Job 1000 van 1000


Solliciteren



Senior DevSecOps Engineer


We are looking for a Senior DevSecOps Engineer to join our BUX team based in Amsterdambr/br/Our engineering team sits at the heart of the companybr/br/We have a well-rounded team that cares about building great products that matterbr/br/You’ll be part of a modern fintech company where you can try things, break things, fix them, and learn fastbr/br/Your work is visible, your input matters, and you help shape both the product and how we build itbr/br/We stay close to what’s happening in investing and fintech, and we share what we learnbr/br/It’s a place where you can stretch your skills, contribute to something real, and grow alongside people who take their craft seriously and enjoy building things togetherbr/br/In this role, you’ll go beyond managing infrastructurebr/br/You’ll shape our cloud technical direction, drive DevSecOps excellence across the organisation, and mentor DevOps engineers to help build and scale the platform that powers millions of tradesbr/br/You will work closely with our Security Engineering colleagues: they set the standards and provide the independent challenge; you build the controls into the platform so that the secure path is also the fastest path for every teambr/br/To do this, you will have the help of other very experienced colleagues, the freedom to brainstorm and suggest new ideas, and the time to execute those ideas in a high-quality waybr/br/As a Senior DevSecOps Engineer, your job is to lead from the front. This could mean:br/br/Define and drive the technical vision for BUX cloud infrastructure across teams and set architectural standards for cloud-native solutions on Google Cloud Platformbr/br/Architect and implement highly available, fault-tolerant cloud infrastructure solutions with low-latency, high-throughput systems required for trading platforms, and own the disaster recovery and backup strategy behind them, proven by restore and failover tests against agreed RTO and RPO rather than by documentationbr/br/Lead ‘Infrastructure as Code’ initiatives using Terraform and evolve Kubernetes platforms for production workloads at scale, including the hardening baseline: network policy, admission control, workload identity and a credible upgrade trackbr/br/Own the platform’s identity and access model: least-privilege IAM, workload identity federation instead of long-lived keys, secrets storage and rotation, and break-glass paths that are logged and rehearsedbr/br/Secure the software supply chain end to end: dependency and container scanning, SBOM generation, artefact signing and build provenance, base image currency, and GitHub Actions runners and permissions that are locked down rather than convenientbr/br/Turn security and compliance requirements into policy-as-code guardrails in Terraform modules and CI/CD, so that a misconfiguration fails a build instead of surfacing in an auditbr/br/Run vulnerability and posture management across the cloud and container layers: detection, triage that separates the reachable from the theoretical, remediation SLAs, and an exception register that is genuinely reviewedbr/br/Technically lead and mentor DevOps engineers across teams, elevating technical capabilities organisation-wide through knowledge sharing and comprehensive documentationbr/br/Drive DevSecOps practices by setting standards for CI/CD pipelines, implementing security scanning, compliance checks, and building automation frameworks with GitHub Actionsbr/br/Take end-to-end ownership of critical infrastructure projects, including messaging systems (Kafka, RabbitMQ), database infrastructure (Cassandra, CloudSQL), and comprehensive observability solutions covering security-relevant telemetry as well as performancebr/br/Collaborate with Java/Kotlin and Python development teams to optimise application performance, troubleshoot production issues, and ensure infrastructure supports Spring Boot microservices and data lake requirementsbr/br/Lead strategic initiatives to improve system reliability, performance, and operational efficiency while ensuring compliance with financial services regulations (ISO 27001, GDPR, DORA), and make control evidence a by-product of the platform: change records, access recertification, configuration baselines and resilience test results produced automatically rather than assembled by handbr/br/Lead the technical response when things go wrong, across both platform and security incidents, including participation in the on‑call rotation, the technical input that drives incident classification and regulatory reporting timelines, and post‑mortems that end in preventive changebr/br/You will have space to share your ideas and be encouraged to express your voicebr/br/You will be one of the most skilled infrastructure experts in the room, with the authority to make strategic decisions on cloud architecturebr/br/You will be challenged to design and maintain critical infrastructure that handles high‑volume trading data in real‑time, ensuring reliability and security for millions of usersbr/br/You will lead the technical direction of BUX’s cloud infrastructure and shape DevOps practice across the entire engineering organisationbr/br/You will get to build security into the platform rather than inspect it afterwards, with the mandate, the budget and the time to do it properlybr/br/You will work with cutting‑edge cloud technologies (GCP, Kubernetes, Terraform) and have the freedom to evaluate and champion adoption of new tools that provide strategic valuebr/br/Lastly, the business domain is interesting. You will learn how the financial system works on the inside, and you will treat the strict requirements of financial services as a design constraint to engineer around rather than a form to fill inbr/br/Benefitsbr/br/Work from anywhere in the world for one month per yearbr/br/Unlimited 1-on-1 access to on‑demand coaching and mindfulness consultations with psychologists through OpenUpbr/br/A supportive environment that encourages continuous learning and developmentbr/br/Dedicated training budget for to use towards improving current skills or learning something entirely newbr/br/Celebrations - we make sure to do plenty of fun stuff together, like dinner and drinks or activities like flyboarding, rafting and off‑road jeep drivingbr/br/Hands-on security engineering inside the delivery process, with real depth in several of: IAM and least‑privilege design at scale, secrets management, pipeline security gating with genuine triage, policy-as-code, supply‑chain signing and provenance, Kubernetes hardening, cloud network security.br/br/We do not expect all of these.br/br/We do expect several of them to be things you have built and operated, not evaluatedTrack record of driving organisation-wide improvements and strategic initiativesSenior Technical Leadership level experience with proven ability to take ownership of projects from start to endExperience with at least two of Kafka, CloudSQL (PostgreSQL MySQL), and GitHub ActionsSolid experience with monitoring, observability, and incident management at scaleStrong collaboration and communication skills across all organisational levels, including with the people whose job is to challenge your designYou regularly use GenAI tools, stay up to date with new ones, and encourage the team to use them to speed up delivery and improve how everyone worksDeep understanding of CI/CD pipelines, DevOps best practices, and DevSecOpsExcellent command of ‘Infrastructure as Code’ using TerraformProficiency in Python development and advanced scripting capabilities (Bash)Experience working somewhere controls have to be evidenced rather than asserted, and the patience that goes with itA keen eye for detail while always keeping the big picture in mindExpert knowledge of Google Cloud Platform (GCP) with focus on Kubernetes and container orchestrationPractical experience of DORA, ISO 27001 or a comparable regime, ideally from the engineering side rather than the documentation sideSupply-chain security in practice: SBOM formats, cosign or Sigstore, SLSA-style provenanceKey and crypto management on a cloud KMS, including rotation and separation of dutiesPolicy-as-code tooling (OPA, Conftest, Gatekeeper or equivalent) and cloud security posture managementThreat modelling alongside product teamsExperience with serverless cloud technologies like Cloud Run and Cloud FunctionsAbility to understand and work with Java/Kotlin code in Spring Boot applicationsExperience with RabbitMQ and CassandraWorking experience with Google PubSub and VertexAIUnderstanding of financial services and neobroker business modelsCertifications such as CKS or Google Professional Cloud Security Engineer, which we read as a signal rather than a requirementbr/br/#J-18808-Ljbffr

Solliciteren