Please Read Before Applying - *This role is located in Buffalo/Williamsville, NY in a hybrid capacity therefore applicants should reside in the Western New York area and be able to maintain a hybrid work schedule. Applicants within a reasonable commutable distance will be prioritized*
Valmar Holdings is looking for a Principal Security Engineer to protect the systems, data, and customer trust behind Valmar Merchant Services and Totality LMS. You will work directly alongside our product and platform engineering teams across payments and software, helping us identify how our systems can be attacked before someone else does - and turning what you learn into stronger products, better defenses, and practical controls.
This is a high-ownership individual contributor role for someone who wants to be in the work. You will personally test applications, APIs, cloud infrastructure, authentication and authorization flows, business logic, and third-party integrations. You will investigate real incidents, help defend against active threats, and lead through technical expertise and practical guidance - not through a management title or layers of process.
The right person can move comfortably between offensive security, defensive engineering, and compliance. You can demonstrate an exploitable weakness to an engineer, help design the fix, validate that remediation actually works, and translate the same technical reality into effective SOC 2 and PCI DSS controls and evidence. We want someone who thinks like an attacker, communicates like a partner, and takes ownership through resolution.
What You Will Own
- Review product and platform designs before implementation. Map attack vectors, trust boundaries, abuse cases, and failure scenarios, then work with engineers to build the right controls in from the start.
- Perform authorized penetration testing across applications, APIs, and cloud infrastructure using manual investigation, code review, automated tooling, and AI-assisted vulnerability discovery and validation. Go beyond scanner output to determine what is actually exploitable and why it matters.
- Test authentication and authorization end to end, including login, account recovery, sessions, permissions, tenant isolation, and custom role-based access controls. Establish whether one customer can reach another customer's data or perform actions they should not be able to take.
- Challenge business workflows across payments and Totality LMS. Look for ways to bypass permissions, manipulate approvals, replay requests, eviate transaction limits, or trigger duplicate processing.
- Assess partners and integrators before connection and as integrations evolve, including data access, credentials, request validation, security practices, and the risk created by third-party access.
- Turn findings into fixes. Demonstrate impact safely, create reproducible evidence, prioritize by business risk, work with engineering through remediation, and retest until the issue is actually closed.
- Lead security incident response and help defend against active attacks. Investigate events, preserve evidence, coordinate containment and recovery, and convert lessons learned into stronger detections, logging, runbooks, and engineering controls.
- Drive security work for SOC 2 audits and applicable PCI DSS assessments. Establish scope with control owners and auditors, manage evidence and gaps throughout the year, and ensure compliance reflects how the systems actually operate.
- Build security into the development lifecycle. Help engineering place automated checks and meaningful security gates at the right points in CI/CD and Git workflows without creating security theater or unnecessary friction.
- Teach continuously. Translate emerging threats, vulnerabilities, attack techniques, and lessons from incidents into practical design guidance, focused training, and changes to how we build.
What Success Looks Like
- Security is engaged early enough to change designs, not simply document risk after systems are built.
- Findings are actionable and prioritized by real business impact. Engineers understand the attack path, know what good remediation looks like, and security stays involved through validation.
- Valmar becomes harder to attack and faster to investigate: better logging, stronger detection, current runbooks, exercised response plans, and fewer preventable repeat issues.
- SOC 2 and PCI DSS evidence is an output of durable controls and disciplined operations rather than a scramble before an audit.
- Security tooling, automation, and AI reduce repetitive work without weakening human review, authorization, confidentiality, or accountability.
- Engineering teams see Security as a technically credible partner that helps them ship safer systems - not a gatekeeper that only identifies problems.
What You Bring
- Hands-on application and API security testing. You have personally found and validated vulnerabilities, demonstrated impact, and worked with engineers through remediation. You can go well beyond a scanner report.
- Production cloud security experience, particularly in AWS. You can review permissions, IAM, secrets, exposed services, logging, and WAF controls and trace how a small configuration mistake can become a path to sensitive systems.
- Experience building security into CI/CD and development workflows, including automated checks and security gates placed where they improve outcomes rather than simply add process.
- Real incident response experience. You have investigated security events and made containment and recovery decisions with engineering teams under pressure.
- Hands-on SOC 2 and PCI DSS experience: implementing or evaluating controls, collecting evidence, answering auditor questions, defining scope, and closing gaps.
- Security design and third-party review experience. You can identify attack paths in proposed systems and evaluate the risks created by partner access and integrations.
- Principal-level technical leadership without requiring people management. You can read code, write scripts or testing tools, make risk tradeoffs clear, and teach engineers how to prevent the next issue.
- Practical AI-assisted security and automation experience. You can build effective prompts and reusable agent skills to reduce security toil, use authorized AI security capabilities for white-hat testing, and independently validate findings and proposed fixes.
Bonus points for:
fintech, payments, card processing, ACH or other money-movement systems; AWS security across ECS, Lambda, API Gateway, RDS and IAM; cardholder data environments, tokenization and PCI scope reduction; multi-tenant platforms and custom RBAC; Go, PHP or Terraform; container security; PostgreSQL security; and practical experience evaluating AI-assisted development workflows.
Tools:
You may use Burp Suite or ZAP, Nmap, Wireshark, Semgrep, Trivy, Prowler, Amazon GuardDuty, and AI-assisted security tooling. Equivalent tools are welcome. What matters is knowing which tool fits the problem, validating its output, and acting on the result.
How We Use AI
AI is part of how we accelerate security work, not a substitute for security judgment. You will build and maintain prompts, automations, and reusable agent skills for work such as initial finding triage, audit evidence preparation, recurring security reporting, and authorized testing. You will test their accuracy and keep human review wherever decisions affect access, customer data, credentials, or production systems.
You will also help engineering teams across Valmar Merchant Services and Totality LMS use AI safely: protecting sensitive data and credentials, reviewing generated code, evaluating the access granted to agents, and recognizing when speed creates new attack surface. Human authorization, professional judgment, and an audit trail remain essential.
This Role Is Not a Fit If
- You want a management role where most of your time is spent directing others rather than personally investigating, testing, and delivering security work.
- Your security work ends when a scanner produces a report. We need someone who can validate exploitability, demonstrate impact, help drive the fix, and retest remediation.
- You want to focus exclusively on offensive testing or exclusively on compliance. This role moves between product security, cloud security, incident response, engineering enablement, and audit readiness.
- You struggle to turn technical findings into clear risk decisions and practical next steps with engineers.
- You prefer Security to operate as a gatekeeper rather than working alongside engineering to find a responsible path forward.
- You are uncomfortable making decisions during an active incident, working through ambiguity, or owning an issue until it is resolved.
- You treat SOC 2 or PCI DSS as a once-a-year evidence exercise rather than an operating discipline supported by real controls.
- You use AI-generated findings or fixes without independently validating them, or you are resistant to using modern security automation and AI tools thoughtfully.