> Markdown version of [/jobs/ext/2861507-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2861507-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Repay Inc - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Application Firewall, Microsoft Azure, C Sharp (Programming Language), Cloud Computing Security, Cloud Engineering, Software Quality, Code Review, Cyber Security, Information Systems, Custom Software, Data as a Services, Software Design Patterns, Identity and Access Management, Python (Programming Language), Open Web Application Security, PCI Data Security Standards, Zero Trust Network Access, Secure Coding, Software Engineering, Systems Integration, TypeScript, Policy as Code, Data Logging, Cloud Platform System, Istio, Large Language Models, Software Security, Kubernetes, Information Technology, Enterprise Integration, Integration Frameworks, CIS Benchmarks, Terraform, Docker, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** September 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d4be196fbc9a16bc ## About the Role REPAY is seeking a highly motivated, self-driven Security Engineer to help lead our Product Security efforts across application and cloud security. This role partners primarily with engineering and infrastructure teams to strengthen the security controls behind REPAY's payment products, improving the resiliency of the applications and cloud environments our customers depend on. You will review new applications, features, and implementations to identify security requirements and improvement opportunities, and you will define the application and cloud security standards that engineering builds against., * Bachelor's degree in computer science, Information Systems, or a related field, or equivalent practical experience. * 5+ years of experience in application security, cloud security, product security, or software engineering with a security focus. * Demonstrated experience performing secure design reviews and threat modeling for modern applications and cloud architectures. * Fluency with application and cloud security frameworks such as OWASP ASVS and Top 10, OWASP SAMM, NIST SSDF, CIS Benchmarks, and cloud provider security best practices. * Hands-on experience with SAST, DAST, SCA, and WAF technologies, including pipeline integration and policy tuning. * Working experience with CSPM tooling and securing AWS and/or Azure environments, including IAM, networking, logging, and data services. * Experience securing Infrastructure as Code, particularly Terraform, and applying policy as code guardrails. * Experience securing containerized and orchestrated workloads (e.g., Docker, Kubernetes, ECS). * Proficiency in at least one programming language (e.g., Python, Go, Java, C#, JavaScript/TypeScript) sufficient to build custom applications and automation and to review application code. * Ability to operate independently, drive complex initiatives, and influence engineering teams without direct authority. * Strong analytical thinking, curiosity, and a desire to continuously improve security posture. Preferred Skills: * Familiarity with AI and agentic tooling, including using them to improve security control efficiency and securing AI features within custom applications, will be a plus. * Experience with LLM and agent security risks, and with frameworks such as the OWASP Top 10 for LLM Applications will be a plus. * Experience in payments, financial services, or another regulated environment, with practical exposure to PCI DSS or SOC 2 will be a plus. * Experience building or operating a security champions program or developer-facing security enablement at scale. * Experience with API security, service mesh, mTLS, and zero trust patterns for service-to-service communication. * Relevant certifications (e.g., CISSP, CSSLP, GIAC GWEB/GCSA/GDSA/GPCS, OSWE, AWS or Azure Security Specialty, CCSP, CKS). ## Description This is an architecture-leaning, hands-on role: you will work alongside software engineers, infrastructure engineers, and solution architects to drive adoption of those standards, and you will build custom applications and automation that make secure patterns the path of least resistance. You will also help shape how REPAY applies AI to improve the efficiency of security controls and how we secure the AI capabilities embedded in our own products. The ideal candidate is fluent in modern application and cloud security frameworks, communicates credibly with developers, and prefers scalable engineering solutions over manual gatekeeping., Application and Cloud Security Architecture * Review new applications, features, integrations, and infrastructure implementations to identify security requirements, design flaws, and improvement opportunities. * Conduct threat modeling and secure design reviews early in the development lifecycle, translating findings into prioritized, actionable engineering requirements. * Serve as the security architecture partner for product and platform initiatives, providing pragmatic guidance that balances risk, delivery timelines, and engineering effort. * Evaluate architectural risk across authentication, authorization, data protection, tenancy isolation, secrets handling, and third-party integrations. Security Standards and Requirements * Define, document, and maintain application and cloud security standards, secure design patterns, and reference architectures. * Map standards to recognized frameworks such as OWASP ASVS and Top 10, NIST SSDF, CIS Benchmarks, and PCI DSS requirements relevant to REPAY's products. * Partner with engineering leaders, infrastructure teams, and architects to plan and drive implementation of standards, including remediation roadmaps for existing systems. * Measure and report on adoption, coverage, and exceptions, and continuously refine standards based on real-world engineering feedback. Application Security Engineering * Own and optimize application security tooling, including SAST, DAST, SCA, secrets scanning, and API security testing, integrated directly into CI/CD pipelines. * Manage web application firewall (WAF) policy design, tuning, rule development, and monitoring to protect production applications. * Triage and validate findings, reduce false positives, and partner with development teams on root cause remediation rather than one-off fixes. * Support secure coding enablement through guidance, code review support, developer training, and security champions model. Cloud Security and Infrastructure as Code * Improve cloud security posture using CSPM and cloud-native security services, driving remediation of misconfigurations and risky identity and network exposure. * Define and implement secure Infrastructure as Code patterns and guardrails in Terraform, including policy as code and pre-deployment validation. * Secure containerized environments, covering image hardening, registry scanning, runtime protection, orchestration configuration, and workload identity. * Partner with infrastructure and cloud engineering teams to embed security controls into landing zones, pipelines, and platform services by default. Custom Development and Automation * Develop, implement, and manage custom applications, services, and integrations that extend and connect security capabilities. * Automate recurring security engineering tasks such as evidence collection, control validation, routing findings, and reporting using APIs and scripting. * Maintain code quality, testing, and operational support for the tooling you build, treating internal security tools as production software. AI Enablement and Securing AI in Products * Evaluate and apply AI and agentic tooling to improve the efficiency and coverage of application and cloud security controls, including triage, code review, and remediation guidance. * Define security requirements and design patterns for AI capabilities built into REPAY's custom applications, addressing prompt injection, data exposure, model and tool abuse, and agent authorization. * Partner with engineering teams to implement guardrails, logging, and monitoring for AI-enabled features and agentic workflows. Collaboration and Cross-Team Enablement * Drive complex, multi-team initiatives from design through adoption, coordinating across product engineering, infrastructure, architecture, and security functions. * Translate security requirements and risk for both technical and non-technical stakeholders, including product owners and leadership. * Support Security Operations and Incident Response teams during application or cloud-related incidents and convert findings into durable control improvements., As the industry-leading financial technology provider in the Consumer Finance and Business to Business spaces, we continue to set the standard for application development and delivery. In 2019, REPAY became a public company listed on the Nasdaq Stock Market (RPAY). For the past three consecutive years, we have placed on the ACG® Atlanta Georgia Fast 40, a list recognizing the top 40 fastest-growing middle-market companies in Georgia. REPAY's leadership empowers each team member to make a difference and stretch to their fullest potential. Our dedication to frequent, transparent communication is shown with companywide meetings where our leaders share company vision and encourage employees to ask questions. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Highest Paying Tech Companies in Europe](https://www.wearedevelopers.com/magazine/162-highest-paying-tech-companies-in-europe)