Application Security Engineer

Repay - Realtime Electronic Payments

  • Atlanta, Georgia
  • 3 days ago

    Highlights

    This role partners primarily with engineering and infrastructure teams to strengthen the security controls behind REPAY's payment products, improving the resiliency of the applications and cloud environments our customers depend on. The ideal candidate is fluent in modern application and cloud security frameworks, communicates credibly with developers, and prefers scalable engineering solutions over manual gatekeeping.

    Numbers & Facts

    LocationAtlanta, Georgia

    Description

    ABOUT THE ROLE

    REPAY is seeking a highly motivated, self-driven Security Engineer to help lead our Product Security efforts across application and cloud security. This role partners primarily with engineering and infrastructure teams to strengthen the security controls behind REPAY's payment products, improving the resiliency of the applications and cloud environments our customers depend on. You will review new applications, features, and implementations to identify security requirements and improvement opportunities, and you will define the application and cloud security standards that engineering builds against.

    This is an architecture-leaning, hands-on role: you will work alongside software engineers, infrastructure engineers, and solution architects to drive adoption of those standards, and you will build custom applications and automation that make secure patterns the path of least resistance. You will also help shape how REPAY applies AI to improve the efficiency of security controls and how we secure the AI capabilities embedded in our own products. The ideal candidate is fluent in modern application and cloud security frameworks, communicates credibly with developers, and prefers scalable engineering solutions over manual gatekeeping.

    RESPONSIBILITIES

    Application and Cloud Security Architecture

    • Review new applications, features, integrations, and infrastructure implementations to identify security requirements, design flaws, and improvement opportunities.

    • Conduct threat modeling and secure design reviews early in the development lifecycle, translating findings into prioritized, actionable engineering requirements.

    • Serve as the security architecture partner for product and platform initiatives, providing pragmatic guidance that balances risk, delivery timelines, and engineering effort.

    • Evaluate architectural risk across authentication, authorization, data protection, tenancy isolation, secrets handling, and third-party integrations.

    Security Standards and Requirements

    • Define, document, and maintain application and cloud security standards, secure design patterns, and reference architectures.

    • Map standards to recognized frameworks such as OWASP ASVS and Top 10, NIST SSDF, CIS Benchmarks, and PCI DSS requirements relevant to REPAY's products.

    • Partner with engineering leaders, infrastructure teams, and architects to plan and drive implementation of standards, including remediation roadmaps for existing systems.

    • Measure and report on adoption, coverage, and exceptions, and continuously refine standards based on real-world engineering feedback.

    Application Security Engineering

    • Own and optimize application security tooling, including SAST, DAST, SCA, secrets scanning, and API security testing, integrated directly into CI/CD pipelines.

    • Manage web application firewall (WAF) policy design, tuning, rule development, and monitoring to protect production applications.

    • Triage and validate findings, reduce false positives, and partner with development teams on root cause remediation rather than one-off fixes.

    • Support secure coding enablement through guidance, code review support, developer training, and security champions model.

    Cloud Security and Infrastructure as Code

    • Improve cloud security posture using CSPM and cloud-native security services, driving remediation of misconfigurations and risky identity and network exposure.

    • Define and implement secure Infrastructure as Code patterns and guardrails in Terraform, including policy as code and pre-deployment validation.

    • Secure containerized environments, covering image hardening, registry scanning, runtime protection, orchestration configuration, and workload identity.

    • Partner with infrastructure and cloud engineering teams to embed security controls into landing zones, pipelines, and platform services by default.

    Custom Development and Automation

    • Develop, implement, and manage custom applications, services, and integrations that extend and connect security capabilities.

    • Automate recurring security engineering tasks such as evidence collection, control validation, routing findings, and reporting using APIs and scripting.

    • Maintain code quality, testing, and operational support for the tooling you build, treating internal security tools as production software.

    AI Enablement and Securing AI in Produc

    Similar Jobs

    See more jobs