Remote
Sr. Security Engineer
About this role
About FastSpring: FastSpring is how AI, SaaS, gaming, software, and digital product companies sell online in more places around the world. We handle all payment needs from checkout to taxes so you can go farther faster. Founded in 2005, we are a privately owned company headquartered in Santa Barbara with offices in Amsterdam, Austin, Belfast, Dublin, Halifax, and Singapore. Sr. Security Engineer Position Overview: We are seeking a Sr.
Security Engineer to join our Agentic Experience group, reporting to the Principal Engineer, Agentic Development. In this role, you will strengthen the security posture of our core payments platform while helping shape security practices for AI-assisted software development. You will work closely with our Agentic Experience group and our CISO, with visibility to executive leadership. This is a hands-on engineering role with broad scope: application security, cloud infrastructure security, and security review of AI/agentic development tooling.
Responsibilities & Goals: Identify, prioritize, and remediate vulnerabilities across our Java-based platform and AWS infrastructure Drive infrastructure security improvements, including IAM policy refinement, instance metadata protections, and network egress controls Conduct security reviews of AI-assisted development pipelines, tool integrations, and agent-accessible services Develop and maintain secure development standards, patterns, and guardrails for engineering teams Partner with the fractional CISO on risk assessment, remediation planning, and compliance initiatives (including PCI DSS) Contribute to incident response readiness and security monitoring improvements Communicate security priorities and progress clearly to technical and executive stakeholders Experience & Qualifications: 7+ years of hands-on security engineering experience (application security, cloud security, or infrastructure security) Strong experience with AWS security services and primitives (IAM, VPC networking, secrets management) Experience working in and securing large production codebases; JVM ecosystem experience preferred Familiarity with modern AI-assisted development tools and an interest in their security implications Strong prioritization and communication skills; ability to advocate for security investments with stakeholders Experience in payments, fintech, or other regulated environments is a plus Relevant certifications (e.g., CISSP, OSCP, AWS Security Specialty) are a plus but not required Nice to Have Security certifications (e.g., AWS Security Specialty, CISSP, OSCP, GIAC).