ABOUT REPAY REPAY (“Realtime Electronic Payments” / NASDAQ TICKER: RPAY) is an established and fast-growing publicly traded financial technology and payment processing company headquartered in Atlanta, Georgia, with offices across the country. REPAY enables its customers to accept payments anytime, anywhere, and through any channel while providing a secure, seamless, and enjoyable payment experience for the end consumers. REPAY offers a comprehensive suite of electronic payment and funding solutions, including debit and credit card processing, ACH processing, Instant Funding, and electronic bill payment systems with full IVR, text, and mobile capabilities. The scalability of its products allows merchants of all sizes to add an instant arsenal of intelligent payment technology solutions to their businesses without significant development costs or infrastructure investments.
ABOUT THE ROLE
REPAY is seeking a highly motivated, self-driven Security Engineer to help lead our Product Security efforts across application and cloud security. This role partners primarily with engineering and infrastructure teams to strengthen the security controls behind REPAY’s payment products, improving the resiliency of the applications and cloud environments our customers depend on. You will review new applications, features, and implementations to identify security requirements and improvement opportunities, and you will define the application and cloud security standards that engineering builds against.
This is an architecture-leaning, hands-on role: you will work alongside software engineers, infrastructure engineers, and solution architects to drive adoption of those standards, and you will build custom applications and automation that make secure patterns the path of least resistance. You will also help shape how REPAY applies AI to improve the efficiency of security controls and how we secure the AI capabilities embedded in our own products. The ideal candidate is fluent in modern application and cloud security frameworks, communicates credibly with developers, and prefers scalable engineering solutions over manual gatekeeping.
RESPONSIBILITIES
Application and Cloud Security Architecture
- Review new applications, features, integrations, and infrastructure implementations to identify security requirements, design flaws, and improvement opportunities.
- Conduct threat modeling and secure design reviews early in the development lifecycle, translating findings into prioritized, actionable engineering requirements.
- Serve as the security architecture partner for product and platform initiatives, providing pragmatic guidance that balances risk, delivery timelines, and engineering effort.
- Evaluate architectural risk across authentication, authorization, data protection, tenancy isolation, secrets handling, and third-party integrations.
Security Standards and Requirements
- Define, document, and maintain application and cloud security standards, secure design patterns, and reference architectures.
- Map standards to recognized frameworks such as OWASP ASVS and Top 10, NIST SSDF, CIS Benchmarks, and PCI DSS requirements relevant to REPAY’s products.
- Partner with engineering leaders, infrastructure teams, and architects to plan and drive implementation of standards, including remediation roadmaps for existing systems.
- Measure and report on adoption, coverage, and exceptions, and continuously refine standards based on real-world engineering feedback.
Application Security Engineering
- Own and optimize application security tooling, including SAST, DAST, SCA, secrets scanning, and API security testing, integrated directly into CI/CD pipelines.
- Manage web application firewall (WAF) policy design, tuning, rule development, and monitoring to protect production applications.
- Triage and validate findings, reduce false positives, and partner with development teams on root cause remediation rather than one-off fixes.
- Support secure coding enablement through guidance, code review support, developer training, and security champions model.
Cloud Security and Infrastructure as Code
- Improve cloud security posture using CSPM and cloud-native security services, driving remediation of misconfigurations and risky identity and network exposure.
- Define and implement secure Infrastructure as Code patterns and guardrails in Terraform, including policy as code and pre-deployment validation.
- Secure containerized environments, covering image hardening, registry scanning, runtime protection, orchestration configuration, and workload identity.
- Partner with infrastructure and cloud engineering teams to embed security controls into landing zones, pipelines, and platform services by default.
Custom Development and Automation
- Develop, implement, and manage custom applications, services, and integrations that extend and connect security capabilities.
- Automate recurring security engineering tasks such as evidence collection, control validation, routing findings, and reporting using APIs and scripting.
- Maintain code quality, testing, and operational support for the tooling you build, treating internal security tools as production software.
AI Enablement and Securing AI in Products
- Evaluate and apply AI and agentic tooling to improve the efficiency and coverage of application and cloud security controls, including triage, code review, and remediation guidance.
- Define security requirements and design patterns for AI capabilities built into REPAY’s custom applications, addressing prompt injection, data exposure, model and tool abuse, and agent authorization.
- Partner with engineering teams to implement guardrails, logging, and monitoring for AI-enabled features and agentic workflows.
Collaboration and Cross-Team Enablement
- Drive complex, multi-team initiatives from design through adoption, coordinating across product engineering, infrastructure, architecture, and security functions.
- Translate security requirements and risk for both technical and non-technical stakeholders, including product owners and leadership.
- Support Security Operations and Incident Response teams during application or cloud-related incidents and convert findings into durable control improvements.
SKILLS & EXPERIENCE NEEDED
Qualifications:
- Bachelor's degree in computer science, Information Systems, or a related field, or equivalent practical experience.
- 5+ years of experience in application security, cloud security, product security, or software engineering with a security focus.
- Demonstrated experience performing secure design reviews and threat modeling for modern applications and cloud architectures.
- Fluency with application and cloud security frameworks such as OWASP ASVS and Top 10, OWASP SAMM, NIST SSDF, CIS Benchmarks, and cloud provider security best practices.
- Hands-on experience with SAST, DAST, SCA, and WAF technologies, including pipeline integration and policy tuning.
- Working experience with CSPM tooling and securing AWS and/or Azure environments, including IAM, networking, logging, and data services.
- Experience securing Infrastructure as Code, particularly Terraform, and applying policy as code guardrails.
- Experience securing containerized and orchestrated workloads (e.g., Docker, Kubernetes, ECS).
- Proficiency in at least one programming language (e.g., Python, Go, Java, C#, JavaScript/TypeScript) sufficient to build custom applications and automation and to review application code.
- Ability to operate independently, drive complex initiatives, and influence engineering teams without direct authority.
- Strong analytical thinking, curiosity, and a desire to continuously improve security posture.
Preferred Skills:
- Familiarity with AI and agentic tooling, including using them to improve security control efficiency and securing AI features within custom applications, will be a plus.
- Experience with LLM and agent security risks, and with frameworks such as the OWASP Top 10 for LLM Applications will be a plus.
- Experience in payments, financial services, or another regulated environment, with practical exposure to PCI DSS or SOC 2 will be a plus.
- Experience building or operating a security champions program or developer-facing security enablement at scale.
- Experience with API security, service mesh, mTLS, and zero trust patterns for service-to-service communication.
- Relevant certifications (e.g., CISSP, CSSLP, GIAC GWEB/GCSA/GDSA/GPCS, OSWE, AWS or Azure Security Specialty, CCSP, CKS).
WHY JOIN REPAY.… BECAUSE CULTURE IS EVERYTHING
GROWTH & PEOPLE-CENTERED LEADERSHIP As the industry-leading financial technology provider in the Consumer Finance and Business to Business spaces, we continue to set the standard for application development and delivery. In 2019, REPAY became a public company listed on the Nasdaq Stock Market (RPAY). For the past three consecutive years, we have placed on the ACG® Atlanta Georgia Fast 40, a list recognizing the top 40 fastest-growing middle-market companies in Georgia. REPAY’s leadership empowers each team member to make a difference and stretch to their fullest potential. Our dedication to frequent, transparent communication is shown with companywide meetings where our leaders share company vision and encourage employees to ask questions.
FUN WORK ENVIRONMENT & GREAT TEAMS We offer it all: business to casual dress, great snacks & beverages, and open-air collaborative team settings. REPAY has been certified as a Great Place to Work® company for 2017, 2018, 2019, 2020, 2021, and 2022. The REPAY team is fun, smart, collaborative, and truly enjoys working together. Making a difference in our local communities – we support several philanthropic initiatives every year to give back to our local communities. We are self-driven, motivated professionals who do not require micro-management to ensure we produce high quality and timely work.
INNOVATION & EDUCATION We create highly sophisticated payment processing applications and are always pushing the boundaries of what is possible. We are constantly revolutionizing the industry by building on new ideas from clients and employees. We provide the resources necessary to ensure new innovations can develop quickly and with quality. We encourage continuing education, including professional conferences and events.
PUTTING OUR PEOPLE FIRST We believe our people are the best, and we care immensely about their success. We offer a comprehensive benefits package which includes 100% coverage of employee healthcare premiums and several free benefits, including life insurance, disability insurance, and work-life balance resources. All benefits go into effect day one. Our employees’ futures are important to us, which is why we have a 401(k)-employer match and and an Employee Stock Purchase Plan. REPAY employees are eligible to participate in our Annual Bonus Program. This bonus award reflects excellent performance of individual contributions and goals achieved during the past year.
REPAY’s core values are Excellence, Passion, Innovation, Respect, and Integrity.
REPAY is an Equal Opportunity Employer and we promote a company culture where diversity, equity and inclusion are central. We are committed to build our teams and grow a company in which employees can succeed, regardless of race, color, national origin, sex, sexual orientation, gender identity or expression, transgender status, pregnancy, religion, age (40 and over), disability, service in the uniformed services, protected veteran status, genetic information, or any other classification protected by federal, state or local law. Celebrating our diverse backgrounds, views and beliefs allows us to embrace what makes us unique and continue to innovate and push the boundaries of what is possible.
We are interested in every qualified candidate who is eligible to work in the United States. This position is not eligible for hire in California. Additionally, we are not able to sponsor visas.
Seen 24 hours ago.
Original posting on REPAY - Realtime Electronic Payments's site ↗
Posting text belongs to the employer. Removal requests: contact us.
Nearby
Live postings like this one
Same employer first, then the same role elsewhere.
- 3d ago
- 3d ago
- Remote9d ago
- Remote10d ago
- 10d ago
- 17d ago
- Remote18d ago
- Remote23d ago
One job at a time
One posting. One CV. $25.
Pick the job you actually want and we write for it.