logo

Senior DevSecOps Engineer (Infrastructure & Cloud Security)

Cyprus · DEVSECOPS
Apply

Responsibilities

  • Define and enforce the security architecture for AWS and Azure: organisation and landing-zone design, service control policies and Azure Policy, network segmentation and private connectivity, encryption and key management (AWS KMS, Azure Key Vault), logging and monitoring baselines.
  • Own the perimeter and edge: WAF and DDoS protection, VPN and zero-trust access, DNS, certificate, and exposure management for anything internet-facing.
  • Run vulnerability management end to end: asset discovery, scanning, prioritisation by exploitability and business impact, remediation SLAs tracked with the infrastructure team.
  • Design security into new infrastructure from the start: threat-model and review architecture changes, define secure patterns other engineers can reuse, and say “no” with a workable alternative when needed.
  • Own Active Directory: administrative tiering, privileged-group hygiene, Group Policy and Conditional Access baselines
  • Design and run the group access model: least privilege across AWS IAM, Azure RBAC, Kubernetes RBAC, databases, network devices and SaaS; single sign-on and phishing-resistant MFA everywhere; privileged access management with just-in-time elevation for administrators; tested break-glass procedures.
  • Own the security telemetry pipeline into the SIEM: AWS CloudTrail, AD and Entra sign-in and audit logs; EDR; Kubernetes audit logs; WAF, VPN, network and application logs. Decide what is collected, for how long and at what cost.
  • Treat security as code: Terraform modules with secure defaults; policy-as-code (Open Policy Agent, AWS Config rules, Azure Policy) enforced in pipelines and at runtime; drift detection and automatic remediation where safe.
  • Own API security for internal and client-facing APIs (REST, WebSocket, FIX and streaming market-data interfaces): authentication and authorisation patterns, token and key handling, rate limiting and abuse protection, gateway and WAF rules, schema validation, logging of security-relevant events.
  • Automate evidence collection and continuous control monitoring so that ISO 27001 and SOC 2 audits become a by-product of normal operations.
  • Be the technical owner of the ISO/IEC 27001:2022 Annex A technological controls (A.8) and of SOC 2 (Security and Availability criteria) control operation. Support internal audits, surveillance audits and SOC 2 Type II fieldwork.
  • Map technical controls to DORA: the ICT risk-management framework, the annual digital operational resilience testing programme (vulnerability assessments, penetration tests, scenario tests, readiness for threat-led penetration testing) and the technical inputs to the ICT third-party register.
  • Run security reviews of ICT third parties and cloud services. Maintain shared-responsibility and data-flow documentation.

Requirements

  • Experience. 6+ years of hands-on infrastructure, cloud or security engineering, of which 3+ years with security as your primary responsibility, in a regulated financial-services environment — brokerage, trading, payments, banking or crypto services.
  • AWS and Azure in production. Security of complex, multi-account / multi-subscription, hybrid estates on both platforms: IAM and RBAC, networking and private connectivity, KMS and Key Vault, logging and native detection services, landing zones and policy enforcement. You have designed infrastructure, not only reviewed it.
  • Active Directory. Deep, practical knowledge of AD — tiering, Group Policy, Conditional Access, hybrid identity, the common attack paths and how to close them — plus enterprise IAM and PAM design and access-rights governance.
  • Detection and response. You have built and tuned SIEM and EDR detections, owned alerting quality and run security incidents end to end under time pressure. You understand how a Security Operations Center works from the inside — as well as what a SOC 2 report is.
  • Automation. Terraform (or equivalent IaC), CI/CD security gates, Kubernetes and container security, policy-as-code, and confident scripting in Python, Bash and PowerShell. You understand APIs well enough to secure them and to automate through them.
  • Crypto-asset infrastructure. Hands-on exposure to securing wallet or key-management systems, exchanges or crypto payment rails — HSM or MPC signing, hot/cold segregation, transaction-flow monitoring.

Conditions

  • Reliability: official employment from the first day, bonuses, annual employee review (salary review or bonus, feedback on work results)
  • Stability: our clients are in different countries, therefore we are ready for any changes in work of any country
  • Development: a lot of projects and products, which means increasing expertise in working with different technologies, or even switching to completely new ones for you within the company
  • Active corporate life: we participate in thematic conferences and forums in our cool sphere of business, corporate parties in the best restaurants of the city with participation of stars, etc
  • Comfort: Offices are in different countries. You can work from anywhere in the world
Share this job opening

Application:

I agree to the processing of my personal data in accordance with the B2BROKER Privacy Policy