Manager of Platform Security (Richmond Hill)

Manager of Platform Security (Richmond Hill)

05 Aug
|
Paymentus
|
Richmond Hill

05 Aug

Paymentus

Richmond Hill

The Manager of Platform Security is responsible for leading a team of security engineers focused on the security of the Paymentus SaaS platform, including web applications, RESTful APIs, cloud-native services, containerized workloads, serverless functions, and AI-enabled application components. This role owns the execution of application and platform security engineering practices across the software development lifecycle and partners closely with Engineering, Product, DevOps, Cloud Infrastructure, Compliance, and Security Operations to identify, prioritize, and remediate security risks before they impact Paymentus customers, partners, or regulated payment environments.

Essential Functions/ Responsibilities

- Lead, manage, mentor, and develop a team of platform and application security engineers responsible for securing the Paymentus SaaS platform.
- Build and mature the platform security program across application security, API security, cloud security, container security, Kubernetes security, serverless security, and AI application security.
- Partner with software engineering teams to embed security into the full SDLC, including requirements, architecture, design reviews, threat modeling, secure coding, automated testing, deployment, monitoring, and remediation.
- Provide hands‑on technical leadership for security reviews of applications and services written primarily in Java, NodeJS, Python, and Golang.
- Assess and guide security design for applications and frameworks including Spring, Struts, Express, Flask, Django, FastAPI, LiteLLM, and related open‑source and commercial frameworks.
- Review and advise on secure configuration and deployment patterns for application servers and web infrastructure, including Tomcat, JBoss, nginx, reverse proxies, gateways, and edge delivery services.
- Lead security assessment and control development for public cloud environments across AWS, GCP, and Azure, including identity and access management, network controls, encryption, secrets management, workload isolation, logging, and detection capabilities.
- Define and enforce security standards for Kubernetes, containerized workloads, container registries, CI/CD pipelines, infrastructure as code, admission controls, service mesh patterns, and runtime security.
- Drive secure architecture and security control reviews for RESTful APIs, internal APIs, partner APIs, authentication flows, authorization models, service-to-service communication, rate limiting, input validation, API gateways, and abuse‑prevention controls.
- Establish and mature security practices aligned with modern application security guidance, including OWASP Top 10, OWASP API Security Top 10, and OWASP Top 10 for Large Language Model Applications.
- Lead security risk assessments for AI‑enabled application components, including prompt injection, insecure output handling, sensitive information disclosure, model abuse, excessive agency, insecure plugin and tool integrations, data leakage, and AI supply chain risks.
- Develop secure design patterns and engineering guardrails for applications using LLM gateways, model orchestration layers, retrieval‑augmented generation, AI agents, and third‑party AI services.
- Own and improve application security testing capabilities, including SAST, DAST, SCA, container image scanning, IaC scanning, secrets detection, API security testing, dependency governance, and manual security reviews.




- Ensure security tooling is effectively integrated into CI/CD pipelines with risk‑based gates, actionable findings, developer‑friendly feedback loops, and measurable remediation outcomes.
- Lead the application vulnerability management process for the platform, including triage, severity validation, exploitability analysis, remediation guidance, exception review, SLA tracking, and executive reporting.
- Partner with Engineering and Product leadership to prioritize security work based on business risk, customer impact, regulatory obligations, exploitability, and platform architecture.
- Support penetration testing, red team exercises, bug bounty intake, customer security reviews, and independent assessments related to the Paymentus platform.
- Collaborate with Security Operations and Incident Response teams on application‑layer detections, attack‑path analysis, logging requirements, incident investigations, and post‑incident remediation.
- Develop and maintain platform security standards, secure coding guidelines, architecture patterns, control baselines, and security review procedures.
- Provide technical consultations on CDN, WAF, bot mitigation, API protection, DDoS protection, caching, edge security, and traffic management controls using technologies such as Cloudflare and Fastly.
- Establish metrics and reporting for platform security posture, including vulnerability trends, remediation performance, secure SDLC adoption, security testing coverage, risk exceptions, and engineering engagement.
- Support compliance and audit obligations relevant to a publicly traded fintech and payment technology company, including PCI DSS, SOC 2, SOX‑related technology controls, privacy obligations, customer security commitments, and internal security policies.

Supervisory Responsibility

This role has direct supervisory responsibility for a team of security engineers.

Education and Experience

- Bachelors Degree in Computer Science, Software Engineering, Computer Engineering, Information Security, or a related technical field, or equivalent practical experience.
- 8+ years of combined experience in software engineering, application security, product security, platform security, cloud security, or security engineering.
- 3+ years of experience managing or technically leading security engineers, software engineers, or platform engineering teams.
- Extensive hands‑on software development experience in one or more of the following languages: Java, NodeJS, Python, Golang.
- Deep technical knowledge of modern web application architecture, SaaS platforms, microservices, distributed systems, RESTful APIs, authentication, authorization, session management, secure data handling, and service‑to‑service communication.
- Strong knowledge of application security vulnerabilities and secure remediation patterns, including injection flaws, broken access control, authentication weaknesses, insecure deserialization, SSRF, XXE, XSS, CSRF, business logic flaws, insecure file handling, and supply chain risks.




- Strong knowledge of API security risks, including broken object‑level authorization, broken function‑level authorization, excessive data exposure, mass assignment, unrestricted resource consumption, improper inventory management, and unsafe API integrations.
- Solid knowledge of AI and LLM application security risks, including prompt injection, insecure output handling, sensitive data exposure, model misuse, insecure tool use, plugin risk, excessive agency, and AI supply chain concerns.
- Hands‑on experience securing cloud environments in one or more major public cloud platforms: AWS, GCP, Azure.
- Hands‑on experience with Kubernetes, containers, container registries, image hardening, workload identity, network policies, secrets management, runtime controls, and deployment security.
- Experience securing CI/CD pipelines and developer workflows, including source control, build systems, artifact repositories, automated testing, release gates, and infrastructure as code.
- Experience with security testing tools and practices, including SAST, DAST, SCA, container scanning, IaC scanning, secrets scanning, API testing, manual code review, and threat modeling.

Salary $120-$160k

This job operates in a professional office and technology environment. This role routinely uses standard office and engineering equipment, including laptop computers, collaboration tools, cloud platforms, security platforms, source code repositories, ticketing systems, and communication systems. The role requires frequent collaboration with geographically distributed teams and may involve participation in security incident response, urgent vulnerability remediation, production risk reviews, and executive briefings.

Physical Demands

The employee may occasionally be required to lift up to 25 lbs.

EEO Statement

Paymentus is an equal opportunity employer. We enthusiastically accept our responsibility to make employment decisions without regard to race, religious creed, color, age, sex, sexual orientation, national origin, ancestry, citizenship status, religion, marital status, disability, military service or veteran status, genetic information, medical condition including medical characteristics, or any other classification protected by applicable federal, state, provincial, and local laws and ordinances. Our management is dedicated to ensuring the fulfillment of this policy with respect to hiring, placement, promotion, transfer, demotion, layoff, termination, recruitment advertising, pay, and other forms of compensation, training, and general treatment during employment.

Reasonable Accommodation

Paymentus recognizes and supports its obligation to endeavor to accommodate job applicants and employees with known physical or mental disabilities who are able to perform the essential functions of the position, with or without reasonable accommodation. Paymentus will endeavor to provide reasonable accommodations to otherwise qualified job applicants and employees with known physical or mental disabilities, unless doing so would impose an undue hardship on the Company or pose a direct threat of substantial harm to the employee or others.

An applicant or employee who believes he or she needs a reasonable accommodation of a disability should discuss the need for possible accommodation with the Human Resources Department, or his or her direct supervisor.

#J-18808-Ljbffr

📌 Manager of Platform Security (Richmond Hill)
🏢 Paymentus
📍 Richmond Hill

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: manager of platform security (richmond hill) / richmond hill

Subscribe to this job alert:

Get the latest job offers by email for: manager of platform security (richmond hill) / richmond hill