payabl.
Senior Product Security Engineer
Remote role where the employee must remain based in a particular country.
Portugal only
Employer listed it 7 days ago · Found 1h ago
First listed 7 days ago and still open.
Salary
Not stated
Location
Portugal only
Timezone
CET ±2
Contract
Full-time
Experience
Senior
Category
Software
This employer didn't state pay. Jobs like this usually pay around $165k–$225k a year, a typical range taken from 597 senior-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in Portugal. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Portugal, Remote"
What Nomaders makes of it
- Residency required in Portugal
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
The role is about:
We are looking for a Senior Product Security Engineer to build product security across our engineering organization. You will build the practice, not inherit it. Reporting to the Head of Information Security, you will embed security directly into the software development lifecycle — from architecture and design through build, deployment, and remediation. You will introduce security gates into engineering workflows, select and operate the right application security tooling, and use AI and automation to increase security coverage without slowing product delivery.
Location: Fully remote from Portugal or Poland
Reporting to: Head of Information Security
What you will do:
Design and introduce security gates into the development lifecycle, including embeded secure release practices and guardrails into the way software is built and deployed.
Lead threat modelling for new products and major changes
Provide secure-by-design input for new product builds across card issuing, embedded finance / banking-as-a-service, and other payment products
Define secure-by-default architecture patterns for the application layer — authentication, authorization, API design, service-to-service trust — so the secure path is the easiest path for engineering teams
Decide where traditional tooling is the right fit and where AI-assisted alternatives provide better coverage or efficiency
Own CI/CD pipeline and software supply-chain security controls across engineering teams
Implement and improve container image scanning, dependency management, software bill of materials, and security checks on infrastructure-as-code and deployment manifests
Build the practice AI-first - introduce AI agents and LLM-assisted workflows the default delivery mechanism for application security
Drive remediation of application-layer findings with engineering teams, including findings from penetration tests, scanners, and disclosure reports
What we need:
5+ years of experience in Product Security, Application Security in payments, fintech, banking, e-money, or another fintech product environment
Strong hands-on experience embedding security into the software development lifecycle
You read code comfortably and hold your own in design discussions with senior engineers
Proven experience with threat modelling, secure-by-design reviews, and working with engineers during architecture and delivery stages
Hands-on experience with application security tooling such as SAST, SCA, secrets detection, and DAST
Hands-on experience securing cloud-native applications on AWS or other major cloud
Strong AI proficiency and hands-on experience (agentic workflows and loops, RAG, MCP, etc)
Solid understanding of Cloud-first environment and modern development practices
Experience securing CI/CD pipelines and improving software supply-chain security
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
- ·Grow with Us: Annual Learning Budget for professional development (eligible after probation)—because your growth is our growth.
- ·Celebrate Together: We bring colleagues from all offices together for unforgettable company celebrations.
- ·Global Collaboration & Events: Opportunities to participate in international company events and initiatives, connecting with colleagues from all regions and contributing to a truly global community
- ·Please review our Privacy Policy to understand how we process your personal data during the recruitment process: https://payabl.com/privacy-policy
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at payabl., mentioning your remote working experience and working hours (CET ±2).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 2h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $165k to $225k per year · You'll be taken to the employer's careers page.