About the role:
We run a payment gateway that processes live card transactions for merchants, and we're investing seriously in the security, compliance, and architecture of our platform. We're hiring a senior backend engineer to own that work end-to-end — to take our Spring Boot payment stack and make it secure, PCI-validated, and clean to integrate with.
This is a high-ownership role, not a ticket queue. You'll be trusted to assess what needs to be done, prioritise it, and drive it to completion — coordinating with our acquirer, QSA, and scanning vendors as you go. If you enjoy turning high-stakes, ambiguous payment problems into well-engineered, auditable systems, you'll fit right in.
What you'll do:
- Drive our PCI DSS v4.0.1 validation as a service provider — scope definition, remediation, the SAQ/assessment process, and keeping us compliant year-round.
- Harden how we store, process, and transmit cardholder data: encryption, tokenization, masking, and disciplined logging hygiene.
- Design and evolve our payment APIs (hosted payment page + server-to-server), including a tokenization / hosted-fields model so merchants integrate once and stay low-scope.
- Build secure integration plumbing: HMAC-signed webhooks, key management, and clean authentication.
- Strengthen fraud and risk controls — 3DS vs non-3DS routing, velocity limits, anomaly detection, AVS/CVV handling.
- Keep our developer-facing documentation accurate, consistent, and a pleasure to integrate against.
What we're looking for:
- Strong backend engineering in Java / Spring Boot — this is our core stack.
- Hands-on payments experience: gateways, processors, card-not-present flows, 3D Secure.
- Working knowledge of PCI DSS and the secure handling of cardholder data (you know exactly why a CVV must never touch a log).
- Excellent API design and a security-first instinct.
- Organised and self-directed — able to own a program, track it, document it, and work credibly with external assessors. This is the trait we care about most.
Nice to have:
- Tokenization / card-vault design, hosted fields, or PSP / payment-facilitator experience.
- Fraud and risk systems, chargeback and dispute workflows.
- Having taken a company through a PCI audit before.
- Experience with AWS and MySQL.
The details
- Type: Full-time
- Location: Remote
- Compensation: 10-12 LPA
- Stack: Spring Boot, MySQL, AWS
How to apply
Apply directly or email at [Confidential Information].
In a few lines, tell us about a payment or compliance problem you personally owned and shipped — that's what we'll read first.