Loading this job…
This is the one engineering seat we hire globally, and the only hard requirement is four hours of daily overlap with India Standard Time. Everything else, including how the three-month schedule is arranged, bends around wherever you happen to live.
Authentication at MailerMen runs on ASP.NET Core Identity with JWT bearer tokens, and it has picked up the usual scar tissue: refresh tokens that never expire, a password reset flow with a race condition in it, and role checks scattered through controllers instead of expressed as policies. You help clean up all three. Later in the term you implement OAuth sign in for employer accounts and write the threat model document that should have existed before any of this was built.
You are paired with our security-minded backend engineer for a weekly hour that is yours to direct, plus asynchronous review on every pull request you open. You will read other people's code as often as you write your own, which happens to be the fastest way anybody learns this particular subject. No prior security work is expected, only curiosity and care.
MailerMen runs a verified job board covering startup and product roles across twelve markets, and takes on interns across engineering, data, design and marketing to build it.