DevSecOps Engineer (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
DevSecOps Engineer (Fintech): Designing and enforcing secure-by-default infrastructure and CI/CD pipelines for a wealth management platform with an accent on identity management, Kubernetes hardening, and supply chain security. Focus on implementing policy-as-code, designing secure AWS architectures, and automating threat detection to eliminate insecure behavior.
Location: Onsite in Nicosia, Cyprus. Relocation support is provided.
Company
is a fintech company redefining wealth management and family governance through data-driven platforms and scalable architecture.
What you will do
- Design and enforce secure-by-default infrastructure across AWS and Kubernetes.
- Own secrets management and identity flows using HashiCorp Vault and OIDC/IRSA.
- Harden Kubernetes clusters with policy-driven security controls (OPA, Kyverno, RBAC).
- Build secure CI/CD pipelines with image signing (cosign), SBOM generation, and scanning.
- Implement end-to-end workload identity and mTLS between services.
- Drive threat modeling practices using STRIDE and LINDDUN methodologies.
Requirements
- 4+ years of experience in DevSecOps, Security Engineering, or SRE.
- Proven experience securing production Kubernetes-based systems.
- Deep expertise in AWS security (IAM, SCP, IRSA, CloudTrail).
- Strong knowledge of software supply chain security and identity models.
- Professional working proficiency in both Russian and English.
- Must be based in or willing to relocate to Nicosia, Cyprus for onsite work.
Nice to have
- Experience in regulated financial environments or multi-tenant SaaS platforms.
- Exposure to service meshes such as Istio or Linkerd.
- Familiarity with KDB+ time-series databases.
- AI-forward mindset for leveraging AI tools to enhance productivity.
Culture & Benefits
- Innovative fintech environment with a focus on ownership and bias for action.
- Opportunity to architect infrastructure for significant scale and optimize costs.
- Work with cutting-edge cloud-native technologies.
- Relocation support for team members moving from abroad.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →