Skip to main content
Paymentus logo

Cloud Security Engineer

Paymentus
9 hours ago
Full-time
On-site
Richmond Hill, CA

Paymentus, a fintech company delivering cloud-native payments software, is looking for a Cloud Security Engineer to join its on-site team in Richmond Hill, CA. The role reports to the Manager of Security Engineering and Works closely with Engineering, Cloud Infrastructure, DevOps, Platform Engineering, Product, Compliance, Security Operations, and Application Security. If you enjoy hands-on work securing cloud-native infrastructure and partnering with engineering teams to embed security into deployment and operations, this could be the right challenge for you.

The position centers on protecting Paymentus’s cloud-native stack, across public cloud platforms, Kubernetes, containers, serverless technologies, CI/CD pipelines, infrastructure as code, cloud identity, network controls, secrets management, logging, and monitoring. It demands practical cloud security know-how across AWS, GCP, and Azure, with a track record of securing modern SaaS platforms, web apps, RESTful APIs, microservices, and distributed systems. You’ll assess cloud architectures, spot insecure patterns, build scalable controls, automate security checks, and work directly with engineers to remediate risk without slowing delivery.

On-site in Richmond Hill, the role blends deep technical work with collaboration across security, engineering, and product teams. It’s ideal for someone who can translate complex security concepts into actionable changes, help establish secure patterns, and guide teams through practical risk reduction in a fast-moving environment.

Guarding Paymentus cloud, day by day

Your daily work weaves security into how the cloud is designed, provisioned, and operated. You’ll partner with engineering and infrastructure teams to bake security into cloud architecture, platform design, and production operations, ensuring secure deployment and reliable running of services. You’ll perform cloud security architecture reviews for workloads across AWS, GCP, and Azure, covering compute, storage, networking, identity, encryption, logging, and service-to-service communication, and you’ll continuously improve IAM controls, including least privilege, role design, workload identity, cross-account access, and access governance. You’ll harden Kubernetes and containerized workloads, implement serverless security controls, and review infrastructure as code for misconfigurations and policy violations. Building automated guardrails, policy-as-code, and CI/CD security gates will be a core part of your job, helping developers move quickly while staying secure. You’ll also help secure cloud networking, edge security with CDN and WAF platforms, and API security across RESTful APIs, API gateways, and service mesh, while maintaining visibility through cloud-native logging and detection platforms. Collaboration with Security Operations, Incident Response, and engineering teams ensures rapid remediation and improved threat detection. You’ll help establish secure baselines, reference architectures, and deployment patterns, and you’ll support penetration testing, audits, and external assessments as needed. Research into emerging cloud threats and misconfiguration patterns will keep Paymentus ahead of risk, and clear communication of security risks to technical and leadership stakeholders will be essential.

Your must-haves to join the cloud security team

  • Bachelor’s degree in engineering, computer science, software engineering, information security, or a related technical field, or equivalent practical experience
  • About five or more years working in cloud security, infrastructure security, platform security, or related security engineering roles
  • Hands-on experience securing workloads in major public clouds, with strong preference for experience across AWS, GCP, and Azure
  • Solid grasp of cloud-native architectures, SaaS platforms, microservices, RESTful APIs, authentication, authorization, encryption, logging, monitoring, and service-to-service communication
  • Advanced knowledge of cloud IAM, including least privilege, role design, service accounts, workload identity, cross-account access, privileged access, federation, and access governance
  • Hands-on Kubernetes security experience, including RBAC, cluster hardening, admission controls, network policies, pod security, secrets management, and runtime security
  • Practical experience with container security, covering image scanning, base image hardening, registries, image provenance, runtime controls, and deployment patterns
  • Experience securing serverless technologies, such as function permissions, event source validation, secrets handling, logging, and abuse prevention
  • Familiarity with infrastructure as code and policy-as-code tools (Terraform, CloudFormation or equivalent)
  • Background securing CI/CD pipelines, source control, build and release processes, artifact repositories, and deployment workflows
  • Proficiency with cloud security tooling (CSPM, CNAPP, CWPP, CIEM, cloud vulnerability management, IaC scanning, container scanning, and secrets scanning)
  • Strong knowledge of cloud networking and perimeter controls (segmentation, routing, firewalls, private endpoints, TLS, DNS, API gateways, exposure management)
  • Familiarity with CDN, WAF, bot mitigation, rate limiting, edge security, and origin protection using Cloudflare and Fastly
  • Experience with common app servers and reverse proxies (Tomcat, JBoss, nginx or equivalents) and modern app security guidelines (OWASP Top 10, OWASP API Security Top 10, and OWASP Top 10 for Large Language Model Applications)
  • Ability to analyze cloud security findings, identify root causes, and recommend practical remediation steps
  • Capacity to work independently, juggle multiple priorities, and deliver solid results in a fast-moving engineering environment
  • Strong written and verbal communication, able to explain risks clearly to technical and non-technical stakeholders
  • Proven collaboration skills and the ability to build trusted relationships with engineering, product, DevOps, cloud infrastructure, compliance, and security teams

Nice-to-haves that help you stand out

  • Experience in fintech, payments, banking, or other highly regulated SaaS settings
  • Background with payment processing environments, cardholder data environments, tokenization, payment APIs, transaction platforms, or fraud infrastructure
  • Experience supporting PCI DSS, SOC 2, SOX tech controls, NIST CSF, ISO 27001, or similar frameworks
  • Experience securing multi-cloud environments across AWS, GCP, and Azure
  • Knowledge of Kubernetes admission controllers, service mesh security, cloud workload identity, runtime detection, image signing, SBOM, and supply chain security
  • Experience building cloud security guardrails, landing zones, reusable modules, policy-as-code, or developer self-service security capabilities
  • Familiarity with cloud-native logging and detection tools, cloud audit logs, SIEM integrations, and incident investigation workflows
  • Experience supporting red team findings, penetration testing, attack-path analysis, cloud incident response, or cloud threat hunting
  • Certifications such as AWS Security Specialty, Google Professional Cloud Security Engineer, Azure Security Engineer, CCSP, CISSP, CKS, CKAD, CKA, or Kubernetes Security Specialist

Pay, benefits and practical details

This is a full-time, on-site role based in Richmond Hill, CA, in a professional office and technology-focused environment. The team works with laptops, cloud platforms, security platforms, source code repositories, ticketing systems, and collaboration tools, with regular collaboration among distributed teams and possible involvement in security incident response and urgent vulnerability remediation.

Typical work hours are Monday through Friday during normal business hours, with occasional evenings, weekends, or on-call work based on business needs, security incidents, critical vulnerabilities, production releases, audit deadlines, or customer commitments. Travel is minimal, with occasional trips for meetings, events, customer security discussions, conferences, audits, or vendor engagements. The role may involve shifting tasks as needed, and there are no specific salary figures provided here. Paymentus is an equal opportunity employer and supports reasonable accommodations for applicants with disabilities; discuss any accommodation needs with human resources or a direct supervisor.

Tips to shine in this cloud security role

Highlight in your resume that you bring 5+ years of hands-on cloud security experience across AWS, GCP, and Azure, with concrete examples of securing SaaS platforms and distributed systems.

Demonstrate the must-have skills with real-world projects. Describe how you implemented RBAC, workload identity, and cross-account access in a multi-cloud setup, or how you automated IaC security checks and CI/CD gates that prevented insecure deployments.

Prepare to discuss how you would approach a cloud security architectural review for a new SaaS workload, including how you assess identity, network controls, data protection, logging, and service-to-service communication, plus how you would present remediation plans to engineering teams.

Ask a targeted question about the role’s security program, for example how Paymentus aligns cloud security with PCI DSS, SOC 2, or other compliance obligations, or how the team uses guardrails or policy-as-code to enable developer self-service while maintaining control.