DevOps Engineer
Corytech is an international fintech company that develops modern payment solutions and operates across global markets. We are actively scaling our business, opening up new opportunities, and continuously improving our internal processes.
About the role
We are looking for an engineer to own the security of the infrastructure and CI/CD pipeline of a payment platform operating in a regulated environment (PCI DSS Level 1; EU DORA and MiCA requirements for an EU-regulated business line). You will work within the DevOps team alongside the DevOps Lead, with methodological support from an external virtual CISO. This is not a penetration tester or SOC analyst role: you will build security into infrastructure and processes and keep it running.
Responsibilities
• Harden cloud infrastructure (AWS: EKS, EC2, RDS, S3, IAM), secondary hosting and the CDN/WAF layer against CIS Benchmarks — everything as code in Terraform.
• Access management: least-privilege IAM roles, MFA, privileged access (session-based access, no static keys), break-glass procedures; user and role exports for periodic access reviews.
• Security monitoring: operate the SIEM/HIDS (Wazuh — rules, decoders, configuration assessment, agent rollout), GuardDuty, CloudTrail and Security Hub; route security alerts to the on-call engineer (duty rotation in PagerDuty, including out-of-hours escalation; tune false positives).
• Vulnerability management: scanning (Inspector, Trivy, Wazuh), prioritisation, tracking remediation against SLA, retesting.
• CI/CD security (GitHub Actions with self-hosted runners): SAST and SCA (Sonar, Trivy), secret scanning, branch protection, container image scanning, no secrets in code.
• Secrets and key management: KMS, Secrets Manager / External Secrets, password manager vaults, rotation.
• Network segmentation: DMZ and cardholder-data-environment zones, security groups, WAF rules.
• Backup and disaster recovery: encryption, isolated copies, restore tests with measured RTO and RPO.
• Endpoint security: take part in rolling out MDM / EDR across company devices.
• Incident response: technical part (triage, evidence collection, containment); participation in tabletop exercises.
• Audit evidence for PCI DSS, DORA and ISO/IEC 27001: configurations, screenshots, reports.
Requirements
• 3+ years in DevOps / SRE / cloud engineering, of which at least 1 year with security responsibilities.
• Solid AWS: IAM, VPC, EKS, KMS, CloudTrail, GuardDuty.
• Kubernetes in production: RBAC, network policies, Pod Security, secrets handling.
• Terraform and an infrastructure-as-code mindset; Git workflow with code review.
• Linux administration and hardening.
• Hands-on experience with a SIEM / HIDS (Wazuh preferred; Elastic Security, Splunk, OSSEC or similar acceptable).
• Understanding of OWASP Top 10, CVE / CVSS, cryptography and PKI basics.
• English: able to read documentation and communicate with auditors in writing (B1+).
Nice to have
• Fintech or payments background; PCI DSS (CDE segmentation, QSA audit preparation).
• Familiarity with DORA, ISO/IEC 27001, CIS Controls.
• Teleport, JumpCloud, Falco, Cloudflare Zero Trust / WAF.
• Certifications: AWS Certified Security – Specialty, CKS, CKA, CompTIA Security+.
• Python or Bash scripting for automated checks.
Selection process:
•HR screening.
•Technical interview with the DevOps Lead (infrastructure, Kubernetes, Terraform).
•Security interview with the CISO (30–45 min): scenario-based questions on AWS IAM, monitoring, incident response and vulnerability management.
•Final interview with the CTO.
What we offer:
💥 Unlimited opportunities to bring your ideas to life.
💥 A friendly and experienced team.
💥 50% reimbursement of professional education and training costs.
💥 24 calendar days of paid annual leave.
💥 50% compensation for lunches at the office.