Visa-posted 5 days ago
$173,100 - $250,900/Yr
Full-time • Senior
Highlands Ranch, CO

Visa’s Technology Organization is a community of problem solvers and innovators reshaping the future of commerce. We operate the world’s most sophisticated processing networks capable of handling more than 65k secure transactions a second across 80M merchants, 15k Financial Institutions, and billions of everyday people. While working with us you’ll get to work on complex distributed systems and solve massive scale problems centered on new payment flows, business and data solutions, cyber security, and B2C platforms. We are looking for a versatile, curious, and energetic Lead Software Engineer who embraces solving complex challenges on a global scale. As a Visa Engineer, you will be working on multiple projects and work as an integral part of a cross-functional development team. This position is for an Engineer focused on Encryption-related enhancements within the Connex Advantage switching application.

  • Prepare technical documents, develop code, review code, build environment, review test results, and prepare plan for implementation.
  • Analyze technical impact, stability, and functionality due to any custom change.
  • Evaluate code to ensure it is valid, meets industry standards and is compatible with devices and/or operating systems.
  • Confer with management or development teams to prioritize needs, resolve conflicts, and help choose solutions.
  • Develop or validate test routines and schedules to ensure that test cases mimic external interfaces.
  • Lead design reviews and provide guidance to junior team members who are participating in design reviews.
  • Review design documentation with engineering team members, senior project members, and architects to validate design for completeness and ensure alignment with requirements across an application, project, or product.
  • Proactively identify defects in software code and isolate/contain the defects to prevent customer impact.
  • Build partnerships with product management to ensure that the products being built deliver real value.
  • Identify problems uncovered by testing or customer feedback and correct problems.
  • Design and implement encryption controls for the Connex Advantage switch across data in transit and at rest, including strong TLS configurations (TLS 1.2/1.3, mTLS), authenticated encryption modes, and secure key storage.
  • Own and drive PCI DSS compliance activities relevant to switching (scope definition, compensating controls, evidence collection, and QSA engagement), ensuring continuous compliance and scope reduction.
  • Work with Hardware Security Modules (HSMs) for payments use cases (e.g., key generation/rotation, key ceremonies with dual control and split knowledge) and support DUKPT, TR‑31 key blocks, TR‑34 remote key loading, and PIN/PAN protection.
  • Define monitoring, logging, and incident response for cryptographic controls.
  • Maintain cryptographic inventories, key custody records, and certificate/PKI hygiene.
  • 10+ years of relevant work experience with a Bachelor’s Degree or at least 7 years of work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 4 years of work experience with a PhD, OR 13+ years of relevant work experience.
  • Strong knowledge on HP Nonstop systems and Connex Advantage Architecture.
  • 13+ years related experience working on Connex/eFunds software required.
  • Proven experience as a Connex developer or in similar roles.
  • Proficiency in Programming languages TAL, C, COBOL, SCOBOL and TACL on the HP NonStop platform.
  • Expertise in HP Nonstop tools like FUP, SCUP, Peruse, Inspect, Debug, Spoolcom, Pathway, Enform, DDL, Guardian Procedure calls, TCP/IP programming, TMF.
  • Good understanding of ISO8583 message formats.
  • Knowledge of financial industry practices, regulations, and operations.
  • Hands-on experience designing and implementing encryption for high throughput payment switching, including AES GCM or similar authenticated encryption, secure key storage, and hardened TLS (TLS 1.2/1.3, mTLS).
  • Practical experience working with HSMs in card payments environments (e.g., Thales payShield, Atalla/Utimaco). Knowledge of and experience with key generation/rotation, key ceremonies (dual control/split knowledge), secure backup/archival, and firmware management.
  • Expertise with payments key management standards and flows: DUKPT, TR 31 key blocks, TR 34 remote key loading, PIN block formats (ISO 0/1/3), PAN masking/truncation, and tokenization approaches.
  • Demonstrated ownership of PCI DSS compliance in a switching or authorization platform, including scope reduction, compensating controls, evidence production, and partnering with QSAs. Familiarity with PCI DSS v4.0 control families relevant to switching (e.g., 2, 3, 4, 5, 7, 8, 10, 11, 12).
  • Working knowledge of EMV and 3 D Secure implications for cryptography and data flows.
  • Strong technical knowledge and proven experience with card network certifications and key exchange processes.
  • Familiarity with applicable standards and validations: NIST SP 800 57/56/38 series, FIPS 140 2/140 3, OWASP ASVS. Experience applying these in NonStop/Connex environments.
  • Experience building monitoring and incident response for crypto controls (certificate lifecycle, cipher/TLS baselines, key inventory/drift detection) and automating compliance evidence.
  • Excellent problem-solving and analytical skills.
  • Strong communication (both written and verbal) and interpersonal skills.
  • Experience with end-to-end systems development life cycles and standards in Connex/HPE Nonstop development environment.
  • Proficiency in analyzing solutions design and requirements documents.
  • Medical
  • Dental
  • Vision
  • 401 (k)
  • FSA/HSA
  • Life Insurance
  • Paid Time Off
  • Wellness Program
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service