×
Register Here to Apply for Jobs or Post Jobs. X

Senior Application Security Engineer

Job in Richmond Hill, Ontario, Canada
Listing for: Paymentus
Full Time position
Listed on 2026-07-25
Job specializations:
  • Software Development
Job Description & How to Apply Below
The  Senior Application Security Engineer  is responsible for helping secure the Paymentus SaaS platform by partnering directly with software engineering, product, cloud infrastructure, Dev Ops, and security teams to identify, assess, and remediate application security risks across web applications, RESTful APIs, microservices, cloud-native services, and AI-enabled application components.

This is a hands‑on technical role reporting to the  Manager of Platform Security . The Senior Application Security Engineer will perform secure design reviews, threat modeling, source code review, API security assessments, application security testing, vulnerability validation, and remediation guidance for applications and services that support Paymentus’ payment technology platform.

The successful candidate must have strong hands‑on software development experience, deep knowledge of modern application security, and the ability to work effectively with engineering teams to improve security without unnecessarily slowing product delivery. This role requires practical expertise in SaaS application security, RESTful API security, cloud‑native application patterns, secure coding, software supply chain risk, and emerging AI/LLM application security risks.

Supervisory Responsibility
This role does not have direct supervisory responsibility.

The Senior Application Security Engineer is expected to provide technical leadership, mentorship, and guidance to software engineers, security engineers, and other technical stakeholders. This includes helping engineering teams understand security risks, adopt secure coding practices, and remediate application security issues effectively.

Education and Experience

Bachelor’s Degree in Engineering, Computer Science, Software Engineering, Information Security, or a related technical field, or equivalent practical experience.

6+ years of experience in software engineering, application security, product security, platform security, security engineering, or a closely related technical role.

Extensive hands‑on development experience in one or more of the following languages:  Java, NodeJS, Python, Golang .

Strong understanding of modern SaaS application architecture, web applications, microservices, distributed systems, RESTful APIs, authentication, authorization, session management, secure data handling, and service‑to‑service communication.

Deep knowledge of application security vulnerabilities and secure remediation patterns.

Strong knowledge of API security risks, including broken object‑level authorization, broken function‑level authorization, excessive data exposure, mass assignment, unrestricted resource consumption, improper inventory management, and unsafe third‑party API consumption.

Strong understanding of modern application security guidelines, including  OWASP Top 10 ,  OWASP API Security Top 10 , and  OWASP Top 10 for Large Language Model Applications .

Practical knowledge of AI and LLM application security risks, including prompt injection, insecure output handling, sensitive data exposure, insecure plugin/tool usage, model misuse, excessive agency, and AI supply chain concerns.

Hands‑on experience performing secure code review, threat modeling, architecture review, vulnerability validation, and security testing.

Experience using and tuning application security tools such as SAST, DAST, SCA, container scanning, IaC scanning, secrets scanning, and API security testing tools.

Experience securing applications deployed in one or more public cloud environments, including  AWS, GCP, or Azure .

Knowledge of Kubernetes, containerization, container registries, container image hardening, workload identity, secrets management, network policies, and runtime security concepts.

Knowledge of serverless application security, including function permissions, event validation, input handling, logging, dependency control, and abuse prevention.

Familiarity with application servers, web servers, and reverse proxy technologies such as  Tomcat, JBoss, nginx , or similar platforms.

Familiarity with CDN, WAF, bot mitigation, rate limiting, and edge security controls using platforms such as  Cloudflare  and …
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary