Senior Security Engineer
Mangopay is a wallet-based payment infrastructure built specifically for organisations with complex, multi-party fund flows. A pioneer in multi-party payments.
Our solution optimises fund flows on behalf of the organisations we work with using wallets as programmable, composable building blocks.
Mangopay’s regulated platform collects payments, secures transactions and holds funds, splits money between the various parties in the funds flow, and ultimately manages the payout to service providers, sellers, and consumers.
Platforms and fintechs using Mangopay regain control and transparency over multi-party payment flows, generate additional revenue, and improve operational efficiency. They can stay compliant while innovating and scaling.
Job Description
Mangopay is looking for a Senior Security Engineer to strengthen its technical security capability and support Engineering and Platform teams in designing, building and operating secure services.
Reporting to the CISO, this is a hands-on role combining security engineering, technical ownership of security controls and close collaboration with Engineering.
The Security Engineer will act as the main technical bridge between Security and Engineering, helping teams assess security risks, resolve vulnerabilities, review architecture decisions and ensure that security controls are effectively integrated across Mangopay’s cloud, application and software-development environments.
The objective of the role is to enable secure delivery at scale through technical expertise, automation, practical guidance and effective operation of security controls.
Key Responsibilities
Partner with Engineering and Platform teams to provide practical security guidance on applications, APIs, infrastructure and major technical changes.
Perform risk-based security reviews and support the integration of security throughout the SDLC.
Review complex security architecture topics and provide guidance on cloud security, identity and access management, network security, application security and cloud-native services.
Assess vulnerabilities and CVEs, determine technical impact and exploitability, support remediation decisions and validate fixes.
Own and operate the Security Engineering toolset and technical security controls, ensuring they are appropriately configured, maintained, integrated and continuously improved.
Design, implement and review cloud and network security controls, including firewall policies, access controls and preventative guardrails.
Automate repetitive security activities and integrate security controls into Engineering and Platform workflows.
Work with the SOC to translate technical security findings and alerts into actionable remediation for Engineering teams.
Contribute to technical remediation and assurance activities linked to audits, regulatory requirements and security assessments.
Qualifications
Strong experience in Security Engineering, Cloud Security, Application Security, Product Security or a similar hands-on technical security role.
Strong practical knowledge of cloud security and cloud-native architectures, ideally within AWS environments.
Good understanding of application and API security, including authentication, authorisation, access control and common security vulnerabilities.
Experience with CI/CD environments and integrating security controls into software-development workflows.
Experience assessing vulnerabilities and CVEs and providing practical remediation guidance to Engineering teams.
Good understanding of identity and access management, network security, encryption, secrets management and cloud security principles.
Ability to review technical architectures, identify security risks and recommend proportionate controls.
Experience with vulnerability management, cloud security and infrastructure security technologies.
Ability to communicate effectively with software engineers, Platform engineers and architects and translate security requirements into practical technical solutions.
Strong analytical, troubleshooting and problem-solving skills.
Nice to Have
Experience in fintech, payments, financial services or another regulated environment.
Experience securing large-scale API-based platforms.
Experience with infrastructure-as-code, containers and Kubernetes.
Experience with threat modelling and secure design reviews.
Knowledge of PCI DSS, SOC 2, DORA or similar regulatory and assurance frameworks.
Relevant cloud or security certifications are beneficial but not required.
Additional information
Call HR
Interview with Senior Member
Interview with Head of Info Security
- Département
- Technology
- Locations
- Mangopay - Luxembourg
- Remote status
- Hybrid
- Employment type
- Full-time
About Mangopay
Founded in 2013, Mangopay is the wallet-first infrastructure for multi-party payment flows, designed to give platforms the control, scalability, and revenue opportunities they need to thrive. Mangopay offers programmable wallets that mirror real-world multi-party experiences, enabling platforms to hold, split, and move funds across buyers, sellers, and partners, while unlocking new monetization streams.
With over €160 billion processed, 700 million wallets created, and 350 million users onboarded, Mangopay has demonstrated scale and reliability. Leading platforms like Vinted, Mirakl, Wallapop, Chrono24, and Debenhams use Mangopay to power complex flows, double transaction volumes, and streamline global operations.