Talent.com
Paymentus
Senior Application Security EngineerPaymentus • Richmond Hill, York Region, Canada
Senior Application Security Engineer

Senior Application Security Engineer

Paymentus • Richmond Hill, York Region, Canada
30+ days ago
Job type
  • Full-time
Job description

The Senior Application Security Engineer is responsible for helping secure the Paymentus SaaS platform by partnering directly with software engineering, product, cloud infrastructure, DevOps, and security teams to identify, assess, and remediate application security risks across web applications, RESTful APIs, microservices, cloud-native services, and AI-enabled application components.

This is a hands‑on technical role reporting to the Manager of Platform Security. The Senior Application Security Engineer will perform secure design reviews, threat modeling, source code review, API security assessments, application security testing, vulnerability validation, and remediation guidance for applications and services that support Paymentus’ payment technology platform.

The successful candidate must have strong hands‑on software development experience, deep knowledge of modern application security, and the ability to work effectively with engineering teams to improve security without unnecessarily slowing product delivery. This role requires practical expertise in SaaS application security, RESTful API security, cloud‑native application patterns, secure coding, software supply chain risk, and emerging AI/LLM application security risks.

Supervisory Responsibility

This role does not have direct supervisory responsibility.

The Senior Application Security Engineer is expected to provide technical leadership, mentorship, and guidance to software engineers, security engineers, and other technical stakeholders. This includes helping engineering teams understand security risks, adopt secure coding practices, and remediate application security issues effectively.

Education and Experience

  • Bachelor’s Degree in Engineering, Computer Science, Software Engineering, Information Security, or a related technical field, or equivalent practical experience.
  • 6+ years of experience in software engineering, application security, product security, platform security, security engineering, or a closely related technical role.
  • Extensive hands‑on development experience in one or more of the following languages: Java, NodeJS, Python, Golang.
  • Strong understanding of modern SaaS application architecture, web applications, microservices, distributed systems, RESTful APIs, authentication, authorization, session management, secure data handling, and service‑to‑service communication.
  • Deep knowledge of application security vulnerabilities and secure remediation patterns.
  • Strong knowledge of API security risks, including broken object‑level authorization, broken function‑level authorization, excessive data exposure, mass assignment, unrestricted resource consumption, improper inventory management, and unsafe third‑party API consumption.
  • Strong understanding of modern application security guidelines, including OWASP Top 10, OWASP API Security Top 10, and OWASP Top 10 for Large Language Model Applications.
  • Practical knowledge of AI and LLM application security risks, including prompt injection, insecure output handling, sensitive data exposure, insecure plugin/tool usage, model misuse, excessive agency, and AI supply chain concerns.
  • Hands‑on experience performing secure code review, threat modeling, architecture review, vulnerability validation, and security testing.
  • Experience using and tuning application security tools such as SAST, DAST, SCA, container scanning, IaC scanning, secrets scanning, and API security testing tools.
  • Experience securing applications deployed in one or more public cloud environments, including AWS, GCP, or Azure.
  • Knowledge of Kubernetes, containerization, container registries, container image hardening, workload identity, secrets management, network policies, and runtime security concepts.
  • Knowledge of serverless application security, including function permissions, event validation, input handling, logging, dependency control, and abuse prevention.
  • Familiarity with application servers, web servers, and reverse proxy technologies such as Tomcat, JBoss, nginx, or similar platforms.
  • Familiarity with CDN, WAF, bot mitigation, rate limiting, and edge security controls using platforms such as Cloudflare and Fastly.
  • Experience working with CI/CD pipelines, source control systems, artifact repositories, build systems, infrastructure as code, and developer workflow automation.
  • Ability to analyze security findings, determine exploitability, identify root cause, and recommend practical remediation steps.
  • Ability to work independently, manage multiple priorities, and deliver high‑quality results in a fast‑paced engineering environment.
  • Strong written and verbal communication skills, including the ability to explain security issues clearly to technical and non‑technical stakeholders.
  • Strong collaboration skills and the ability to build trusted working relationships with engineering, product, DevOps, cloud infrastructure, compliance, and security teams.

Preferred Qualifications

  • Experience working in fintech, payments, banking, financial services, or another highly regulated SaaS environment.
  • Experience with payment processing, cardholder data environments, tokenization, fraud controls, transaction platforms, or payment APIs.
  • Experience supporting PCI DSS, SOC 2, SOX technology controls, NIST CSF, ISO 27001, or similar security and compliance frameworks.
  • Experience with Spring Security, Java security libraries, OAuth 2.0, OIDC, SAML, JWT, mTLS, API gateways, and service‑to‑service authentication patterns.
  • Experience with Kubernetes admission controls, service mesh security, policy-as-code, runtime detection, and cloud workload protection platforms.
  • Experience building secure shared libraries, developer security tooling, reusable security controls, or paved‑road security patterns.
  • Experience with bug bounty programs, red team engagements, penetration testing, or exploit development.
  • Relevant certifications such as CSSLP, CISSP, CCSP, GWAPT, GWEB, OSWE, AWS Security Specialty, Google Professional Cloud Security Engineer, Azure Security Engineer, CKS, CKAD, or equivalent practical experience.

EEO Statement

Paymentus is an equal opportunity employer. We enthusiastically accept our responsibility to make employment decisions without regard to race, religious creed, color, age, sex, sexual orientation, national origin, ancestry, citizenship status, religion, marital status, disability, military service or veteran status, genetic information, medical condition including medical characteristics, or any other classification protected by applicable federal, state, provincial, and local laws and ordinances. Our management is dedicated to ensuring the fulfillment of this policy with respect to hiring, placement, promotion, transfer, demotion, layoff, termination, recruitment advertising, pay, and other forms of compensation, training, and general treatment during employment.

Reasonable Accommodation

Paymentus recognizes and supports its obligation to endeavor to accommodate job applicants and employees with known physical or mental disabilities who are able to perform the essential functions of the position, with or without reasonable accommodation. Paymentus will endeavor to provide reasonable accommodations to otherwise qualified job applicants and employees with known physical or mental disabilities, unless doing so would impose an undue hardship on the Company or pose a direct threat of substantial harm to the employee or others.

An applicant or employee who believes he or she needs a reasonable accommodation of a disability should discuss the need for possible accommodation with the Human Resources Department, or his or her direct supervisor.

#J-18808-Ljbffr

Create a job alert for this search

Senior Application Security Engineer • Richmond Hill, York Region, Canada

Similar jobs

Application Security Engineer - C$60 - C$67 An Hour

HireTalent - Staffing & Recruiting FirmToronto County, Canada
Full-time

Seeking a Cyber Security expert to recertify third-party connections, ensuring compliance with encryption requirements by supporting IT Application owners and investigating data flow. Show more

 • Promoted

Senior Application Security Developer - C$146,200 - C$197,800 A Year

ClioToronto County, Canada
Full-time

Develops and implements security tools, remediates vulnerabilities, and provides guidance to teams, ensuring application security. Show more

 • Promoted

Senior Security Engineer - C$130,000 - C$160,000 A Year

OpenTableEast York, Canada
Full-time

Seeking a Security Engineer to conduct threat modeling, security design reviews, and risk assessments for applications and APIs.Role involves building automation, assisting in incident response, an... Show more

 • Promoted

Senior Application Security Engineer - C$192,000 - C$240,000 A Year

BrexToronto County, Canada
Full-time

Seeking a Senior Application Security Engineer to identify and respond to security vulnerabilities across the Brex platform.Responsibilities include code reviews, penetration testing, and developin... Show more

 • Promoted

Senior Specialist Application Security - $122,305 - $163,639 A Year

ipss inc.Toronto, Canada
Full-time +1

Job Title: Senior Specialist Application SecurityDivision: Office of the Chief Information Security OfficerReports To: Manager Application SecuritySalary Range:$122,305 to $163,639Work Location:55 ... Show more

 • Promoted

Lead Application Security Engineer At Opendoor

Segment (Twilio)Toronto, Canada
Full-time

Step into a leadership position as a Lead Application Security Engineer at Opendoor, where you'll shape the future of secure software development.Automate security processes while mentoring eng... Show more

 • Promoted

Senior Application Security Engineer

PaymentusRichmond Hill, York region, Canada
Full-time

Senior Application Security Engineer.Paymentus SaaS platform by partnering directly with software engineering, product, cloud infrastructure, DevOps, and security teams to identify, assess, and rem... Show more

 • Promoted

Senior Application Security Engineer

CognizantToronto, Ontario, Canada
Full-time

Job Title - App Security Specialist.DevOps, with at least 2 - 3 years hands-on security exposure (secure coding, pipeline security, API security, threat modeling).Seniority level: Mid-Senior level.... Show more

 • Promoted

Application Engineer - Security Tech Solutions (Remote)

SICK Sensor IntelligenceToronto, Ontario, Canada
Remote

Sie entwickeln Applikationslösungen im Bereich Sicherheitstechnik.Bewerber benötigen ein Studium in Elektrotechnik und Erfahrung in der Elektrokonstruktion sowie gute Englischkenntnisse. Show more

 • Promoted

Sr. Application Security Engineer - $150,000 - $190,000 A Year - Remote

vCluster LabsToronto County, Canada
Remote
Full-time

Responsible for end-to-end security of a Kubernetes multi-tenancy product, including security reviews, threat modeling, vulnerability management, and developer training. Show more

 • Promoted

Staff Application Security Engineer - $221,000 - $286,000 A Year

ThumbtackToronto County, Canada
Full-time

Lead application security initiatives, design secure architectures, and mentor engineers to enhance Thumbtack's security posture and enable innovation at scale. Show more

 • Promoted

Senior Security Engineer, Bug Bounty

MozillaToronto, Ontario, Canada
Full-time

About This Team And Role At Mozilla, we believe the internet is a global public resource—open and accessible to all.As a Security Engineer, you’ll protect that vision by building, breaking, and har... Show more

 • Promoted

Senior Appsec Engineer: Build Secure, Ai-Driven Apps - C$146,200 - C$197,800 A Year

Leading Legal Tech CompanyToronto County, Canada
Full-time

Seeking a Senior Application Security Developer for a legal tech company to build tools for security flaw prevention and vulnerability remediation.Requires programming experience. Show more

 • Promoted

Senior Appsec Engineer: Build Secure, Ai-Driven Apps - C$146,200 - C$197,800 A Year

Legal Tech CompanyToronto, Canada
Full-time

A leading legal tech company is seeking a Senior Application Security Developer to enhance its security team.The role involves developing tools to prevent security flaws and support vulnerability r... Show more

 • Promoted

Senior Security Engineer

RootlyToronto, Canada
Full-time

OverviewAbout Rootly: At Rootly, we are on a mission to be the go-to way companies respond when things go wrong, helping every organization be more reliable.We do this by building an industry-leadi... Show more

 • Promoted

Senior Application Security Engineer - C$131,500 - C$155,000 A Year

Spring FinancialToronto County, Canada
Full-time

Senior Application Security Engineer responsible for leading technical efforts to secure software systems, embedding security best practices, and mentoring engineers.Focuses on secure development l... Show more

 • Promoted

Senior Application Security Specialist

AIR MILES Reward ProgramToronto, Ontario, Canada
Full-time

The AIR MILES Reward Program is one of Canada’s most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households.AIR MILES co... Show more

 • Promoted

Application Security, Lead - C$120,000 - C$140,000 A Year

InteracToronto, Canada
Full-time

Who We Are:**Every transaction matters.At Interac, we protect both — driving trust, security, and inclusion, so our digital economy thrives.Founded in 1984, Interac connects Canadians through secur... Show more

 • Promoted

Application Security Software Engineer

PointClickCareToronto
Full-time

This range is provided by PointClickCare.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.PointClickCare is a leading North American healthcare t... Show more

 • Promoted

Senior Application Security Engineer — Ai & Pen Testing (Hybrid) - C$192,000 - C$240,000 A Year

Fintech CompanyToronto, Canada
Full-time

A leading fintech company is seeking a Senior Application Security Engineer in Vancouver, BC.This role focuses on finding and addressing vulnerabilities across the platform, performing penetration ... Show more