{"id":2032053,"url":"https://alion.io/job/repay-application-security-engineer","title":"Application Security Engineer","company":{"id":2422893,"name":"REPAY","domain":"repay.com","url":"https://alion.io/company/repay-com","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"explicit","locations":["Atlanta, United States","United States"],"countries":["US"],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":116000,"max_usd":211000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":256},"experience_years_min":5,"visa_sponsorship":true,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agentic Workflows","optional":false},{"name":"AI Agents","optional":false},{"name":"Amazon ECS","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"C#","optional":false},{"name":"CI/CD","optional":false},{"name":"CIS Benchmarks","optional":false},{"name":"Docker","optional":false},{"name":"Go","optional":false},{"name":"IAM","optional":false},{"name":"JavaScript","optional":false},{"name":"Kubernetes","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP ASVS","optional":false},{"name":"OWASP SAMM","optional":false},{"name":"PCI DSS","optional":false},{"name":"Python","optional":false},{"name":"Terraform","optional":false},{"name":"Threat Modeling","optional":false},{"name":"TypeScript","optional":false},{"name":"LLM","optional":true},{"name":"OWASP Top 10","optional":true},{"name":"Service Mesh","optional":true},{"name":"SOC 2","optional":true},{"name":"Zero Trust","optional":true}],"status":"live","first_seen_at":"2026-09-10T00:00:00Z","employer_posted_date":"2026-09-10","last_verified_at":"2026-10-08T18:02:31Z","board_verified":true,"closed_at":null,"days_open":29,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":29},"description":"ABOUT REPAY\nREPAY (“Realtime Electronic Payments” / NASDAQ TICKER: RPAY) is an established and fast-growing publicly traded financial technology and payment processing company headquartered in Atlanta, Georgia, with offices across the country. REPAY enables its customers to accept payments anytime, anywhere, and through any channel while providing a secure, seamless, and enjoyable payment experience for the end consumers. REPAY offers a comprehensive suite of electronic payment and funding solutions, including debit and credit card processing, ACH processing, Instant Funding, and electronic bill payment systems with full IVR, text, and mobile capabilities. The scalability of its products allows merchants of all sizes to add an instant arsenal of intelligent payment technology solutions to their businesses without significant development costs or infrastructure investments.\nABOUT THE ROLE\nREPAY is seeking a highly motivated, self-driven Security Engineer to help lead our Product Security efforts across application and cloud security. This role partners primarily with engineering and infrastructure teams to strengthen the security controls behind REPAY’s payment products, improving the resiliency of the applications and cloud environments our customers depend on. You will review new applications, features, and implementations to identify security requirements and improvement opportunities, and you will define the application and cloud security standards that engineering builds against.\nThis is an architecture-leaning, hands-on role: you will work alongside software engineers, infrastructure engineers, and solution architects to drive adoption of those standards, and you will build custom applications and automation that make secure patterns the path of least resistance. You will also help shape how REPAY applies AI to improve the efficiency of security controls and how we secure the AI capabilities embedded in our own products. The ideal candidate is fluent in modern application and cloud security frameworks, communicates credibly with developers, and prefers scalable engineering solutions over manual gatekeeping.\nRESPONSIBILITIES\nApplication and Cloud Security Architecture\nReview new applications, features, integrations, and infrastructure implementations to identify security requirements, design flaws, and improvement opportunities.\n\nConduct threat modeling and secure design reviews early in the development lifecycle, translating findings into prioritized, actionable engineering requirements.\n\nServe as the security architecture partner for product and platform initiatives, providing pragmatic guidance that balances risk, delivery timelines, and engineering effort.\n\nEvaluate architectural risk across authentication, authorization, data protection, tenancy isolation, secrets handling, and third-party integrations.\n\nSecurity Standards and Requirements\nDefine, document, and maintain application and cloud security standards, secure design patterns, and reference architectures.\n\nMap standards to recognized frameworks such as OWASP ASVS and Top 10, NIST SSDF, CIS Benchmarks, and PCI DSS requirements relevant to REPAY’s products.\n\nPartner with engineering leaders, infrastructure teams, and architects to plan and drive implementation of standards, including remediation roadmaps for existing systems.\n\nMeasure and report on adoption, coverage, and exceptions, and continuously refine standards based on real-world engineering feedback.\n\nApplication Security Engineering\nOwn and optimize application security tooling, including SAST, DAST, SCA, secrets scanning, and API security testing, integrated directly into CI/CD pipelines.\n\nManage web application firewall (WAF) policy design, tuning, rule development, and monitoring to protect production applications.\n\nTriage and validate findings, reduce false positives, and partner with development teams on root cause remediation rather than one-off fixes.\n\nSupport secure coding enablement through guidance, code review support, developer training, and security champions model.\n\nCloud Security and Infrastructure as Code\nImprove cloud security posture using CSPM and cloud-native security services, driving remediation of misconfigurations and risky identity and network exposure.\n\nDefine and implement secure Infrastructure as Code patterns and guardrails in Terraform, including policy as code and pre-deployment validation.\n\nSecure containerized environments, covering image hardening, registry scanning, runtime protection, orchestration configuration, and workload identity.\n\nPartner with infrastructure and cloud engineering teams to embed security controls into landing zones, pipelines, and platform services by default.\n\nCustom Development and Automation\nDevelop, implement, and manage custom applications, services, and integrations that extend and connect security capabilities.\n\nAutomate recurring security engineering tasks such as evidence collection, control validation, routing findings, and reporting using APIs and scripting.\n\nMaintain code quality, testing, and operational support for the tooling you build, treating internal security tools as production software.\n\nAI Enablement and Securing AI in Products\nEvaluate and apply AI and agentic tooling to improve the efficiency and coverage of application and cloud security controls, including triage, code review, and remediation guidance.\n\nDefine security requirements and design patterns for AI capabilities built into REPAY’s custom applications, addressing prompt injection, data exposure, model and tool abuse, and agent authorization.\n\nPartner with engineering teams to implement guardrails, logging, and monitoring for AI-enabled features and agentic workflows.\n\nCollaboration and Cross-Team Enablement\nDrive complex, multi-team initiatives from design through adoption, coordinating across product engineering, infrastructure, architecture, and security functions.\n\nTranslate security requirements and risk for both technical and non-technical stakeholders, including product owners and leadership.\n\nSupport Security Operations and Incident Response teams during application or cloud-related incidents and convert findings into durable control improvements.\n\nSKILLS & EXPERIENCE NEEDED\nQualifications:\nBachelor's degree in computer science, Information Systems, or a related field, or equivalent practical experience.\n\n5+ years of experience in application security, cloud security, product security, or software engineering with a security focus.\n\nDemonstrated experience performing secure design reviews and threat modeling for modern applications and cloud architectures.\n\nFluency with application and cloud security frameworks such as OWASP ASVS and Top 10, OWASP SAMM, NIST SSDF, CIS Benchmarks, and cloud provider security best practices.\n\nHands-on experience with SAST, DAST, SCA, and WAF technologies, including pipeline integration and policy tuning.\n\nWorking experience with CSPM tooling and securing AWS and/or Azure environments, including IAM, networking, logging, and data services.\n\nExperience securing Infrastructure as Code, particularly Terraform, and applying policy as code guardrails.\n\nExperience securing containerized and orchestrated workloads (e.g., Docker, Kubernetes, ECS).\n\nProficiency in at least one programming language (e.g., Python, Go, Java, C#, JavaScript/TypeScript) sufficient to build custom applications and automation and to review application code.\n\nAbility to operate independently, drive complex initiatives, and influence engineering teams without direct authority.\n\nStrong analytical thinking, curiosity, and a desire to continuously improve security posture.\n\nPreferred Skills:\nFamiliarity with AI and agentic tooling, including using them to improve security control efficiency and securing AI features within custom applications, will be a plus.\n\nExperience with LLM and agent security risks, and with frameworks such as the OWASP Top 10 for LLM Applications will be a plus.\n\nExperience in payments, financial services, or another regulated environment, with practical exposure to PCI DSS or SOC 2 will be a plus.\n\nExperience building or operating a security champions program or developer-facing security enablement at scale.\n\nExperience with API security, service mesh, mTLS, and zero trust patterns for service-to-service communication.\n\nRelevant certifications (e.g., CISSP, CSSLP, GIAC GWEB/GCSA/GDSA/GPCS, OSWE, AWS or Azure Security Specialty, CCSP, CKS).\n\nWHY JOIN REPAY.… BECAUSE CULTURE IS EVERYTHING\nGROWTH & PEOPLE-CENTERED LEADERSHIP\nAs the industry-leading financial technology provider in the Consumer Finance and Business to Business spaces, we continue to set the standard for application development and delivery. In 2019, REPAY became a public company listed on the Nasdaq Stock Market (RPAY). For the past three consecutive years, we have placed on the ACG® Atlanta Georgia Fast 40, a list recognizing the top 40 fastest-growing middle-market companies in Georgia. REPAY’s leadership empowers each team member to make a difference and stretch to their fullest potential. Our dedication to frequent, transparent communication is shown with companywide meetings where our leaders share company vision and encourage employees to ask questions.\nFUN WORK ENVIRONMENT & GREAT TEAMS\nWe offer it all: business to casual dress, great snacks & beverages, and open-air collaborative team settings. REPAY has been certified as a Great Place to Work® company for 2017, 2018, 2019, 2020, 2021, and 2022. The REPAY team is fun, smart, collaborative, and truly enjoys working together. Making a difference in our local communities - we support several philanthropic initiatives every year to give back to our local communities. We are self-driven, motivated professionals who do not require micro-management to ensure we produce high quality and timely work.\nINNOVATION & EDUCATION\nWe create highly sophisticated payment processing applications and are always pushing the boundaries of what is possible. We are constantly revolutionizing the industry by building on new ideas from clients and employees. We provide the resources necessary to ensure new innovations can develop quickly and with quality. We encourage continuing education, including professional conferences and events.\nPUTTING OUR PEOPLE FIRST\nWe believe our people are the best, and we care immensely about their success. We offer a comprehensive benefits package which includes 100% coverage of employee healthcare premiums and several free benefits, including life insurance, disability insurance, and work-life balance resources. All benefits go into effect day one. Our employees’ futures are important to us, which is why we have a 401(k)-employer match and and an Employee Stock Purchase Plan. REPAY employees are eligible to participate in our Annual Bonus Program. This bonus award reflects excellent performance of individual contributions and goals achieved during the past year.\nREPAY’s core values are Excellence, Passion, Innovation, Respect, and Integrity.\nREPAY is an Equal Opportunity Employer and we promote a company culture where diversity, equity and inclusion are central. We are committed to build our teams and grow a company in which employees can succeed, regardless of race, color, national origin, sex, sexual orientation, gender identity or expression, transgender status, pregnancy, religion, age (40 and over), disability, service in the uniformed services, protected veteran status, genetic information, or any other classification protected by federal, state or local law. Celebrating our diverse backgrounds, views and beliefs allows us to embrace what makes us unique and continue to innovate and push the boundaries of what is possible.\nWe are interested in every qualified candidate who is eligible to work in the United States. This position is not eligible for hire in California. Additionally, we are not able to sponsor visas.","description_format":"text","description_chars":11963,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Equity","Life insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Blockchain & Crypto","Financial Services","Payment Processing & Gateways"],"lifecycle":[{"event":"open","at":"2026-10-07T14:37:02Z"}],"visa":[],"liveness":{"score":65,"band":"ok","label":"Likely open","p_open":1,"p_active":0.86,"p_room":0.75,"age_days":28,"expected_fill_days":38,"reasons":["conf:1","win:late"],"computed_at":"2026-10-08T05:49:30Z"},"pay":null,"html_url":"https://alion.io/job/repay-application-security-engineer","json_url":"https://alion.io/job/repay-application-security-engineer.json","meta":{"generated_at":"2026-10-09T00:50:11Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1222,"day_limit":5000,"remaining_today":3778,"minute_limit":60,"resets_at":"2026-10-10T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":2422893},"rest":"https://alion.io/mcp/rest/get_company?id=2422893"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Frepay-application-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Frepay-application-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Frepay-application-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/repay-application-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Frepay-application-security-engineer"}]}