Somali Payment Switch, based in Mogadishu, is looking for an experienced Full-Stack Software Engineer to fill an open position. This role falls within the Engineering sector and requires candidates with 3 - 4 years of relevant experience. Qualified candidates are urged to apply before the Aug, 17 deadline.
Position Title: Full-Stack Software Engineer
Department: Information Technology
Position Level: Level 1 Officer
Reports To: Head of Information Technology
Employment Type: Full-time
Location: Mogadishu, Somalia
1.
Background
The Somali Payment Switch (SPS) is the national retail payment infrastructure responsible for real-time clearing and settlement of payments across Somali financial institutions. As a central component of Somalia’s financial ecosystem, SPS enables secure interoperability among banks, mobile money operators, government institutions, and other approved payment service providers.
As SPS operates critical national financial infrastructure, its systems and services are subject to strict requirements for availability, security, confidentiality, integrity, auditability, change control, and business continuity. SPS is also expanding ISO 20022-enabled products and services, participant and government-system integrations, APIs, overlay services, operational applications, portals, dashboards, and mobile-enabled services to support increasing transaction volumes. SPS is therefore strengthening its software-engineering capacity through the appointment of a dedicated Full-Stack Software Engineer.
2.
Position Summary
The Full-Stack Software Engineer supports the design, development, testing, deployment, documentation, maintenance, and production support of SPS web applications, responsive user interfaces, backend services, APIs, participant integrations, operational tools, portals, dashboards, reporting applications, mobile-enabled services, and approved payment-processing components. The role works across frontend, backend, integration, and data-access layers, primarily supporting SPS-owned applications and overlay services and, where authorized, controlled changes to core payment-processing components. The Engineer implements approved product, scheme, operational, security, and regulatory requirements while supporting secure releases, automated testing, production stability, and continuous improvement.
3.
Key Responsibilities
Full-Stack Application Development
1.
Develop and maintain responsive web applications, portals, dashboards, administrative interfaces, and participant-facing tools using React and TypeScript.
2.
Build and maintain backend services and microservices using either Java with Spring Boot or C# with .NET, in accordance with approved architecture and coding standards.
3.
Develop end-to-end features across frontend, backend, integration, and data-access layers, ensuring secure and efficient data exchange.
4.
Develop and maintain SPS-owned applications, APIs, integration services, operational tools, reporting solutions, and overlay products.
5.
Implement approved changes to core payment-processing components only where SPS has authorized source-code access, defined technical ownership, appropriate testing environments, and approved review and release controls.
6.
Apply responsive design, accessibility, performance, usability, and secure client-side development practices.
7.
Support mobile-enabled services and mobile API integration, with working knowledge of mobile application architecture, authentication, secure storage, push notifications, testing, and release processes using Flutter, React Native, Kotlin, Swift, or comparable technologies.
Payment Processing and Standards
1.
Translate approved product, scheme, operational, security, and regulatory requirements into maintainable software designs and implementations.
2.
Implement approved transaction routing, validation, limits, fees, status handling, reversals, refunds, timeouts, exception processing, duplicate-detection, and idempotency controls.
3.
Support settlement, reconciliation, reporting, notification, and operational-control components without independently defining or approving scheme rules, pricing, transaction limits, settlement policies, or operating procedures.
4.
Implement, validate, map, version, and document ISO 20022 messages, including participant-specific adapters and transformations.
5.
Maintain awareness of ISO 8583 and support card or legacy payment integrations where required.
6.
Preserve end-to-end transaction traceability through correlation identifiers, timestamps, audit events, structured logging, error codes, and status tracking.
7.
Assess technical feasibility, dependencies, security implications, and implementation risks and communicate them to authorized business and technical owners.
Participant and System Integration
1.
Develop and maintain secure REST APIs, gRPC services, messaging interfaces, middleware integrations, webhooks, and file-based interfaces.
2.
Integrate banks, payment service providers, mobile wallets, government systems, settlement services, vendors, and other authorized systems.
3.
Implement and maintain JSON, XML, XSD, XPath, XSLT, Protocol Buffers, and message-transformation solutions such as Jolt where applicable.
4.
Build and support event-driven and message-broker integrations using RabbitMQ, Kafka, or equivalent technologies.
5.
Prepare technical specifications, sandbox configurations, test cases, error catalogues, interface mappings, and participant-integration documentation.
6.
Support participant testing, certification, production onboarding, and post-implementation verification in coordination with Operations, Product, Scheme Management, or other designated onboarding functions.
7.
Diagnose technical integration failures, maintain interface versions, and protect participant confidentiality throughout troubleshooting and support.
Secure Software Engineering and Code Quality
1.
Implement approved secure-coding, input-validation, authentication, authorization, encryption, secrets-management, audit-logging, secure error-handling, and dependency controls.
2.
Support compliance with applicable Central Bank of Somalia requirements, ISO/IEC 27001 controls adopted by SPS, PCI DSS where applicable, OWASP secure-development guidance, and other applicable legal, privacy, contractual, security, and SPS policy obligations.
3.
Participate in threat modelling, security testing, peer review, and remediation of static-analysis, dependency, vulnerability, and code-quality findings.
4.
Ensure live payment data is not used in development or testing unless specifically authorized and protected; do not bypass release controls, deploy unapproved artifacts, or modify production financial records outside approved procedures.
5.
Apply clean-code, modular-design, SOLID, testability, and maintainability principles.
6.
Refactor legacy or poorly structured code under approved change procedures and eliminate unnecessary duplication, dead code, excessive complexity, insecure practices, and avoidable technical debt.
7.
Apply appropriate architectural and software-design patterns, maintain reusable components and libraries, and prevent uncontrolled duplication of critical payment logic.
8.
Review code and technical outputs produced by junior developers, interns, consultants, or vendors and escalate material quality, security, or performance concerns without exercising formal line-management authority.
Testing and Quality Assurance
1.
Own unit, integration, contract, regression, and developer-level automated testing for assigned software components.
2.
Support security, performance, system-integration, participant-certification, user-acceptance, resilience, and production-verification testing.
3.
Use appropriate testing frameworks such as JUnit, xUnit, NUnit, PyTest, Jest, Selenium, Cypress, or equivalent tools.
4.
Work with Quality Assurance, Product, Operations, and participant teams to define acceptance criteria and retain appropriate test and release evidence.
5.
Reproduce defects, document root causes, implement controlled fixes, and add regression tests to prevent recurrence.
6.
Maintain automated coverage for agreed critical payment paths, including positive, negative, duplicate, timeout, reversal, and exception scenarios.
DevSecOps and Release Support
1.
Maintain application build, test, and deployment pipelines using Git and approved continuous-integration and continuous-delivery tools.
2.
Produce versioned, traceable, and reproducible release packages and maintain source-revision, dependency, build, test, and change records.
3.
Configure automated testing, code-quality, dependency, and security checks within application pipelines.
4.
Prepare database-migration scripts, deployment instructions, smoke tests, rollback or roll-forward procedures, and post-release monitoring requirements.
5.
Support controlled deployments and coordinate database migrations with Infrastructure, the Database Administrator, Information Security, and other relevant control functions.
6.
Observe segregation of duties, with production-platform ownership, privileged deployment access, and final release authorization retained by the designated control functions.
7.
Use Docker and approved tooling for application packaging and deployment support, and coordinate with Infrastructure or DevOps personnel on cloud platforms, Kubernetes, networking, secrets management, and Infrastructure as Code.
Production Support and Incident Management
1.
Monitor and support assigned applications during normal working hours using approved logs, dashboards, monitoring, and observability tools.
2.
Participate in an approved on-call rota for critical incidents, maintenance windows, production deployments, and major releases.
3.
Investigate failed, delayed, duplicated, or inconsistent transactions and application or service degradation.
4.
Preserve technical evidence and contribute to incident timelines, root-cause analysis, corrective actions, and problem records.
5.
Escalate conditions that may affect settlement integrity, participant balances, confidentiality, data integrity, or service availability.
6.
Implement authorized corrective fixes and support post-incident validation, lessons learned, and preventive actions.
7.
Participate in operational, cyber-security, disaster-recovery, and resilience exercises relevant to assigned services.
Documentation, Reporting and Knowledge Transfer
1.
Maintain architecture diagrams, data flows, interface specifications, API documentation, and data dictionaries.
2.
Document ISO 20022 mappings, participant integrations, error catalogues, message flows, and system dependencies.
3.
Maintain runbooks, deployment guides, configuration guidance, release notes, rollback procedures, and recovery dependencies.
4.
Record known limitations, operational thresholds, security considerations, and support requirements.
5.
Maintain appropriate source-code documentation and repository records and update documentation as an integral part of every material software change.
6.
Prepare periodic progress, risk, incident, and technical-status reports for management and relevant stakeholders.
7.
Conduct technical walkthroughs and transfer knowledge to authorized SPS personnel.
Technical Coordination and Continuous Improvement
1.
Coordinate assigned development and integration activities and provide technical guidance, peer support, and knowledge transfer to junior developers, interns, consultants, or vendors.
2.
Validate assigned technical deliverables and escalate material quality, security, delivery, or performance concerns to the Head of Information Technology.
3.
Participate effectively in Agile or Scrum planning, daily stand-ups, sprint reviews, and retrospectives.
4.
Collaborate with Product, Operations, Information Security, Infrastructure, the Database Administrator, participants, vendors, and other relevant stakeholders.
5.
Identify opportunities to improve software architecture, reliability, performance, automation, developer productivity, and maintainability.
6.
Evaluate emerging software, mobile, fintech, and payment technologies and propose controlled adoption where they can improve SPS services.
Other Duties
1.
Perform other software-engineering and technology-related duties assigned by the Head of Information Technology to support SPS institutional and technology objectives.
2.
Engage in continuous professional development and meet the annual professional-development requirements applicable to the position.
About Mogadishu
Mogadishu, known locally as Muqdisho, is the capital of Somalia and the country's largest city. It serves as the political, economic, and cultural heart of the nation. The city hosts the headquarters of numerous UN agencies, international NGOs, and government institutions, offering diverse career opportunities for development and humanitarian professionals.
Ereyada Soomaaliga (Somali Keywords): Shaqo Muqdisho • Shaqo Cusub • Injineernimo • Shaqo Buuxda