Security Engineer

Bright Market, LLC
United States
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$155,000.0 - $187,000.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Amazon Web Services Cloud Computing Security Continuous Integration Programming Tools Identity and Access Management Java Virtual Machine (JVM) Key Management PCI Data Security Standards Software Security Amazon Virtual Private Cloud (VPC) Static Application Security Testing
+1 more
Dynamic Application Security Testing

Job description

We are seeking a Sr. Security Engineer to join our Agentic Experience group, reporting to the Principal Engineer, Agentic Development. In this role, you will strengthen the security posture of our core payments platform while helping shape security practices for AI-assisted software development. You will work closely with our Agentic Experience group and our CISO, with visibility to executive leadership. This is a hands-on engineering role with broad scope: application security, cloud infrastructure security, and security review of AI/agentic development tooling., * Identify, prioritize, and remediate vulnerabilities across our Java-based platform and AWS infrastructure

  • Drive infrastructure security improvements, including IAM policy refinement, instance metadata protections, and network egress controls
  • Conduct security reviews of AI-assisted development pipelines, tool integrations, and agent-accessible services
  • Develop and maintain secure development standards, patterns, and guardrails for engineering teams
  • Partner with the fractional CISO on risk assessment, remediation planning, and compliance initiatives (including PCI DSS)
  • Contribute to incident response readiness and security monitoring improvements
  • Communicate security priorities and progress clearly to technical and executive stakeholders

Requirements

  • 7+ years of hands-on security engineering experience (application security, cloud security, or infrastructure security)
  • Strong experience with AWS security services and primitives (IAM, VPC networking, secrets management)
  • Experience working in and securing large production codebases; JVM ecosystem experience preferred
  • Familiarity with modern AI-assisted development tools and an interest in their security implications
  • Strong prioritization and communication skills; ability to advocate for security investments with stakeholders
  • Experience in payments, fintech, or other regulated environments is a plus
  • Relevant certifications (e.g., CISSP, OSCP, AWS Security Specialty) are a plus but not required

Nice to Have

  • Security certifications (e.g., AWS Security Specialty, CISSP, OSCP, GIAC).
  • Experience securing payments, ecommerce, or subscription/billing platforms.
  • Experience with secure SDLC practices and integrating security tooling (SAST/DAST/SCA) into CI/CD.
  • Familiarity with global, multi-currency, or tax-calculation systems and their data-sensitivity considerations.

Benefits & conditions

Consistent with FastSpring’s values and applicable law, we provide the following information to promote pay transparency and equity. The base pay range below represents a good faith estimate of the low and high end base pay range for the listed position. This role may be eligible for the corporate bonus plan (or, if a sales role, a commission plan as defined in the sales incentive plan document). In addition, FastSpring provides a variety of benefits to employees. Estimated Base Pay Range $155,000-$187,000 USD

About the company

FastSpring is an EQUAL EMPLOYMENT OPPORTUNITY/AFFIRMATIVE ACTION employer. Candidates are considered for employment with FastSpring without regard to their race, color, religion, national origin, age, sex, gender, pregnancy, disability, sexual orientation, gender identity, genetic information, military status, veteran status (specifically status as a disabled veteran, special disabled veteran, Vietnam Era veteran, recently separated veteran, armed forces service medal veteran, or other protected veteran) or other classification protected by applicable federal, state or local law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:41 min

Protecting etcd databases using Key Management System plugins

Alex Soto Alex Soto · LIVE

2:30 min

Evaluating and selecting an AI pair programming tool

Alexander Trusheim Alexander Trusheim +1 · World Congress 2025

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:03 min

Balancing robust code verification with user liability paradigms

John Woods John Woods · LIVE

Videos

See all

Related articles

See all