More jobs:
Senior DevSecOps Engineer
Job in
1000, Amsterdam, North Holland, Netherlands
Listed on 2026-09-16
Listing for:
BUX B.V.
Full Time
position Listed on 2026-09-16
Job specializations:
-
IT/Tech
Cloud Computing: Infrastructure & Operations, Systems Engineer, Cybersecurity, SRE/Site Reliability
Job Description & How to Apply Below
Our engineering team sits at the heart of the company. We have a well-rounded team that cares about building great products that matter. You'll be part of a modern fintech company where you can try things, break things, fix them, and learn fast. Your work is visible, your input matters, and you help shape both the product and how we build it.
We stay close to what's happening in investing and fintech, and we share what we learn. It's a place where you can stretch your skills, contribute to something real, and grow alongside people who take their craft seriously and enjoy building things together.
What you will do
In this role, you'll go beyond managing infrastructure. You'll shape our cloud technical direction, drive Dev Sec Ops excellence across the organisation, and mentor Dev Ops engineers to help build and scale the platform that powers millions of trades. You will work closely with our Security Engineering colleagues: they set the standards and provide the independent challenge; you build the controls into the platform so that the secure path is also the fastest path for every team.
To do this, you will have the help of other very experienced colleagues, the freedom to brainstorm and suggest new ideas, and the time to execute those ideas in a high-quality way.
As a Senior Dev Sec Ops Engineer, your job is to lead from the front. This could mean:
Define and drive the technical vision for BUX cloud infrastructure across teams and set architectural standards for cloud-native solutions on Google Cloud Platform
Architect and implement highly available, fault-tolerant cloud infrastructure solutions with low-latency, high-throughput systems required for trading platforms, and own the disaster recovery and backup strategy behind them, proven by restore and failover tests against agreed RTO and RPO rather than by documentation
Lead 'Infrastructure as Code' initiatives using Terraform and evolve Kubernetes platforms for production workloads at scale, including the hardening baseline: network policy, admission control, workload identity and a credible upgrade track
Own the platform's identity and access model: least-privilege IAM, workload identity federation instead of long-lived keys, secrets storage and rotation, and break-glass paths that are logged and rehearsed
Secure the software supply chain end to end: dependency and container scanning, SBOM generation, artefact signing and build provenance, base image currency, and Git Hub Actions runners and permissions that are locked down rather than convenient
Turn security and compliance requirements into policy-as-code guardrails in Terraform modules and CI/CD, so that a misconfiguration fails a build instead of surfacing in an audit
Run vulnerability and posture management across the cloud and container layers: detection, triage that separates the reachable from the theoretical, remediation SLAs, and an exception register that is genuinely reviewed
Technically lead and mentor Dev Ops engineers across teams, elevating technical capabilities organisation-wide through knowledge sharing and comprehensive documentation
Drive Dev Sec Ops practices by setting standards for CI/CD pipelines, implementing security scanning, compliance checks, and building automation frameworks with Git Hub Actions
Take end-to-end ownership of critical infrastructure projects, including messaging systems (Kafka, RabbitMQ), database infrastructure (Cassandra, CloudSQL), and comprehensive observability solutions covering security-relevant telemetry as well as performance
Collaborate with Java/Kotlin and Python development teams to optimise application performance, troubleshoot production issues, and ensure infrastructure supports Spring Boot microservices and data lake requirements
Lead strategic initiatives to improve system reliability, performance, and operational efficiency while ensuring compliance with financial services regulations (ISO 27001, GDPR, DORA), and make control evidence a by-product of the platform: change records, access recertification, configuration baselines and resilience test results produced automatically rather than assembled by hand
Lead the technical response when things go wrong, across both platform and security incidents, including participation in the on-call rotation, the technical input that drives incident classification and regulatory reporting timelines, and post-mortems that end in…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×