Security Engineer

GoCardless
Riga, LatviaPosted 21 February 2026

Job Description

<div class="content-intro"><h3><strong>About Us at GoCardless</strong></h3> <p>GoCardless is a <strong>global bank payment</strong> company. Over <strong>100,000 businesses</strong>, from start-ups to household names, use GoCardless to collect and send payments through direct debit, real-time payments and open banking. </p> <p>GoCardless processes <strong>US$130bn+</strong> of payments annually, across <strong>30+ countries</strong>; helping customers collect and send both <strong>recurring</strong> and <strong>one-off payments</strong>, without the chasing, stress or expensive fees. We use AI-powered solutions to improve payment success and reduce fraud. And, with open banking connectivity to over <strong>2,500 banks</strong>, we help our customers make faster, more informed decisions.</p> <p>We are headquartered in the<strong> UK</strong> with offices in <strong>London</strong> and <strong>Leeds</strong>, and additional locations in <strong>Australia, France, Ireland, Latvia, Portugal</strong> and the <strong>United States.</strong></p> <p>At GoCardless, we're all about <strong>supporting you</strong>! We’re committed to making our hiring process <strong>inclusive</strong> and <strong>accessible</strong>. If you need extra support or adjustments, reach out to your <strong>Talent Partner</strong> — we’re here to help! </p> <p>And remember: we don’t expect you to meet every single requirement. If you’re excited by this role, <strong>we encourage you to apply!</strong></p></div><p><strong>The role</strong></p> <p>As a Product Security Engineer, you will enable development teams to take ownership of the security and privacy of their product by collaborating to set requirements and standards, performing design reviews and vulnerability assessments, and helping build security controls. You will also work closely with the dedicated Security Operations and Security Engineering teams. </p> <p>You will be someone who has experience securing a cloud-native environment, and, in particular, in embedding security and privacy standards in engineering functions. You should also be comfortable automating security and privacy engineering and performing various security assessments.</p> <p><strong>What excites you </strong></p> <ul> <li>Developing high-quality code for extensive tasks, showcasing proficiency in leading systems and architecture design independently. </li> <li>Leading the design and documentation processes for complex tasks, breaking them down into manageable segments for team collaboration while also handling the most challenging portions.</li> <li>Contributing significantly to the company-wide systems architecture, impacting the organisation's technological landscape.</li> <li>Providing guidance to developers and architects on secure coding methodologies, architectural design, and security best practices, fostering a culture of excellence within the team.</li> <li>Overseeing the vulnerability management program, conducting routine assessments, prioritising resolutions, and tracking progress towards securing systems.</li> <li>Demonstrating advanced proficiency in security testing, ensuring comprehensive evaluations of system, application, and network security postures.</li> <li>Creating and maintaining robust security policies, procedures, and guidelines for effective programme management.</li> </ul> <p><strong>What excites us </strong></p> <ul> <li>Experience in cloud-based application and infrastructure security - especially, DevSecOps</li> <li>Background in threat modelling and security architecture/secure design</li> <li>Awareness of or exposure to security and privacy standards, such as ISO27001, SOC1, CyberEssentials, GDPR, or similar</li> <li><strong>Nice to have: </strong>Cybersecurity certifications, such as CISSP, CEH, Professional Cloud Security Engineer, or similar</li> <li>Technical experience in working with cloud computing providers such as GCP or AWS</li> <li>Technical leadership qualities - setting direction al ... (truncated, view full listing at source)