Search by job, company or skills

Senior Backend Engineer Payments & PCI Compliance

Early Applicant
  • Posted a month ago
  • Be among the first 10 applicants

Job Description

About the role:

We run a payment gateway that processes live card transactions for merchants, and we're investing seriously in the security, compliance, and architecture of our platform. We're hiring a senior backend engineer to own that work end-to-end — to take our Spring Boot payment stack and make it secure, PCI-validated, and clean to integrate with.

This is a high-ownership role, not a ticket queue. You'll be trusted to assess what needs to be done, prioritise it, and drive it to completion — coordinating with our acquirer, QSA, and scanning vendors as you go. If you enjoy turning high-stakes, ambiguous payment problems into well-engineered, auditable systems, you'll fit right in.

What you'll do:
  • Drive our PCI DSS v4.0.1 validation as a service provider — scope definition, remediation, the SAQ/assessment process, and keeping us compliant year-round.

  • Harden how we store, process, and transmit cardholder data: encryption, tokenization, masking, and disciplined logging hygiene.

  • Design and evolve our payment APIs (hosted payment page + server-to-server), including a tokenization / hosted-fields model so merchants integrate once and stay low-scope.

  • Build secure integration plumbing: HMAC-signed webhooks, key management, and clean authentication.

  • Strengthen fraud and risk controls — 3DS vs non-3DS routing, velocity limits, anomaly detection, AVS/CVV handling.

  • Keep our developer-facing documentation accurate, consistent, and a pleasure to integrate against.
What we're looking for:
  • Strong backend engineering in Java / Spring Boot — this is our core stack.

  • Hands-on payments experience: gateways, processors, card-not-present flows, 3D Secure.

  • Working knowledge of PCI DSS and the secure handling of cardholder data (you know exactly why a CVV must never touch a log).

  • Excellent API design and a security-first instinct.

  • Organised and self-directed — able to own a program, track it, document it, and work credibly with external assessors. This is the trait we care about most.

Nice to have:
  • Tokenization / card-vault design, hosted fields, or PSP / payment-facilitator experience.
  • Fraud and risk systems, chargeback and dispute workflows.
  • Having taken a company through a PCI audit before.
  • Experience with AWS and MySQL.

The details
  • Type: Full-time
  • Location: Remote
  • Compensation: 10-12 LPA
  • Stack: Spring Boot, MySQL, AWS

How to apply

Apply directly or email at [Confidential Information].

In a few lines, tell us about a payment or compliance problem you personally owned and shipped — that's what we'll read first.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 149629143