Senior Application Security Engineer
Paymentus — Canada · Posted ~1 day ago
🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.
Log in to add to target listDescription
Summary/Objective
The Senior Application Security Engineer is responsible for helping secure the Paymentus SaaS platform by partnering directly with software engineering, product, cloud infrastructure, DevOps, and security teams to identify, assess, and remediate application security risks across web applications, RESTful APIs, microservices, cloud-native services, and AI-enabled application components.
This is a hands-on technical role reporting to the Manager of Platform Security.
The Senior Application Security Engineer will perform secure design reviews, threat modeling, source code review, API security assessments, application security testing, vulnerability validation, and remediation guidance for applications and services that support Paymentus’ payment technology platform.
The successful candidate must have strong hands-on software development experience, deep knowledge of modern application security, and the ability to work effectively with engineering teams to improve security without unnecessarily slowing product delivery.
This role requires practical expertise in SaaS application security, RESTful API security, cloud-native application patterns, secure coding, software supply chain risk, and emerging AI/LLM application security risks.
Supervisory Responsibility
This role does not have direct supervisory responsibility.
The Senior Application Security Engineer is expected to provide technical leadership, mentorship, and guidance to software engineers, security engineers, and other technical stakeholders.
This includes helping engineering teams understand security risks, adopt secure coding practices, and remediate application security issues effectively.
Education and Experience
Bachelor’s Degree in Engineering, Computer Science, Software Engineering, Information Security, or a related technical field, or equivalent practical experience.6+ years of experience in software engineering, application security, product security, platform security, security engineering, or a closely related technical role.Extensive hands-on development experience in one or more of the following languages: Java, NodeJS, Python, Golang.Strong understanding of modern SaaS application architecture, web applications, microservices, distributed systems, RESTful APIs, authentication, authorization, session management, secure data handling, and service-to-service communication.Deep knowledge of application security vulnerabilities and secure remediation patterns.Strong knowledge of API security risks, including broken object-level authorization, broken function-level authorization, excessive data exposure, mass assignment, unrestricted resource consumption, improper inventory management, and unsafe third-party API consumption.Strong understanding of modern application security guidelines, including OWASP Top 10, OWASP API Security Top 10, and OWASP Top 10 for Large Language Model Applications.Practical knowledge of AI and LLM application security risks, including prompt injection, insecure output handling, sensitive data exposure, insecure plugin/tool usage, model misuse, excessive agency, and AI supply chain concerns.Hands-on experience performing secure code review, threat modeling, architecture review, vulnerability validation, and security testing.Experience using and tuning application security tools such as SAST, DAST, SCA, container scanning, IaC scanning, secrets scanning, and API security testing tools.Experience securing applications deployed in one or more public cloud environments, including AWS, GCP, or Azure.Knowledge of Kubernetes, containerization, container registries, container image hardening, workload identity, secrets management, network policies, and runtime security concepts.Knowledge of serverless application security, including function permissions, event validation, input handling, logging, dependency control, and abuse prevention.Familiarity with application servers, web servers, and reverse proxy technologies such as Tomcat, JBoss, nginx, or similar platforms.Familiarity with CDN, WAF, bot mitigation, rate limiting, and edge security controls using platforms such as Cloudflare and Fastly.Experience working with CI/CD pipelines, source control systems, artifact repositories, build systems, infrastructure as code, and developer workflow automation.Ability to analyze security findings, determine exploitability, identify root cause, and recommend practical remediation steps.Ability to work independently, manage multiple priorities, and deliver high-quality results in a fast-paced engineering environment.Strong written and verbal communication skills, including the ability to explain security issues clearly to technical and non-technical stakeholders.Strong collaboration skills and the ability to build trusted working relationships with engineering, product, DevOps, cloud infrastructure, compliance, and security teams.Preferred Qualifications
Experience working in fintech, payments, banking, financial services, or another highly regulated SaaS environment.Experience with payment processing, cardholder data environments, tokenization, fraud controls, transaction platforms, or payment APIs.Experience supporting PCI DSS, SOC 2, SOX technology controls, NIST CSF, ISO 27001, or similar security and compliance frameworks.Experience with Spring Security, Java security libraries, OAuth 2.0, OIDC, SAML, JWT, mTLS, API gateways, and service-to-service authentication patterns.Experience with Kubernetes admission controls, service mesh security, policy-as-code, runtime detection, and cloud workload protection platforms.Experience building secure shared libraries, developer security tooling, reusable security controls, or paved-road security patterns.Experience with bug bounty programs, red team engagements, penetration testing, or exploit development.Relevant certifications such as CSSLP, CISSP, CCSP, GWAPT, GWEB, OSWE, AWS Security Specialty, Google Professional Cloud Security Engineer, Azure Security Engineer, CKS, CKAD, or equivalent practical experience.
EEO Statement
Paymentus is an equal opportunity employer.
We enthusiastically accept our responsibility to make employment decisions without regard to race, religious creed, color, age, sex, sexual orientation, national origin, ancestry, citizenship status, religion, marital status, disability, military service or veteran status, genetic information, medical condition including medical characteristics, or any other classification protected by applicable federal, state, provincial, and local laws and ordinances.
Our management is dedicated to ensuring the fulfillment of this policy with respect to hiring, placement, promotion, transfer, demotion, layoff, termination, recruitment advertising, pay, and other forms of compensation, training, and general treatment during employment.
Reasonable Accommodation
Paymentus recognizes and supports its obligation to endeavor to accommodate job applicants and employees with known physical or mental disabilities who are able to perform the essential functions of the position, with or without reasonable accommodation.
Paymentus will endeavor to provide reasonable accommodations to otherwise qualified job applicants and employees with known physical or mental disabilities, unless doing so would impose an undue hardship on the Company or pose a direct threat of substantial harm to the employee or others.
An applicant or employee who believes he or she needs a reasonable accommodation of a disability should discuss the need for possible accommodation with the Human Resources Department, or his or her direct supervisor.
We have 61,141 jobs that might be an even better fit for you
DontApply's real value goes far beyond a single job link or company name. Just upload your resume — in under a minute we'll analyze all 61,141 jobs and tell you exactly which ones you should apply to right now.
Upload My Resume