
An Introduction to Primer
Primer is the unified infrastructure for global payments. We give finance and payments teams the visibility and control to reduce complexity, improve performance, and capture more revenue - all from a single platform.
Which team will you be joining?
You'll be joining the ProdSec/AppSec team to help build the entire product security surface for a company processing payments at scale: threat modelling, security review, compliance, incident escalation, and the multi-year AppSec roadmap. You'd be the second hire, and the function that function finally gets to share the work with.
This is a hands-on delivery role, and a genuinely formative one. You'll help set the security strategy and architecture; you take real ownership of the work that turns it into reality, reviews, research, automation, and the day-to-day partnership with engineering teams.
What will you be doing?
- Running security reviews and threat modelling on features and systems across Primer's product, and turning findings into clear, actionable guidance
- Independently planning and delivering your own security projects, from initial design through to rollout
- Building tooling and automation that makes future reviews faster and cheaper to run
- Coordinating penetration testing and tracking remediation through to closure
- Supporting recurring compliance work (SOC2, PCI), including evidence collection and remediation tracking
- Contributing to AppSec roadmap initiatives across application threats, AI security, supply chain security, and ASPM
- Picking up proactive security work, threat research and hands-on investigation
- Working alongside Cloud, Infra, and GRC on the security aspects of their projects
What we're looking for
- Working experience in product or application security: security reviews or threat modelling and spotting risks that matter
- Ability to read and write code, not just review it. Comfortable building small tools and automation
- Sound judgement about risk and the ability to explain reasoning clearly
- Ability to plan and deliver work independently
- Clear communication with engineers who aren't security specialists
Nice to have:
- Exposure to compliance frameworks like SOC2 or PCI
- Background in payments, fintech, or another regulated, high-stakes domain
- Interest in supply chain security, detection engineering, or AI security
Benefits
- Fully remote and globally distributed team
- Competitive share options
- Uncapped holiday (25 days minimum)
- Co-working space access across major cities
- Workations & Company Retreat
- Β£500 towards home office setup
- Generous learning budget
- Private Medical Insurance
Timezone overlap
UTC+0β+3
Culture
Async-friendly
Benefits
Equity, Unlimited PTO, Coworking, Home office, Learning, Health, Equipment, Commission, Parental leave
Open to
Europe Β· Africa
Sign in to track applications and earn points.