Summary/Objective
The Manager of Platform Security is responsible for leading a team of security engineers focused on the security of the Paymentus SaaS platform, including web applications, RESTful APIs, cloud-native services, containerized workloads, serverless functions, and AI-enabled application components. This role owns the execution of application and platform security engineering practices across the software development lifecycle and partners closely with Engineering, Product, DevOps, Cloud Infrastructure, Compliance, and Security Operations to identify, prioritize, and remediate security risks before they impact Paymentus customers, partners, or regulated payment environments.
The successful candidate must combine strong people leadership with deep hands-on technical expertise. This is not a purely governance or advisory role. The individual must be capable of reviewing application architecture, assessing source code and API implementations, challenging insecure design decisions, guiding engineers through secure remediation, and building scalable security controls for modern SaaS platforms.
Essential Functions/ Responsibilities
- Lead, manage, mentor, and develop a team of platform and application security engineers responsible for securing the Paymentus SaaS platform.
- Build and mature the platform security program across application security, API security, cloud security, container security, Kubernetes security, serverless security, and AI application security.
- Partner with software engineering teams to embed security into the full SDLC, including requirements, architecture, design reviews, threat modeling, secure coding, automated testing, deployment, monitoring, and remediation.
- Provide hands-on technical leadership for security reviews of applications and services written primarily in Java, NodeJS, Python, and Golang.
- Assess and guide security design for applications and frameworks including Spring, Struts, Express, Flask, Django, FastAPI, LiteLLM, and related open-source and commercial frameworks.
- Review and advise on secure configuration and deployment patterns for application servers and web infrastructure, including Tomcat, JBoss, nginx, reverse proxies, gateways, and edge delivery services.
- Lead security assessment and control development for public cloud environments across AWS, GCP, and Azure, including identity and access management, network controls, encryption, secrets management, workload isolation, logging, and detection capabilities.
- Define and enforce security standards for Kubernetes, containerized workloads, container registries, CI/CD pipelines, infrastructure as code, admission controls, service mesh patterns, and runtime security.
- Define and enforce security standards for serverless technologies, including secure function design, least-privilege execution roles, event-source validation, dependency control, logging, and abuse prevention.
- Drive secure architecture and security control reviews for RESTful APIs, internal APIs, partner APIs, authentication flows, authorization models, service-to-service communication, rate limiting, input validation, API gateways, and abuse-prevention controls.
- Establish and mature security practices aligned with modern application security guidance, including OWASP Top 10, OWASP API Security Top 10, and OWASP Top 10 for Large Language Model Applications.
- Lead security risk assessments for AI-enabled application components, including prompt injection, insecure output handling, sensitive information disclosure, model abuse, excessive agency, insecure plugin and tool integrations, data leakage, and AI supply chain risks.
- Develop secure design patterns and engineering guardrails for applications using LLM gateways, model orchestration layers, retrieval-augmented generation, AI agents, and third-party AI services.
- Own and improve application security testing capabilities, including SAST, DAST, SCA, container image scanning, IaC scanning, secrets detection, API security testing, dependency governance, and manual security reviews.
- Ensure security tooling is effectively integrated into CI/CD pipelines with risk-based gates, actionable findings, developer-friendly feedback loops, and measurable remediation outcomes.
- Lead the application vulnerability management process for the platform, including triage, severity validation, exploitability analysis, remediation guidance, exception review, SLA tracking, and executive reporting.
- Partner with Engineering and Product leadership to prioritize security work based on business risk, customer impact, regulatory obligations, exploitability, and platform architecture.
- Support penetration testing, red team exercises, bug bounty intake, customer security reviews, and independent assessments related to the Paymentus platform.
- Collaborate with Security Operations and Incident Response teams on application-layer detections, attack-path analysis, logging requirements, incident investigations, and post-incident remediation.
- Develop and maintain platform security standards, secure coding guidelines, architecture patterns, control baselines, and security review procedures.
- Provide technical consultations on CDN, WAF, bot mitigation, API protection, DDoS protection, caching, edge security, and traffic management controls using technologies such as Cloudflare and Fastly.
- Establish metrics and reporting for platform security posture, including vulnerability trends, remediation performance, secure SDLC adoption, security testing coverage, risk exceptions, and engineering engagement.
- Support compliance and audit obligations relevant to a publicly traded fintech and payment technology company, including PCI DSS, SOC 2, SOX-related technology controls, privacy obligations, customer security commitments, and internal security policies.
- Attract, hire, develop, and retain high-performing security engineering talent.
- Keep current with emerging application security, cloud security, AI security, API security, software supply chain, and attacker tradecraft trends, and translate those trends into practical improvements for the Paymentus platform.
Supervisory Responsibility
This role has direct supervisory responsibility for a team of security engineers. Responsibilities include hiring, onboarding, performance management, coaching, technical mentorship, career development, workload prioritization, project delivery, and talent retention. The Manager of Platform Security is expected to build a strong engineering-oriented security culture that balances risk reduction, developer enablement, operational excellence, and business velocity.
Education and Experience
- Bachelors Degree in Computer Science, Software Engineering, Computer Engineering, Information Security, or a related technical field, or equivalent practical experience.
- 8+ years of combined experience in software engineering, application security, product security, platform security, cloud security, or security engineering.
- 3+ years of experience managing or technically leading security engineers, software engineers, or platform engineering teams.
- Extensive hands-on software development experience in one or more of the following languages: Java, NodeJS, Python, Golang.
- Deep technical knowledge of modern web application architecture, SaaS platforms, microservices, distributed systems, RESTful APIs, authentication, authorization, session management, secure data handling, and service-to-service communication.
- Strong knowledge of application security vulnerabilities and secure remediation patterns, including injection flaws, broken access control, authentication weaknesses, insecure deserialization, SSRF, XXE, XSS, CSRF, business logic flaws, insecure file handling, and supply chain risks.
- Strong knowledge of API security risks, including broken object-level authorization, broken function-level authorization, excessive data exposure, mass assignment, unrestricted resource consumption, improper inventory management, and unsafe API integrations.
- Strong knowledge of AI and LLM application security risks, including prompt injection, insecure output handling, sensitive data exposure, model misuse, insecure tool use, plugin risk, excessive agency, and AI supply chain concerns.
- Hands-on experience securing cloud environments in one or more major public cloud platforms: AWS, GCP, Azure.
- Hands-on experience with Kubernetes, containers, container registries, image hardening, workload identity, network policies, secrets management, runtime controls, and deployment security.
- Experience securing CI/CD pipelines and developer workflows, including source control, build systems, artifact repositories, automated testing, release gates, and infrastructure as code.
- Experience with security testing tools and practices, including SAST, DAST, SCA, container scanning, IaC scanning, secrets scanning, API testing, manual code review, and threat modeling.
- Experience working with Engineering and Product teams to resolve complex security issues without unnecessarily blocking delivery.
- Strong analytical skills with the ability to quickly identify root cause, exploitability, compensating controls, and appropriate remediation paths.
- Strong written and verbal communication skills, including the ability to explain technical security issues to engineers and risk-based business impact to executives.
- Strong organizational and prioritization skills, including experience delivering multiple concurrent security initiatives in a fast-moving engineering environment.
Preferred Qualifications
- Experience working in fintech, payments, banking, financial services, or another highly regulated SaaS environment.
- Experience with PCI DSS, SOC 2, SOX technology controls, NIST CSF, ISO 27001, or similar control frameworks.
- Experience with payment systems, payment processing, tokenization, cardholder data environments, fraud controls, or high-volume transaction platforms.
- Experience with CDN, WAF, bot mitigation, rate limiting, API gateway, and edge security platforms such as Cloudflare and Fastly.
- Experience with application servers and runtime platforms such as Tomcat, JBoss, nginx, JVM-based applications, NodeJS services, Python services, and Go services.
- Experience with frameworks and platforms such as Spring, Struts, Express, LiteLLM, and modern LLM integration frameworks.
- Experience developing security paved roads, reusable secure libraries, shared platform controls, secure service templates, policy-as-code, or developer self-service security capabilities.
- Experience building security metrics, executive dashboards, remediation scorecards, and risk-based reporting.
- Relevant certifications such as CISSP, CSSLP, CCSP, AWS Security Specialty, Google Professional Cloud Security Engineer, Azure Security Engineer, CKS, CKAD, OSWE, GWAPT, GWEB, or equivalent practical experience.
Work Environment
This job operates in a professional office and technology environment. This role routinely uses standard office and engineering equipment, including laptop computers, collaboration tools, cloud platforms, security platforms, source code repositories, ticketing systems, and communication systems. The role requires frequent collaboration with geographically distributed teams and may involve participation in security incident response, urgent vulnerability remediation, production risk reviews, and executive briefings.
Physical Demands
While performing the duties of this job, the employee is regularly required to talk, hear, type, read, and view computer screens for extended periods. Specific vision abilities required by this job include close vision and the ability to adjust focus. The employee may occasionally be required to stand, walk, reach with hands and arms, lift files or equipment, open filing cabinets, bend, or stand on a stool as necessary. The employee may occasionally be required to lift up to 25 lbs.
Position Type/Expected Hours of Work
This is a full-time position. Days and hours of work are generally Monday through Friday during normal business hours. Occasional evening, weekend, or on-call work may be required based on business needs, security incidents, critical vulnerabilities, production releases, audit deadlines, or customer commitments.
Travel
Minimal travel is expected. Occasional travel may be required for company meetings, team events, customer security discussions, conferences, audits, or vendor engagements.
Other Duties
This job description is not designed to cover or contain a comprehensive listing of all activities, duties, or responsibilities required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.
EEO Statement
Paymentus is an equal opportunity employer. We enthusiastically accept our responsibility to make employment decisions without regard to race, religious creed, color, age, sex, sexual orientation, national origin, ancestry, citizenship status, religion, marital status, disability, military service or veteran status, genetic information, medical condition including medical characteristics, or any other classification protected by applicable federal, state, provincial, and local laws and ordinances. Our management is dedicated to ensuring the fulfillment of this policy with respect to hiring, placement, promotion, transfer, demotion, layoff, termination, recruitment advertising, pay, and other forms of compensation, training, and general treatment during employment.
Reasonable Accommodation
Paymentus recognizes and supports its obligation to endeavor to accommodate job applicants and employees with known physical or mental disabilities who are able to perform the essential functions of the position, with or without reasonable accommodation. Paymentus will endeavor to provide reasonable accommodations to otherwise qualified job applicants and employees with known physical or mental disabilities, unless doing so would impose an undue hardship on the Company or pose a direct threat of substantial harm to the employee or others.
An applicant or employee who believes he or she needs a reasonable accommodation of a disability should discuss the need for possible accommodation with the Human Resources Department, or his or her direct supervisor.