Senior Product Security Engineer
payabl. Lisbon, Portugal
Financial Services · 201-500 employees
About the role
You will design and implement security gates across the software development lifecycle and lead threat modeling for new products. Additionally, you will operate application security tooling and drive remediation efforts while fostering a security-first culture within engineering teams.
What they look for
Requirements
The role requires at least 5 years of experience in product or application security with strong hands-on expertise in CI/CD and supply-chain security. Candidates must demonstrate the ability to influence engineering teams and possess strong verbal and written English communication skills.
Benefits
Full description
The role is about:
We are looking for a Senior Product Security Engineer to strengthen and scale product security across our engineering organisation. Reporting to the Head of Information Security, you will embed security directly into the software development lifecycle — from architecture and design through build, deployment, and remediation — helping us launch secure products across card issuing, embedded finance / banking-as-a-service, and other payment solutions.
This is a hands-on senior role with real ownership: you will introduce security gates into engineering workflows, select and operate the right application security tooling, improve CI/CD and software supply-chain security, and use AI and automation to increase security coverage without slowing product delivery.
- Location: Limassol, Cyprus
- Reporting to: Head of Information Security
What you will do:
- Design and introduce security gates into the development lifecycle, including security requirements at design stage
- Lead threat modelling for new products and major changes
- Introduce security review practices into the pull-request flow
- Provide secure-by-design input for new product builds across card issuing, embedded finance / banking-as-a-service, and other payment products
- Select, deploy, and operate application security tooling across static analysis (SAST), software composition analysis (SCA), secrets detection, and dynamic testing (DAST)
- Decide pragmatically where traditional tooling is the right fit and where AI-assisted alternatives provide better coverage or efficiency
- Build AI-assisted secure code review and finding triage into the engineering workflow
- Own CI/CD pipeline and software supply-chain security controls across engineering teams
- Implement and improve container image scanning, dependency management, software bill of materials, and security checks on infrastructure-as-code and deployment manifests
- Help ensure secure release practices are embedded in the way software is built and deployed
- Operate and maintain the group’s Product Security Requirements as a living standard applied to real launches
- Drive remediation of application-layer findings with engineering teams, including findings from penetration tests, scanners, and disclosure reports
- Define realistic SLAs, track remediation ageing, and provide honest reporting
- Build product security awareness and capability across engineering through training, design reviews, and security champions initiatives
- Apply AI and automation to day-to-day product security work, including code review support, finding triage, and workflow acceleration
- Help extend security review coverage across multiple engineering teams without introducing unnecessary friction
What we need:
- 5+ years of experience in Product Security, Application Security, Security Engineering, or a closely related software security role
- Strong hands-on experience embedding security into the software development lifecycle
- Proven experience with threat modelling, secure-by-design reviews, and working with engineers during architecture and delivery stages
- Hands-on experience with application security tooling such as SAST, SCA, secrets detection, and DAST
- Experience securing CI/CD pipelines and improving software supply-chain security
- Ability to work directly with engineering teams and influence secure delivery in practice, not just through policy
- Strong ownership mindset — able to define, implement, improve, and drive adoption of security practices across multiple teams
- Strong written and verbal English
Nice to have:
- Experience in payments, fintech, banking, e-money, or another regulated product environment
- Experience supporting new product launches in cloud-native or API-driven environments
- Familiarity with container security, Kubernetes security, and infrastructure-as-code security
- Experience with AI-assisted security workflows or automation in AppSec / Product Security
- Detection-as-code or security-as-code mindset
- Certifications such as CISSP, CSSLP, CCSP, OSCP, or similar
Hiring Process:
- Step 1 – Thinking in Action (40 minutes) Your first conversation will be with our Talent Acquisition team. We'll explore your background, career journey, motivations, and overall fit for the role. As part of this discussion, you'll also complete a short technical screening that will be reviewed by our engineering team. This stage helps us understand both your experience and how you approach technical challenges.
- Step 2 – Hiring Manager interview (60-minutes) you will meet the hiring manager Head of Information Security, to explore your skills, achievements, and alignment with the role.
- Step 3 – Final Interview (45 minutes) The final stage is a group interview with senior members of our Technology squad, which may include the CTO, CPO and Head of Security. Together, we'll discuss team fit, collaboration style, expectations from both sides, and any remaining questions about the role, team, or technology domain. This is also an opportunity for you to learn more about our culture and ways of working.
The perks of being a payabl.er:
- Future-Proof Your Finances: Once you’ve passed probation, we’ll kickstart your Provident Fund to secure your future.
- Grow with Us: Annual Learning Budget for professional development (eligible after probation)—because your growth is our growth.
- Wolt Your Way Through Lunch: €150 monthly Wolt allowance to keep you fueled and happy.
- Stay Active Your Way: Enjoy a SportsBenefits membership giving you access to a wide variety of gyms and sports facilities to support your active lifestyle.
- Drive in Style: After one year with us, you may be eligible for a company car—performance and availability permitting.
- Park with Ease: Complimentary parking space just steps from the office, so your commute is as smooth as your workday.
- Max Out Your Downtime: 25 days of vacation + public holidays + 10 days of sick leave.
- Shop & Save: Exclusive local discount card + tickets for exciting events like Beonix, basketball games, and more.
- Speak Like a Local: Join free Greek language classes, twice a week, open to all team members.
- Celebrate Together: We bring colleagues from all offices together for unforgettable company celebrations.
- Global Collaboration & Events: Opportunities to participate in international company events and initiatives, connecting with colleagues from all regions and contributing to a truly global community
The benefits listed above are for our Cyprus office location only, a list of benefits and contract type will be assessed subject to your location and discussed in the first interview with your Talent Acquisition Partner.
Let's embark on a journey to redefine the landscape of payments together. We're not just offering a role; we're inviting you to be a part of something bigger. Join our team, and let's innovate, disrupt, and lead the future of payments. Together, we can make an impact that resonates. Welcome to the team!
Please review our Privacy Policy to understand how we process your personal data during the recruitment process: https://payabl.com/privacy-policy
Similar roles
-
Cloud & Security Engineer (m/w/d)
MPC Münchmeyer Petersen & Co. GmbH Hamburg, Germany
-
Senior Security Engineer
Roofr Canada
-
Lead Security Engineer – Infrastructure, HSM
JPMorgan Chase & Co. Bengaluru, Karnataka, India
- Security Engineer
-
Senior Security Engineer
Daylight Security New York, New York, United States
-
VDOT Application Security Architect
TOMORROW HIRE Richmond, Virginia, United States · $168K–$210K/yr