Senior Product Security Engineer
Brak informacji o wynagrodzeniu
SeniorFull-time
#438819·Dodano wczoraj·0
Źródło: payabl.Tech Stack / Keywords
product securityapplication securitythreat modellingSASTSCADASTAWSCI/CDsoftware supply-chain securityAI
Firma i stanowisko
We're powering the growth of merchants by helping them take payments easily, securely and globally.
Wymagania
- 5+ years of experience in Product Security or Application Security in payments, fintech, banking, e-money, or related fintech environments.
- Strong hands-on experience embedding security into the software development lifecycle.
- Comfortable reading code and participating in design discussions with senior engineers.
- Proven experience with threat modelling, secure-by-design reviews, and collaborative work during architecture and delivery stages.
- Hands-on experience with application security tooling such as SAST, SCA, secrets detection, and DAST.
- Hands-on experience securing cloud-native applications on AWS or other major clouds.
- Strong AI proficiency with hands-on experience in agentic workflows, RAG, MCP, etc.
- Solid understanding of Cloud-first environments and modern development practices.
- Experience securing CI/CD pipelines and enhancing software supply-chain security.
- Ability to work directly with engineering teams to influence secure delivery beyond policy.
- Strong ownership mindset to define, implement, improve, and drive adoption of security practices across teams.
- Strong written and verbal English skills.
Nice to have:
- Experience supporting new product launches in cloud-native or API-driven environments.
- Detection-as-code or security-as-code mindset.
- Penetration testing or offensive security background.
- Certifications such as CISSP, CSSLP, CCSP, or OSCP.
Obowiązki
- Design and introduce security gates into the development lifecycle, including embedded secure release practices and guardrails.
- Lead threat modelling for new products and major changes.
- Provide secure-by-design input for new product builds across card issuing, embedded finance / banking-as-a-service, and other payment products.
- Define secure-by-default architecture patterns for authentication, authorization, API design, and service-to-service trust.
- Decide on the appropriate use of traditional tooling versus AI-assisted alternatives.
- Own CI/CD pipeline and software supply-chain security controls.
- Implement and improve container image scanning, dependency management, software bill of materials, and security checks on infrastructure-as-code and deployment manifests.
- Introduce AI agents and LLM-assisted workflows as the default for application security.
- Drive remediation of application-layer findings from penetration tests, scanners, and disclosure reports with engineering teams.
Benefity
- Annual Learning Budget for professional development after probation.
- Company celebrations bringing colleagues from all offices together.
- Opportunities to participate in international company events and initiatives.
Dofinansowanie szkoleń
Spotkania integracyjne
Inne informacje
Location: Fully remote from Portugal or Poland.
payabl
13 aktywnych ofert