Senior Product Security Engineer

6 hours, 53 minutes ago
Full-time
Senior
Cybersecurity
payabl.

payabl.

payabl. empowers merchants to handle payments on a global scale by offering a comprehensive solution that includes card acquiring, alternative payment methods, payment accounts, and prepaid cards.

Diversified Financial Services
51-250
Founded 2011

Description

  • Design and introduce security gates, secure release practices, and guardrails throughout the development lifecycle.
  • Lead threat modeling and secure-by-design reviews for new products and major changes.
  • Advise on secure architecture for card issuing, embedded finance, banking-as-a-service, and payment products.
  • Define secure-by-default application patterns for authentication, authorization, APIs, and service-to-service trust.
  • Select and operate application security tooling, including AI-assisted solutions where appropriate.
  • Own CI/CD pipeline and software supply-chain security controls across engineering teams.
  • Implement container scanning, dependency management, software bills of materials, and infrastructure-as-code security checks.
  • Introduce AI agents and LLM-assisted workflows into application security operations.
  • Drive remediation of findings from penetration tests, security scanners, and disclosure reports with engineering teams.

Requirements

  • 5+ years of Product Security or Application Security experience in payments, fintech, banking, e-money, or a similar environment.
  • Strong hands-on experience embedding security into the software development lifecycle.
  • Ability to read code and participate effectively in design discussions with senior engineers.
  • Experience with threat modeling, secure-by-design reviews, and architecture and delivery engagements.
  • Hands-on experience with SAST, SCA, secrets detection, and DAST tooling.
  • Experience securing cloud-native applications on AWS or another major cloud platform.
  • Strong AI proficiency, including agentic workflows, RAG, MCP, or similar technologies.
  • Understanding of cloud-first environments and modern development practices.
  • Experience securing CI/CD pipelines and improving software supply-chain security.
  • Strong ownership, communication, and influence skills, with strong written and verbal English.
  • Experience with cloud-native or API-driven product launches, security-as-code, or detection-as-code preferred.
  • Penetration testing or offensive security experience preferred.
  • CISSP, CSSLP, CCSP, OSCP, or similar certification preferred.

Benefits

  • Fully remote work from Portugal or Poland.
  • Annual professional development budget after probation.
  • Company celebrations bringing colleagues from all offices together.
  • Opportunities to participate in international company events and initiatives.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Application Security Engineer - Senior

Banco Plata, S.A., Institución de Banca Múltiple. 1001-5000 Banking / financial services

Plata is seeking an Application Security Engineer to join its Information Security team and embed security controls, testing, and practices throughout the software development lifecycle.

Burp Suite CI/CD Kubernetes Microservices OWASP Penetration Testing
6 hours, 38 minutes ago

Senior Product Security Engineer (Contract)

Iru Enterprise IT, cybersecurity, identity/security, endpoint management, compliance software

Iru is seeking a Senior Product Security Engineer for a 6-month, 40-hour-per-week contract to embed security throughout the software development lifecycle and help teams build secure-by-design products.

AWS Azure GCP GitHub Actions Kubernetes Microservices OAuth OpenID Connect
2 days, 5 hours ago

Senior Application Security Engineer

Radicle Health 11-50 Internet Software & Services

Radicle Health is seeking a Senior Application Security Engineer to strengthen security across its 10 SaaS platforms by integrating security tooling and practices into software development and operations.

AWS HIPAA OWASP Penetration Testing
2 days, 6 hours ago

Lead Security Engineer - Penetration Testing & AI Security

HighLevel 251-1K Internet Software & Services

HighLevel is seeking a Lead Security Engineer to secure its SaaS platform and AI-enabled products through application security leadership, secure development practices, and adversarial testing of AI systems.

Bash CI/CD Cybersecurity DevSecOps Docker Go JavaScript JWT Kubernetes Microservices OpenID Connect OWASP Penetration Testing Python SAML
1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers