Sr. Security Engineer
Sr. Security Engineer
Position Overview:
We are seeking a Sr. Security Engineer to join our Agentic Experience group, reporting to the Principal Engineer, Agentic Development. In this role, you will strengthen the security posture of our core payments platform while helping shape security practices for AI-assisted software development. You will work closely with our Agentic Experience group and our CISO, with visibility to executive leadership. This is a hands-on engineering role with broad scope: application security, cloud infrastructure security, and security review of AI/agentic development tooling.
Responsibilities & Goals:
- Identify, prioritize, and remediate vulnerabilities across our Java-based platform and AWS infrastructure
- Drive infrastructure security improvements, including IAM policy refinement, instance metadata protections, and network egress controls
- Conduct security reviews of AI-assisted development pipelines, tool integrations, and agent-accessible services
- Develop and maintain secure development standards, patterns, and guardrails for engineering teams
- Partner with the fractional CISO on risk assessment, remediation planning, and compliance initiatives (including PCI DSS)
- Contribute to incident response readiness and security monitoring improvements
- Communicate security priorities and progress clearly to technical and executive stakeholders
Experience & Qualifications:
- 7+ years of hands-on security engineering experience (application security, cloud security, or infrastructure security)
- Strong experience with AWS security services and primitives (IAM, VPC networking, secrets management)
- Experience working in and securing large production codebases; JVM ecosystem experience preferred
- Familiarity with modern AI-assisted development tools and an interest in their security implications
- Strong prioritization and communication skills; ability to advocate for security investments with stakeholders
- Experience in payments, fintech, or other regulated environments is a plus
- Relevant certifications (e.g., CISSP, OSCP, AWS Security Specialty) are a plus but not required
Nice to Have
- Security certifications (e.g., AWS Security Specialty, CISSP, OSCP, GIAC).
- Experience securing payments, ecommerce, or subscription/billing platforms.
- Experience with secure SDLC practices and integrating security tooling (SAST/DAST/SCA) into CI/CD.
- Familiarity with global, multi-currency, or tax-calculation systems and their data-sensitivity considerations.
About the Company:
FastSpring is an EQUAL EMPLOYMENT OPPORTUNITY/AFFIRMATIVE ACTION employer. Candidates are considered for employment with FastSpring without regard to their race, color, religion, national origin, age, sex, gender, pregnancy, disability, sexual orientation, gender identity, genetic information, military status, veteran status (specifically status as a disabled veteran, special disabled veteran, Vietnam Era veteran, recently separated veteran, armed forces service medal veteran, or other protected veteran) or other classification protected by applicable federal, state or local law.
AI Transparency Statement:
FastSpring may utilize artificial intelligence (AI) or automated tools during portions of the recruitment process to assist with operational and administrative activities, including candidate communications, scheduling, application organization, and interview documentation. These tools are designed to support efficiency and consistency within the hiring process. AI systems are not used as the sole determinant of hiring outcomes, and all employment decisions are made by qualified human reviewers. We are committed to responsible and fair hiring practices and continue to evaluate our use of technology accordingly.
About the Company
More jobs at FastSpring
-
Senior Software Engineer - Payments
Remote · Remote · Aug 19, 2026