DevOps Engineer
We are hiring a DevSecOps Architect / Technical Lead for a project modernizing digital banking architecture and enhancing security, scalability, and platform reliability.
The customer is a financial services organization providing banking products and digital solutions for individual and business clients. The company operates through an established service network and online platforms and is part of a larger international financial group, supporting ongoing development of its services for a broad client base.
The project is focused on defining a structured architecture roadmap for a large-scale digital banking transformation program. It includes target-state architecture, platform modernization, API governance, security, data and analytics, system decoupling, and phased migration of business capabilities to reduce system dependencies and accelerate future digital development.
Responsibilities:
- Translating the DevSecOps master plan into a practical implementation roadmap.
- Defining reusable CI/CD, security and release-management standards.
- Supporting the transition from Bitbucket/Jenkins to Azure Repos and Azure Pipelines.
- Implementing security scanning and release gates in CI/CD pipelines.
- Configuring security controls for AKS, container images, identities and secrets.
- Establishing artifact signing, SBOM generation and secure promotion processes.
- Integrating platform security events with the bank’s monitoring and SIEM solutions.
- Defining vulnerability-management, audit-evidence and incident-response processes.
- Providing technical leadership, recommendations and knowledge transfer to delivery teams.
Participating directly in configuration, integration and troubleshooting activities.
Requirements:- Experience in DevSecOps, cloud security or platform security for 5+ years.
- Strong hands-on experience with Microsoft Azure.
- Practical experience with Azure DevOps or comparable enterprise CI/CD platforms.
- Experience designing and implementing secure CI/CD pipelines.
- Experience integrating security scanners and quality gates into pipelines.
- Practical knowledge of Kubernetes and container security, preferably AKS.
- Experience with Infrastructure as Code, preferably Terraform.
- Knowledge of identity, secrets and certificate management.
- Understanding of SAST, SCA, DAST, secret scanning, IaC scanning and container scanning.
- Ability to combine solution design and technical leadership with hands-on implementation.
- Strong communication and documentation skills.
Level of English – from Upper-Intermediate and above.
Nice-to-haves:
- Experience in the banking domain.
- Experience with Jenkins, Bitbucket and migration to Azure DevOps.
- Experience with Azure Key Vault, Azure Container Registry and Defender for Containers.
- Familiarity with tools such as SonarQube, Sonatype, Nexus, Gitleaks, Checkov or OWASP ZAP.
- Understanding of SBOM, artifact signing and software supply-chain security.
- Experience with DefectDojo, Microsoft Sentinel or other vulnerability-management and SIEM solutions.
- Experience with Azure Policy, Gatekeeper, OPA or Kubernetes admission controls.
- Experience in banking or another regulated industry.
- Understanding of DORA, audit traceability and segregation-of-duties requirements.