Cloud Security Engineer
Richmond Hill - Canada
Job Summary
The Cloud Security Engineer is responsible for helping secure the cloud-native infrastructure platforms services and deployment patterns that support the Paymentus SaaS platform. This role reports to the Manager of Security Engineering and works closely with Engineering Cloud Infrastructure DevOps Platform Engineering Product Compliance Security Operations and Application Security teams.
This is a hands-on technical role focused on securing Paymentus infrastructure across public cloud Kubernetes containers serverless technologies CI/CD pipelines infrastructure as code cloud identity network controls secrets management logging monitoring and cloud-native security tooling.
The successful candidate must have deep practical knowledge of cloud security across AWS GCP and Azure with strong experience securing modern SaaS platforms web applications RESTful APIs microservices and distributed systems. The role requires the ability to assess cloud architecture identify insecure patterns build scalable security controls automate cloud security checks and partner directly with engineering teams to remediate risk without unnecessarily slowing delivery.
- Help secure Paymentus cloud environments SaaS platform infrastructure application workloads Kubernetes clusters containers serverless functions CI/CD pipelines and cloud-native services.
- Partner with Engineering Cloud Infrastructure DevOps Platform Engineering and Security teams to embed security into cloud architecture platform design infrastructure provisioning application deployment and production operations.
- Perform cloud security architecture reviews for workloads deployed across AWS GCP and Azure including compute storage networking identity secrets encryption logging monitoring and service-to-service communication.
- Review and improve cloud identity and access management controls including least privilege role design service accounts workload identity privileged access cross-account access federation just-in-time access and access review processes.
- Assess and harden Kubernetes environments including cluster configuration workload isolation RBAC admission controls network policies pod security secrets management image provenance runtime controls logging and monitoring.
- Assess and harden containerized workloads including container image security base image governance vulnerability scanning registry controls build-time security runtime restrictions and deployment policy enforcement.
- Review and improve serverless security controls including function permissions event source validation input handling secrets management dependency governance logging monitoring abuse prevention and least-privilege execution roles.
- Review infrastructure as code for security risks misconfigurations policy violations excessive permissions insecure network exposure weak encryption settings missing logging and non-compliant cloud resource patterns.
- Build and maintain automated cloud security controls guardrails detection logic policy-as-code CI/CD security gates and developer self-service checks.
- Support secure configuration and deployment of cloud services that host or support Paymentus applications APIs microservices data flows messaging systems and integration services.
- Assess cloud networking controls including VPC/VNet design segmentation private connectivity firewall rules security groups network ACLs routing ingress/egress controls DNS security TLS configuration and exposure to the public internet.
- Review edge security CDN WAF bot mitigation rate limiting origin protection header controls caching behavior and DDoS protection patterns using platforms such as Cloudflare and Fastly.
- Assess cloud security risks related to RESTful APIs API gateways service mesh authentication flows authorization models rate limiting logging monitoring and service-to-service communication.
- Use and tune cloud security tooling including CSPM CNAPP CWPP CIEM container security Kubernetes security vulnerability management secrets scanning IaC scanning and cloud-native logging and detection platforms.
- Validate cloud security findings for exploitability severity business impact compensating controls and appropriate remediation strategy.
- Provide clear actionable remediation guidance to engineering and infrastructure teams including secure configuration changes architecture alternatives policy changes code-level infrastructure fixes and risk-based prioritization.
- Support vulnerability management for cloud container Kubernetes serverless and infrastructure findings including triage severity validation remediation tracking exception review SLA management and reporting.
- Collaborate with Security Operations and Incident Response teams to improve cloud detection application-layer logging cloud audit trails threat hunting attack-path analysis and post-incident remediation.
- Help establish and maintain secure cloud baselines reference architectures control standards deployment patterns hardening guides and operational procedures.
- Support penetration testing red team exercises external assessments customer security reviews audit requests and remediation validation related to cloud and platform security.
- Research emerging cloud security threats cloud misconfiguration patterns container escape techniques Kubernetes attack paths serverless risks SaaS platform risks API abuse patterns and AI infrastructure security risks.
- Communicate cloud security risks clearly to engineering infrastructure product compliance security and leadership stakeholders.
- Help maintain security standards and practices that support Paymentus obligations as a publicly traded fintech and payment technology company including PCI DSS SOC 2 SOX-related technology controls privacy obligations customer security commitments and internal security policies.
Supervisory Responsibility
This role does not have direct supervisory responsibility.
The Cloud Security Engineer is expected to provide technical leadership mentorship and guidance to engineering cloud infrastructure DevOps platform engineering and security stakeholders. This includes helping teams understand cloud security risks adopt secure platform patterns and remediate cloud Kubernetes container serverless and infrastructure security issues effectively.
Education and Experience
- Bachelors Degree in Engineering Computer Science Software Engineering Information Security or a related technical field or equivalent practical experience.
- 5 years of experience in cloud security infrastructure security platform security DevSecOps security engineering cloud engineering site reliability engineering or a closely related technical role.
- Hands-on experience securing workloads in one or more major public cloud platforms with strong preference for practical experience across AWS GCP and Azure.
- Strong understanding of cloud-native architecture SaaS platforms microservices distributed systems RESTful APIs authentication authorization encryption logging monitoring and service-to-service communication.
- Deep knowledge of cloud identity and access management including least privilege role-based access service accounts workload identity cross-account access privileged access federation and access governance.
- Hands-on experience with Kubernetes security including RBAC cluster hardening admission control network policies pod security controls secrets management workload isolation and runtime security.
- Hands-on experience with container security including image scanning base image hardening container registries image signing or provenance runtime controls and containerized application deployment patterns.
- Experience securing serverless technologies including function permissions event-driven architectures secrets handling logging monitoring and abuse-prevention patterns.
- Experience with infrastructure as code and policy-as-code technologies such as Terraform CloudFormation or similar tools.
- Experience securing CI/CD pipelines source control systems build systems artifact repositories container registries deployment workflows and release automation.
- Experience with cloud security tools and practices such as CSPM CNAPP CWPP CIEM cloud vulnerability management cloud asset inventory cloud detection engineering IaC scanning container scanning and secrets scanning.
- Strong knowledge of cloud networking and perimeter controls including segmentation routing firewall rules private endpoints load balancers TLS DNS ingress/egress controls API gateways and exposure management.
- Familiarity with CDN WAF bot mitigation rate limiting edge security and origin protection using platforms such as Cloudflare and Fastly.
- Familiarity with application servers web servers and reverse proxy technologies such as Tomcat JBoss nginx or similar platforms.
- Good understanding of modern application security guidelines including OWASP Top 10 OWASP API Security Top 10 and OWASP Top 10 for Large Language Model Applications.
- Ability to analyze cloud security findings determine exploitability identify root cause and recommend practical remediation steps.
- Ability to work independently manage multiple priorities and deliver high-quality results in a fast-paced engineering environment.
- Strong written and verbal communication skills including the ability to explain cloud security risks clearly to technical and non-technical stakeholders.
- Strong collaboration skills and the ability to build trusted working relationships with engineering product DevOps cloud infrastructure compliance and security teams.
Preferred Qualifications
- Experience working in fintech payments banking financial services or another highly regulated SaaS environment.
- Experience with payment processing environments cardholder data environments tokenization payment APIs transaction platforms or fraud-related infrastructure.
- Experience supporting PCI DSS SOC 2 SOX technology controls NIST CSF ISO 27001 or similar security and compliance frameworks.
- Experience securing multi-cloud environments across AWS GCP and Azure.
- Experience with Kubernetes admission controllers service mesh security cloud workload identity runtime detection image signing software bill of materials and supply chain security.
- Experience building cloud security guardrails secure landing zones reusable infrastructure modules secure service templates policy-as-code or developer self-service security capabilities.
- Experience with cloud-native logging and detection tools including cloud audit logs SIEM integrations security data lakes threat detection rules and incident investigation workflows.
- Experience with red team findings penetration testing support attack-path analysis cloud incident response or cloud threat hunting.
- Relevant certifications such as AWS Security Specialty Google Professional Cloud Security Engineer Azure Security Engineer CCSP CISSP CKS CKAD CKA Kubernetes Security Specialist or equivalent practical experience.
This job operates in a professional office and technology environment. This role routinely uses standard office and engineering equipment including laptop computers collaboration tools cloud platforms security platforms source code repositories ticketing systems and communication systems. The role requires frequent collaboration with geographically distributed teams and may involve participation in security incident response urgent vulnerability remediation production risk reviews and executive briefings.
While performing the duties of this job the employee is regularly required to talk hear type read and view computer screens for extended periods. Specific vision abilities required by this job include close vision and the ability to adjust focus. The employee may occasionally be required to stand walk reach with hands and arms lift files or equipment open filing cabinets bend or stand on a stool as necessary. The employee may occasionally be required to lift up to 25 lbs.
This is a full-time position. Days and hours of work are generally Monday through Friday during normal business hours. Occasional evening weekend or on-call work may be required based on business needs security incidents critical vulnerabilities production releases audit deadlines or customer commitments.
Minimal travel is expected. Occasional travel may be required for company meetings team events customer security discussions conferences audits or vendor engagements.
This job description is not designed to cover or contain a comprehensive listing of all activities duties or responsibilities required of the employee. Duties responsibilities and activities may change at any time with or without notice.
Paymentus is an equal opportunity employer. We enthusiastically accept our responsibility to make employment decisions without regard to race religious creed color age sex sexual orientation national origin ancestry citizenship status religion marital status disability military service or veteran status genetic information medical condition including medical characteristics or any other classification protected by applicable federal state provincial and local laws and ordinances. Our management is dedicated to ensuring the fulfillment of this policy with respect to hiring placement promotion transfer demotion layoff termination recruitment advertising pay and other forms of compensation training and general treatment during employment.
Paymentus recognizes and supports its obligation to endeavor to accommodate job applicants and employees with known physical or mental disabilities who are able to perform the essential functions of the position with or without reasonable accommodation. Paymentus will endeavor to provide reasonable accommodations to otherwise qualified job applicants and employees with known physical or mental disabilities unless doing so would impose an undue hardship on the Company or pose a direct threat of substantial harm to the employee or others.
An applicant or employee who believes he or she needs a reasonable accommodation of a disability should discuss the need for possible accommodation with the Human Resources Department or his or her direct supervisor.
Required Experience:
IC
About Company
Paymentus delivers secure, smart billing and payment solutions that boost engagement and on-time payments for businesses, governments, utilities, and more.