professional software engineering experience, with meaningful time on both building and breaking web applications
  • Demonstrated ability to find and exploit real vulnerabilities in production systems: web apps, APIs, cloud environments
  • Strong full stack skills: comfortable owning a feature from Postgres to React and everything in between
  • Working knowledge of OWASP Top 10, common vulnerability classes (XSS, CSRF, IDOR, SSRF, SQLi, auth bypass), and at least one penetration testing framework (Burp Suite, OWASP ZAP, or equivalent)
  • Hands-on, daily use of AI coding tools in your current workflow: we will ask you to show us something you built or audited with AI assistance in the last 60 days
  • Ability to write clear, structured security reports that translate technical findings into business risk
  • Ability to work independently in a remote team that relies on written communication

Strong Preferences

  • Experience with cloud security on AWS or GCP: IAM, VPC configuration, CloudTrail / audit logging, container security
  • Familiarity with DevSecOps practices: integrating SAST/DAST into CI/CD, dependency scanning, secrets management
  • Background in security consulting, bug bounty programmes, or professional penetration testing engagements
  • Experience building or securing LLM-powered applications, RAG systems, or agentic workflows
  • Relevant certifications are a bonus but not required: OSCP, OSWE, CEH, AWS Security Specialty, or similar
  • Experience with compliance frameworks (SOC 2, ISO 27001, GDPR, HIPAA) in an audit or assessment context

Bonus Points

  • You've built your own security tooling: custom Burp extensions, automated scanners, AI-assisted recon
  • You've contributed to open-source security projects or published vulnerability research
  • You've worked in a consultancy environment managing multiple client engagements simultaneously
  • You can explain security findings to developers and discuss implementation with security teams

How We Work

Remote-first

Work from anywhere. We rely on written updates, keep meetings short and leave time for uninterrupted work.

AI-first

Every engineer uses AI tools daily for development and audits, and we regularly try new tools. We delegate routine work where the tools can handle it and focus our attention on engineering judgement and review.

Responsibility for your projects

You take a project from scoping through development, testing and launch, then support it. You also manage the client relationship on your engagements.

Client-facing

You'll interact directly with clients, present audit findings, and advise on remediation. Communication skills matter as much as technical ability.

Our Stack

We choose tools to suit each project. These are the ones we use most often:

Languages
TypeScript, Python, JavaScript, Bash
Frontend
React, Next.js, Tailwind CSS
Backend
Node.js, FastAPI, PostgreSQL, Redis
Cloud / Infra
AWS, GCP, Docker, Terraform, GitHub Actions
Security
Burp Suite, OWASP ZAP, Semgrep, Snyk, custom tooling
AI Tooling
Claude Code, Cursor, Copilot, custom LLM agents

Interview Process

The interview has three stages:

  1. 1

    Intro call(30 min)

    Tell us about your work. Show us something you've built or broken with AI tools.

  2. 2

    Technical exercise(async, paid)

    A realistic security assessment or build task. Use whatever tools you want, including AI.

  3. 3

    Working session(90 min)

    Pair with a team member on a real problem. We use the session to see how we work together as well as assess your technical skills.

  4. 4

    Offer

    We move fast when we find the right person.

How to Apply

Send an email to careers@vrg.asia and include:

  • Your CV or LinkedIn profile
  • A short note on the most interesting security finding or technical challenge you've worked on recently
  • A link to something you've built or shipped with AI tools in the last 60 days: GitHub, demo, write-up, anything
  • Optional: relevant certifications, bug bounty profiles, or published research

Please send examples of your work; a cover letter is optional.

VRG is an equal opportunity employer. We assess candidates through their engineering skills and work samples.