Summary/Objective
The Cloud Security Engineer is responsible for helping secure the cloud-native infrastructure, platforms, services, and deployment patterns that support the Paymentus SaaS platform. This role reports to the Manager of Security Engineering and works closely with Engineering, Cloud Infrastructure, DevOps, Platform Engineering, Product, Compliance, Security Operations, and Application Security teams.
This is a hands-on technical role focused on securing Paymentus infrastructure across public cloud, Kubernetes, containers, serverless technologies, CI/CD pipelines, infrastructure as code, cloud identity, network controls, secrets management, logging, monitoring, and cloud-native security tooling.
The successful candidate must have deep practical knowledge of cloud security across AWS, GCP, and Azure, with strong experience securing modern SaaS platforms, web applications, RESTful APIs, microservices, and distributed systems. The role requires the ability to assess cloud architecture, identify insecure patterns, build scalable security controls, automate cloud security checks, and partner directly with engineering teams to remediate risk without unnecessarily slowing delivery.
Essential Functions/ Responsibilities
- Help secure Paymentus cloud environments, SaaS platform infrastructure, application workloads, Kubernetes clusters, containers, serverless functions, CI/CD pipelines, and cloud-native services.
- Partner with Engineering, Cloud Infrastructure, DevOps, Platform Engineering, and Security teams to embed security into cloud architecture, platform design, infrastructure provisioning, application deployment, and production operations.
- Perform cloud security architecture reviews for workloads deployed across AWS, GCP, and Azure, including compute, storage, networking, identity, secrets, encryption, logging, monitoring, and service-to-service communication.
- Review and improve cloud identity and access management controls, including least privilege, role design, service accounts, workload identity, privileged access, cross-account access, federation, just-in-time access, and access review processes.
- Assess and harden Kubernetes environments, including cluster configuration, workload isolation, RBAC, admission controls, network policies, pod security, secrets management, image provenance, runtime controls, logging, and monitoring.
- Assess and harden containerized workloads, including container image security, base image governance, vulnerability scanning, registry controls, build-time security, runtime restrictions, and deployment policy enforcement.
- Review and improve serverless security controls, including function permissions, event source validation, input handling, secrets management, dependency governance, logging, monitoring, abuse prevention, and least-privilege execution roles.
- Review infrastructure as code for security risks, misconfigurations, policy violations, excessive permissions, insecure network exposure, weak encryption settings, missing logging, and non-compliant cloud resource patterns.
- Build and maintain automated cloud security controls, guardrails, detection logic, policy-as-code, CI/CD security gates, and developer self-service checks.
- Support secure configuration and deployment of cloud services that host or support Paymentus applications, APIs, microservices, data flows, messaging systems, and integration services.
- Assess cloud networking controls, including VPC/VNet design, segmentation, private connectivity, firewall rules, security groups, network ACLs, routing, ingress/egress controls, DNS security, TLS configuration, and exposure to the public internet.
- Review edge security, CDN, WAF, bot mitigation, rate limiting, origin protection, header controls, caching behavior, and DDoS protection patterns using platforms such as Cloudflare and Fastly.
- Assess cloud security risks related to RESTful APIs, API gateways, service mesh, authentication flows, authorization models, rate limiting, logging, monitoring, and service-to-service communication.
- Use and tune cloud security tooling, including CSPM, CNAPP, CWPP, CIEM, container security, Kubernetes security, vulnerability management, secrets scanning, IaC scanning, and cloud-native logging and detection platforms.
- Validate cloud security findings for exploitability, severity, business impact, compensating controls, and appropriate remediation strategy.
- Provide clear, actionable remediation guidance to engineering and infrastructure teams, including secure configuration changes, architecture alternatives, policy changes, code-level infrastructure fixes, and risk-based prioritization.
- Support vulnerability management for cloud, container, Kubernetes, serverless, and infrastructure findings, including triage, severity validation, remediation tracking, exception review, SLA management, and reporting.
- Collaborate with Security Operations and Incident Response teams to improve cloud detection, application-layer logging, cloud audit trails, threat hunting, attack-path analysis, and post-incident remediation.
- Help establish and maintain secure cloud baselines, reference architectures, control standards, deployment patterns, hardening guides, and operational procedures.
- Support penetration testing, red team exercises, external assessments, customer security reviews, audit requests, and remediation validation related to cloud and platform security.
- Research emerging cloud security threats, cloud misconfiguration patterns, container escape techniques, Kubernetes attack paths, serverless risks, SaaS platform risks, API abuse patterns, and AI infrastructure security risks.
- Communicate cloud security risks clearly to engineering, infrastructure, product, compliance, security, and leadership stakeholders.
- Help maintain security standards and practices that support Paymentus’ obligations as a publicly traded fintech and payment technology company, including PCI DSS, SOC 2, SOX-related technology controls, privacy obligations, customer security commitments, and internal security policies.
Supervisory Responsibility
This role does not have direct supervisory responsibility.
The Cloud Security Engineer is expected to provide technical leadership, mentorship, and guidance to engineering, cloud infrastructure, DevOps, platform engineering, and security stakeholders. This includes helping teams understand cloud security risks, adopt secure platform patterns, and remediate cloud, Kubernetes, container, serverless, and infrastructure security issues effectively.
Education and Experience
- Bachelor’s Degree in Engineering, Computer Science, Software Engineering, Information Security, or a related technical field, or equivalent practical experience.
- 5+ years of experience in cloud security, infrastructure security, platform security, DevSecOps, security engineering, cloud engineering, site reliability engineering, or a closely related technical role.
- Hands-on experience securing workloads in one or more major public cloud platforms, with strong preference for practical experience across AWS, GCP, and Azure.
- Strong understanding of cloud-native architecture, SaaS platforms, microservices, distributed systems, RESTful APIs, authentication, authorization, encryption, logging, monitoring, and service-to-service communication.
- Deep knowledge of cloud identity and access management, including least privilege, role-based access, service accounts, workload identity, cross-account access, privileged access, federation, and access governance.
- Hands-on experience with Kubernetes security, including RBAC, cluster hardening, admission control, network policies, pod security controls, secrets management, workload isolation, and runtime security.
- Hands-on experience with container security, including image scanning, base image hardening, container registries, image signing or provenance, runtime controls, and containerized application deployment patterns.
- Experience securing serverless technologies, including function permissions, event-driven architectures, secrets handling, logging, monitoring, and abuse-prevention patterns.
- Experience with infrastructure as code and policy-as-code technologies such as Terraform, CloudFormation, or similar tools.
- Experience securing CI/CD pipelines, source control systems, build systems, artifact repositories, container registries, deployment workflows, and release automation.
- Experience with cloud security tools and practices such as CSPM, CNAPP, CWPP, CIEM, cloud vulnerability management, cloud asset inventory, cloud detection engineering, IaC scanning, container scanning, and secrets scanning.
- Strong knowledge of cloud networking and perimeter controls, including segmentation, routing, firewall rules, private endpoints, load balancers, TLS, DNS, ingress/egress controls, API gateways, and exposure management.
- Familiarity with CDN, WAF, bot mitigation, rate limiting, edge security, and origin protection using platforms such as Cloudflare and Fastly.
- Familiarity with application servers, web servers, and reverse proxy technologies such as Tomcat, JBoss, nginx, or similar platforms.
- Good understanding of modern application security guidelines, including OWASP Top 10, OWASP API Security Top 10, and OWASP Top 10 for Large Language Model Applications.
- Ability to analyze cloud security findings, determine exploitability, identify root cause, and recommend practical remediation steps.
- Ability to work independently, manage multiple priorities, and deliver high-quality results in a fast-paced engineering environment.
- Strong written and verbal communication skills, including the ability to explain cloud security risks clearly to technical and non-technical stakeholders.
- Strong collaboration skills and the ability to build trusted working relationships with engineering, product, DevOps, cloud infrastructure, compliance, and security teams.
Preferred Qualifications
- Experience working in fintech, payments, banking, financial services, or another highly regulated SaaS environment.
- Experience with payment processing environments, cardholder data environments, tokenization, payment APIs, transaction platforms, or fraud-related infrastructure.
- Experience supporting PCI DSS, SOC 2, SOX technology controls, NIST CSF, ISO 27001, or similar security and compliance frameworks.
- Experience securing multi-cloud environments across AWS, GCP, and Azure.
- Experience with Kubernetes admission controllers, service mesh security, cloud workload identity, runtime detection, image signing, software bill of materials, and supply chain security.
- Experience building cloud security guardrails, secure landing zones, reusable infrastructure modules, secure service templates, policy-as-code, or developer self-service security capabilities.
- Experience with cloud-native logging and detection tools, including cloud audit logs, SIEM integrations, security data lakes, threat detection rules, and incident investigation workflows.
- Experience with red team findings, penetration testing support, attack-path analysis, cloud incident response, or cloud threat hunting.
- Relevant certifications such as AWS Security Specialty, Google Professional Cloud Security Engineer, Azure Security Engineer, CCSP, CISSP, CKS, CKAD, CKA, Kubernetes Security Specialist, or equivalent practical experience.
Work Environment
This job operates in a professional office and technology environment. This role routinely uses standard office and engineering equipment, including laptop computers, collaboration tools, cloud platforms, security platforms, source code repositories, ticketing systems, and communication systems. The role requires frequent collaboration with geographically distributed teams and may involve participation in security incident response, urgent vulnerability remediation, production risk reviews, and executive briefings.
Physical Demands
While performing the duties of this job, the employee is regularly required to talk, hear, type, read, and view computer screens for extended periods. Specific vision abilities required by this job include close vision and the ability to adjust focus. The employee may occasionally be required to stand, walk, reach with hands and arms, lift files or equipment, open filing cabinets, bend, or stand on a stool as necessary. The employee may occasionally be required to lift up to 25 lbs.
Position Type/Expected Hours of Work
This is a full-time position. Days and hours of work are generally Monday through Friday during normal business hours. Occasional evening, weekend, or on-call work may be required based on business needs, security incidents, critical vulnerabilities, production releases, audit deadlines, or customer commitments.
Travel
Minimal travel is expected. Occasional travel may be required for company meetings, team events, customer security discussions, conferences, audits, or vendor engagements.
Other Duties
This job description is not designed to cover or contain a comprehensive listing of all activities, duties, or responsibilities required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.
EEO Statement
Paymentus is an equal opportunity employer. We enthusiastically accept our responsibility to make employment decisions without regard to race, religious creed, color, age, sex, sexual orientation, national origin, ancestry, citizenship status, religion, marital status, disability, military service or veteran status, genetic information, medical condition including medical characteristics, or any other classification protected by applicable federal, state, provincial, and local laws and ordinances. Our management is dedicated to ensuring the fulfillment of this policy with respect to hiring, placement, promotion, transfer, demotion, layoff, termination, recruitment advertising, pay, and other forms of compensation, training, and general treatment during employment.
Reasonable Accommodation
Paymentus recognizes and supports its obligation to endeavor to accommodate job applicants and employees with known physical or mental disabilities who are able to perform the essential functions of the position, with or without reasonable accommodation. Paymentus will endeavor to provide reasonable accommodations to otherwise qualified job applicants and employees with known physical or mental disabilities, unless doing so would impose an undue hardship on the Company or pose a direct threat of substantial harm to the employee or others.
An applicant or employee who believes he or she needs a reasonable accommodation of a disability should discuss the need for possible accommodation with the Human Resources Department, or his or her direct supervisor.