About this role.
FastSpring is seeking a senior hands-on security engineer to strengthen application, cloud, and AI-assisted development security for its payments platform. The role spans Java application security, AWS infrastructure hardening, secure SDLC practices, vulnerability remediation, and reviews of agentic tooling. The engineer will partner with the Agentic Experience group, a fractional CISO, and executive stakeholders on risk, PCI DSS-related initiatives, monitoring, and incident readiness. Success requires strong AWS security expertise, sound prioritization, and the ability to translate technical security risks into actionable business priorities.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
5/5Pace & Pressure
4/5Autonomy Level
5/5Communication Load
5/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would combine technical severity with exploitability, asset criticality, exposure, data sensitivity, and available compensating controls. Internet-facing payment flows, identity systems, and vulnerabilities with active exploitation evidence would receive immediate attention, while lower-risk findings would enter a time-bound remediation plan with accountable owners.
I would first inventory identities, permissions, privilege-escalation paths, and unused access through tools such as IAM Access Analyzer and CloudTrail. I would then phase in least-privilege roles, permission boundaries, short-lived credentials, and automated policy validation, partnering with service owners to test changes and avoid breaking production workflows.
Key risks include source-code or secret leakage, untrusted tool integrations, excessive agent permissions, prompt injection, insecure generated code, and insufficient auditability. I would map data flows and permissions, restrict agents to least privilege, require approved integrations, implement logging and review controls, and define secure-use guardrails for developers.
I would start with high-signal checks and establish severity-based blocking rules focused on exploitable critical issues. Findings should be routed into existing developer workflows with clear ownership, remediation guidance, baselining for legacy debt, and measurable service-level objectives rather than indiscriminately blocking every build.
I would explain the risk in business terms: affected systems, likelihood, potential customer or regulatory impact, current controls, and the decision needed. I would present a concise remediation plan with cost, timeline, residual risk, and clear options so leadership can make an informed prioritization decision.
About FastSpring:
FastSpring is how AI, SaaS, gaming, software, and digital product companies sell online in more places around the world. We handle all payment needs from checkout to taxes so you can go farther faster.
Founded in 2005, we are a privately owned company headquartered in Santa Barbara with offices in Amsterdam, Austin, Belfast, Dublin, Halifax, and Singapore.
Sr. Security Engineer
Position Overview:
We are seeking a Sr. Security Engineer to join our Agentic Experience group, reporting to the Principal Engineer, Agentic Development. In this role, you will strengthen the security posture of our core payments platform while helping shape security practices for AI-assisted software development. You will work closely with our Agentic Experience group and our CISO, with visibility to executive leadership. This is a hands-on engineering role with broad scope: application security, cloud infrastructure security, and security review of AI/agentic development tooling.
Responsibilities & Goals:
- Identify, prioritize, and remediate vulnerabilities across our Java-based platform and AWS infrastructure
- Drive infrastructure security improvements, including IAM policy refinement, instance metadata protections, and network egress controls
- Conduct security reviews of AI-assisted development pipelines, tool integrations, and agent-accessible services
- Develop and maintain secure development standards, patterns, and guardrails for engineering teams
- Partner with the fractional CISO on risk assessment, remediation planning, and compliance initiatives (including PCI DSS)
- Contribute to incident response readiness and security monitoring improvements
- Communicate security priorities and progress clearly to technical and executive stakeholders
Experience & Qualifications:
- 7+ years of hands-on security engineering experience (application security, cloud security, or infrastructure security)
- Strong experience with AWS security services and primitives (IAM, VPC networking, secrets management)
- Experience working in and securing large production codebases; JVM ecosystem experience preferred
- Familiarity with modern AI-assisted development tools and an interest in their security implications
- Strong prioritization and communication skills; ability to advocate for security investments with stakeholders
- Experience in payments, fintech, or other regulated environments is a plus
- Relevant certifications (e.g., CISSP, OSCP, AWS Security Specialty) are a plus but not required
Nice to Have
- Security certifications (e.g., AWS Security Specialty, CISSP, OSCP, GIAC).
- Experience securing payments, ecommerce, or subscription/billing platforms.
- Experience with secure SDLC practices and integrating security tooling (SAST/DAST/SCA) into CI/CD.
- Familiarity with global, multi-currency, or tax-calculation systems and their data-sensitivity considerations.
Consistent with FastSpring’s values and applicable law, we provide the following information to promote pay transparency and equity. The base pay range below represents a good faith estimate of the low and high end base pay range for the listed position. This role may be eligible for the corporate bonus plan (or, if a sales role, a commission plan as defined in the sales incentive plan document). In addition, FastSpring provides a variety of benefits to employees.
Estimated Base Pay Range
$155,000—$187,000 USD
About the Company:
FastSpring is an EQUAL EMPLOYMENT OPPORTUNITY/AFFIRMATIVE ACTION employer. Candidates are considered for employment with FastSpring without regard to their race, color, religion, national origin, age, sex, gender, pregnancy, disability, sexual orientation, gender identity, genetic information, military status, veteran status (specifically status as a disabled veteran, special disabled veteran, Vietnam Era veteran, recently separated veteran, armed forces service medal veteran, or other protected veteran) or other classification protected by applicable federal, state or local law.
AI Transparency Statement:
FastSpring may utilize artificial intelligence (AI) or automated tools during portions of the recruitment process to assist with operational and administrative activities, including candidate communications, scheduling, application organization, and interview documentation. These tools are designed to support efficiency and consistency within the hiring process. AI systems are not used as the sole determinant of hiring outcomes, and all employment decisions are made by qualified human reviewers. We are committed to responsible and fair hiring practices and continue to evaluate our use of technology accordingly.
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.









