Senior DevSecOps Engineer at BUX
Amsterdam, North Holland, Netherlands -
Full Time


Start Date

Immediate

Expiry Date

17 Dec, 26

Salary

105000.0

Posted On

18 Sep, 26

Experience

11 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Industry

Information Services

Description

In this role, you'll go beyond managing infrastructure. You'll shape our cloud technical direction, drive DevSecOps excellence across the organisation, and mentor DevOps engineers to help build and scale the platform that powers millions of trades. You will work closely with our Security Engineering colleagues: they set the standards and provide the independent challenge; you build the controls into the platform so that the secure path is also the fastest path for every team. To do this, you will have the help of other very experienced colleagues, the freedom to brainstorm and suggest new ideas, and the time to execute those ideas in a high-quality way.

As a Senior DevSecOps Engineer, your job is to lead from the front. This could mean:

  • Define and drive the technical vision for BUX cloud infrastructure across teams and set architectural standards for cloud-native solutions on Google Cloud Platform
  • Architect and implement highly available, fault-tolerant cloud infrastructure solutions with low-latency, high-throughput systems required for trading platforms, and own the disaster recovery and backup strategy behind them, proven by restore and failover tests against agreed RTO and RPO rather than by documentation
  • Lead 'Infrastructure as Code' initiatives using Terraform and evolve Kubernetes platforms for production workloads at scale, including the hardening baseline: network policy, admission control, workload identity and a credible upgrade track
  • Own the platform's identity and access model: least-privilege IAM, workload identity federation instead of long-lived keys, secrets storage and rotation, and break-glass paths that are logged and rehearsed
  • Secure the software supply chain end to end: dependency and container scanning, SBOM generation, artefact signing and build provenance, base image currency, and GitHub Actions runners and permissions that are locked down rather than convenient
  • Turn security and compliance requirements into policy-as-code guardrails in Terraform modules and CI/CD, so that a misconfiguration fails a build instead of surfacing in an audit
  • Run vulnerability and posture management across the cloud and container layers: detection, triage that separates the reachable from the theoretical, remediation SLAs, and an exception register that is genuinely reviewed
  • Technically lead and mentor DevOps engineers across teams, elevating technical capabilities organisation-wide through knowledge sharing and comprehensive documentation
  • Drive DevSecOps practices by setting standards for CI/CD pipelines, implementing security scanning, compliance checks, and building automation frameworks with GitHub Actions
  • Take end-to-end ownership of critical infrastructure projects, including messaging systems (Kafka, RabbitMQ), database infrastructure (Cassandra, CloudSQL), and comprehensive observability solutions covering security-relevant telemetry as well as performance
  • Collaborate with Java/Kotlin and Python development teams to optimise application performance, troubleshoot production issues, and ensure infrastructure supports Spring Boot microservices and data lake requirements
  • Lead strategic initiatives to improve system reliability, performance, and operational efficiency while ensuring compliance with financial services regulations (ISO 27001, GDPR, DORA), and make control evidence a by-product of the platform: change records, access recertification, configuration baselines and resilience test results produced automatically rather than assembled by hand
  • Lead the technical response when things go wrong, across both platform and security incidents, including participation in the on-call rotation, the technical input that drives incident classification and regulatory reporting timelines, and post-mortems that end in preventive change

Responsibilities

In this role, you'll go beyond managing infrastructure. You'll shape our cloud technical direction, drive DevSecOps excellence across the organisation, and mentor DevOps engineers to help build and scale the platform that powers millions of trades. You will work closely with our Security Engineering colleagues: they set the standards and provide the independent challenge; you build the controls into the platform so that the secure path is also the fastest path for every team. To do this, you will have the help of other very experienced colleagues, the freedom to brainstorm and suggest new ideas, and the time to execute those ideas in a high-quality way.

As a Senior DevSecOps Engineer, your job is to lead from the front. This could mean:

  • Define and drive the technical vision for BUX cloud infrastructure across teams and set architectural standards for cloud-native solutions on Google Cloud Platform
  • Architect and implement highly available, fault-tolerant cloud infrastructure solutions with low-latency, high-throughput systems required for trading platforms, and own the disaster recovery and backup strategy behind them, proven by restore and failover tests against agreed RTO and RPO rather than by documentation
  • Lead 'Infrastructure as Code' initiatives using Terraform and evolve Kubernetes platforms for production workloads at scale, including the hardening baseline: network policy, admission control, workload identity and a credible upgrade track
  • Own the platform's identity and access model: least-privilege IAM, workload identity federation instead of long-lived keys, secrets storage and rotation, and break-glass paths that are logged and rehearsed
  • Secure the software supply chain end to end: dependency and container scanning, SBOM generation, artefact signing and build provenance, base image currency, and GitHub Actions runners and permissions that are locked down rather than convenient
  • Turn security and compliance requirements into policy-as-code guardrails in Terraform modules and CI/CD, so that a misconfiguration fails a build instead of surfacing in an audit
  • Run vulnerability and posture management across the cloud and container layers: detection, triage that separates the reachable from the theoretical, remediation SLAs, and an exception register that is genuinely reviewed
  • Technically lead and mentor DevOps engineers across teams, elevating technical capabilities organisation-wide through knowledge sharing and comprehensive documentation
  • Drive DevSecOps practices by setting standards for CI/CD pipelines, implementing security scanning, compliance checks, and building automation frameworks with GitHub Actions
  • Take end-to-end ownership of critical infrastructure projects, including messaging systems (Kafka, RabbitMQ), database infrastructure (Cassandra, CloudSQL), and comprehensive observability solutions covering security-relevant telemetry as well as performance
  • Collaborate with Java/Kotlin and Python development teams to optimise application performance, troubleshoot production issues, and ensure infrastructure supports Spring Boot microservices and data lake requirements
  • Lead strategic initiatives to improve system reliability, performance, and operational efficiency while ensuring compliance with financial services regulations (ISO 27001, GDPR, DORA), and make control evidence a by-product of the platform: change records, access recertification, configuration baselines and resilience test results produced automatically rather than assembled by hand
  • Lead the technical response when things go wrong, across both platform and security incidents, including participation in the on-call rotation, the technical input that drives incident classification and regulatory reporting timelines, and post-mortems that end in preventive change

Loading...