Sr. Manager, Application Security - Remote
PayNearMeAbout the role
Company Description
At PayNearMe, we’re on a mission to make paying and getting paid as simple as possible. We build innovative technology that transforms the way businesses and their customers experience payments. Our industry-leading platform, PayXM™, is the first of its kind—designed to manage the entire payment experience from start to finish. Every click, swipe or tap is seamless, fast and secure, helping non-commerce businesses boost customer satisfaction, accelerate payments, and reduce costs.
Our single platform handles it all: cards, ACH, digital wallets such as PayPal, Venmo, Cash App Pay, Apple Pay and Google Pay, and even cash at more than 62,000 retail locations nationwide. Today, thousands of businesses across consumer lending, iGaming and online sports betting, property management, and tolling trust PayNearMe to deliver a payment experience that drives real results.
In September 2025, we raised a $50 million Series E funding round to accelerate our growth.
We’re a team of 200+ employees across 41 states, headquartered in Silicon Valley with satellite offices in Dallas, TX and Holmdel, NJ.
Join us and be part of a team that’s shaping the future of payments—one experience at a time.
Job Description
We are seeking a Sr Manager, Application Security to lead and mature our Application Security program across a complex environment consisting of both a Ruby-based monolith and distributed Go microservices. This leader will be responsible for building, scaling, and operationalizing secure development practices that integrate seamlessly into our CI/CD pipelines and Agile delivery model.
This role will oversee application security reviews, threat modeling, secure code practices, and optimization of SAST/SCA tooling to ensure meaningful, actionable insights for Engineering leadership. The ideal candidate combines strong technical depth with strategic leadership and the ability to drive security outcomes in a fast-moving fintech environment.
Responsibilities:
- Lead the Application Security team, including hiring, mentoring, and performance management.
- Define and execute the Application Security roadmap aligned with business priorities and regulatory obligations (e.g., PCI, SOC 2).
- Partner closely with Engineering, Product, QA, Infrastructure, and DevOps leadership to embed security early in the SDLC.
- Oversee security design reviews and code security reviews across:
- Go-based microservices
- Ruby-based monolith applications
- Provide technical guidance on secure architecture decisions in a cloud-first (AWS) environment.
- Own and continuously improve the organization’s threat modeling framework and ensure it’s embedded in new feature development and architectural changes.
- Ensure SAST and SCA tooling is integrated into CI/CD and appropriately tuned to reduce false positives.
- Drive meaningful reporting dashboards for Development and Engineering leadership.
- Establish and operationalize a risk-based vulnerability prioritization framework and scoring rubric aligned with OWASP guidance and applicable industry standards.
- Act as a trusted advisor to Engineering leadership and influence architectural decisions that reduce systemic risk.
Qualifications
- 8+ years of experience in Application Security or Secure Software Engineering.
- 3+ years leading or managing technical security teams.
- Strong hands-on experience with:
- Ruby (Rails) application security
- Go (Golang) application security
- Deep knowledge of:
- Secure SDLC practices
- Threat modeling methodologies (e.g., STRIDE, attack trees)
- SAST and SCA tools and rule tuning
- OWASP Top 10 and API Security Top 10
- Experience integrating security tools into CI/CD pipelines.
- Familiarity with cloud-native application security in AWS environments.
- Strong understanding of microservices security patterns (service-to-service auth, token handling, API gateways, etc.).
- Strong communicator capable of influencing senior engineering leaders.
Additional Qualifications that are a plus:
- Experience in fintech, payments, or other regulated environments.
- Knowledge of PCI DSS and SOC 2 security expectations.
- Experience with container security and Kubernetes-based deployments.
- Experience building security metrics and executive-level reporting.
- Passionate about mentoring engineers and raising secure coding maturity.
Additional Information
Why Join Us?:
- Competitive salary and benefits with growth-company options grant
- Fast- paced and professional work culture
- Stock options with standard startup vesting - 1 year cliff; 4 years
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s