Base Career helps you apply smarter for this job.
Key skills for this role
The Manager of Platform Security is responsible for leading a team of security engineers focused on the security of the Paymentus SaaS platform, including web applications, RESTful APIs, cloud-native services, containerized workloads, serverless functions, and AI-enabled application components. This role owns the execution of application and platform security engineering practices across the software development lifecycle and partners closely with Engineering, Product, DevOps, Cloud Infrastructure, Compliance, and Security Operations to identify, prioritize, and remediate security risks before they impact Paymentus customers, partners, or regulated payment environments.
The successful candidate must combine strong people leadership with deep hands-on technical expertise. This is not a purely governance or advisory role. The individual must be capable of reviewing application architecture, assessing source code and API implementations, challenging insecure design decisions, guiding engineers through secure remediation, and building scalable security controls for modern SaaS platforms.
The Manager of Platform Security is responsible for leading a team of security engineers focused on the security of the Paymentus SaaS platform, including web applications, RESTful APIs, cloud-native services, containerized workloads, serverless functions, and AI-enabled application components. This role owns the execution of application and platform security engineering practices across the software development lifecycle and partners closely with Engineering, Product, DevOps, Cloud Infrastructure, Compliance, and Security Operations to identify, prioritize, and remediate security risks before they impact Paymentus customers, partners, or regulated payment environments.
The successful candidate must combine strong people leadership with deep hands-on technical expertise. This is not a purely governance or advisory role. The individual must be capable of reviewing application architecture, assessing source code and API implementations, challenging insecure design decisions, guiding engineers through secure remediation, and building scalable security controls for modern SaaS platforms.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Richmond Hill, CAN
The employer is seeking a Financial Analyst to analyze billing and financial information while supporting invoicing, reconciliations, audit procedures, and finance projects. The role is customer-facing and requires a rel
Richmond Hill, CAN
Richmond Hill, CAN
Richmond Hill, CAN
Charlotte, USA
Dallas, USA
Dallas, USA
Dallas, USA
Richmond Hill, CAN
Bachelors Degree in Computer Science, Software Engineering, Computer Engineering, Information Security, or a related technical field, or equivalent practical experience.
8+ years of combined experience in software engineering, application security, product security, platform security, cloud security, or security engineering.
3+ years of experience managing or technically leading security engineers, software engineers, or platform engineering teams.
Extensive hands-on software development experience in one or more of the following languages: Java, NodeJS, Python, Golang.
Deep technical knowledge of modern web application architecture, SaaS platforms, microservices, distributed systems, RESTful APIs, authentication, authorization, session management, secure data handling, and service-to-service communication.
Strong knowledge of application security vulnerabilities and secure remediation patterns, including injection flaws, broken access control, authentication weaknesses, insecure deserialization, SSRF, XXE, XSS, CSRF, business logic flaws, insecure file handling, and supply chain risks.
Strong knowledge of API security risks, including broken object-level authorization, broken function-level authorization, excessive data exposure, mass assignment, unrestricted resource consumption, improper inventory management, and unsafe API integrations.
Strong knowledge of AI and LLM application security risks, including prompt injection, insecure output handling, sensitive data exposure, model misuse, insecure tool use, plugin risk, excessive agency, and AI supply chain concerns.
Hands-on experience securing cloud environments in one or more major public cloud platforms: AWS, GCP, Azure.
Hands-on experience with Kubernetes, containers, container registries, image hardening, workload identity, network policies, secrets management, runtime controls, and deployment security.
Experience securing CI/CD pipelines and developer workflows, including source control, build systems, artifact repositories, automated testing, release gates, and infrastructure as code.
Experience with security testing tools and practices, including SAST, DAST, SCA, container scanning, IaC scanning, secrets scanning, API testing, manual code review, and threat modeling.
Experience working with Engineering and Product teams to resolve complex security issues without unnecessarily blocking delivery.
Strong analytical skills with the ability to quickly identify root cause, exploitability, compensating controls, and appropriate remediation paths.
Strong written and verbal communication skills, including the ability to explain technical security issues to engineers and risk-based business impact to executives.
Strong organizational and prioritization skills, including experience delivering multiple concurrent security initiatives in a fast-moving engineering environment.
This job operates in a professional office and technology environment. This role routinely uses standard office and engineering equipment, including laptop computers, collaboration tools, cloud platforms, security platforms, source code repositories, ticketing systems, and communication systems. The role requires frequent collaboration with geographically distributed teams and may involve participation in security incident response, urgent vulnerability remediation, production risk reviews, and executive briefings.
While performing the duties of this job, the employee is regularly required to talk, hear, type, read, and view computer screens for extended periods. Specific vision abilities required by this job include close vision and the ability to adjust focus. The employee may occasionally be required to stand, walk, reach with hands and arms, lift files or equipment, open filing cabinets, bend, or stand on a stool as necessary. The employee may occasionally be required to lift up to 25 lbs.
This is a full-time position. Days and hours of work are generally Monday through Friday during normal business hours. Occasional evening, weekend, or on-call work may be required based on business needs, security incidents, critical vulnerabilities, production releases, audit deadlines, or customer commitments.
Minimal travel is expected. Occasional travel may be required for company meetings, team events, customer security discussions, conferences, audits, or vendor engagements.
Paymentus is an equal opportunity employer. We enthusiastically accept our responsibility to make employment decisions without regard to race, religious creed, color, age, sex, sexual orientation, national origin, ancestry, citizenship status, religion, marital status, disability, military service or veteran status, genetic information, medical condition including medical characteristics, or any other classification protected by applicable federal, state, provincial, and local laws and ordinances. Our management is dedicated to ensuring the fulfillment of this policy with respect to hiring, placement, promotion, transfer, demotion, layoff, termination, recruitment advertising, pay, and other forms of compensation, training, and general treatment during employment.
Paymentus recognizes and supports its obligation to endeavor to accommodate job applicants and employees with known physical or mental disabilities who are able to perform the essential functions of the position, with or without reasonable accommodation. Paymentus will endeavor to provide reasonable accommodations to otherwise qualified job applicants and employees with known physical or mental disabilities, unless doing so would impose an undue hardship on the Company or pose a direct threat of substantial harm to the employee or others.
An applicant or employee who believes he or she needs a reasonable accommodation of a disability should discuss the need for possible accommodation with the Human Resources Department, or his or her direct supervisor.
Public U.S. electronic bill-payment platform serving billers and consumers across utilities, finance, government, and healthcare.
Visit company websiteJobs and hiring trendsFull-time
Senior · 8+ years experience
Onsite
Apply faster on company sites with our extension.