Senior DevSecOps Engineer

BUX
BUX

Other Engineering

Amsterdam, Netherlands

Posted on Sep 14, 2026

We are looking for a Senior DevSecOps Engineer to join our BUX team based in Amsterdam.

Our engineering team sits at the heart of the company. We have a well-rounded team that cares about building great products that matter. You'll be part of a modern fintech company where you can try things, break things, fix them, and learn fast. Your work is visible, your input matters, and you help shape both the product and how we build it. We stay close to what's happening in investing and fintech, and we share what we learn. It's a place where you can stretch your skills, contribute to something real, and grow alongside people who take their craft seriously and enjoy building things together.


What you will do


In this role, you'll go beyond managing infrastructure. You'll shape our cloud technical direction, drive DevSecOps excellence across the organisation, and mentor DevOps engineers to help build and scale the platform that powers millions of trades. You will work closely with our Security Engineering colleagues: they set the standards and provide the independent challenge; you build the controls into the platform so that the secure path is also the fastest path for every team. To do this, you will have the help of other very experienced colleagues, the freedom to brainstorm and suggest new ideas, and the time to execute those ideas in a high-quality way.

As a Senior DevSecOps Engineer, your job is to lead from the front. This could mean:

  • Define and drive the technical vision for BUX cloud infrastructure across teams and set architectural standards for cloud-native solutions on Google Cloud Platform

  • Architect and implement highly available, fault-tolerant cloud infrastructure solutions with low-latency, high-throughput systems required for trading platforms, and own the disaster recovery and backup strategy behind them, proven by restore and failover tests against agreed RTO and RPO rather than by documentation

  • Lead 'Infrastructure as Code' initiatives using Terraform and evolve Kubernetes platforms for production workloads at scale, including the hardening baseline: network policy, admission control, workload identity and a credible upgrade track

  • Own the platform's identity and access model: least-privilege IAM, workload identity federation instead of long-lived keys, secrets storage and rotation, and break-glass paths that are logged and rehearsed

  • Secure the software supply chain end to end: dependency and container scanning, SBOM generation, artefact signing and build provenance, base image currency, and GitHub Actions runners and permissions that are locked down rather than convenient

  • Turn security and compliance requirements into policy-as-code guardrails in Terraform modules and CI/CD, so that a misconfiguration fails a build instead of surfacing in an audit

  • Run vulnerability and posture management across the cloud and container layers: detection, triage that separates the reachable from the theoretical, remediation SLAs, and an exception register that is genuinely reviewed

  • Technically lead and mentor DevOps engineers across teams, elevating technical capabilities organisation-wide through knowledge sharing and comprehensive documentation

  • Drive DevSecOps practices by setting standards for CI/CD pipelines, implementing security scanning, compliance checks, and building automation frameworks with GitHub Actions

  • Take end-to-end ownership of critical infrastructure projects, including messaging systems (Kafka, RabbitMQ), database infrastructure (Cassandra, CloudSQL), and comprehensive observability solutions covering security-relevant telemetry as well as performance

  • Collaborate with Java/Kotlin and Python development teams to optimise application performance, troubleshoot production issues, and ensure infrastructure supports Spring Boot microservices and data lake requirements

  • Lead strategic initiatives to improve system reliability, performance, and operational efficiency while ensuring compliance with financial services regulations (ISO 27001, GDPR, DORA), and make control evidence a by-product of the platform: change records, access recertification, configuration baselines and resilience test results produced automatically rather than assembled by hand

  • Lead the technical response when things go wrong, across both platform and security incidents, including participation in the on-call rotation, the technical input that drives incident classification and regulatory reporting timelines, and post-mortems that end in preventive change

What you need to succeed

  • Senior Technical Leadership level experience with proven ability to take ownership of projects from start to end

  • Expert knowledge of Google Cloud Platform (GCP) with focus on Kubernetes and container orchestration

  • Excellent command of 'Infrastructure as Code' using Terraform

  • Proficiency in Python development and advanced scripting capabilities (Bash)

  • Hands-on security engineering inside the delivery process, with real depth in several of: IAM and least-privilege design at scale, secrets management, pipeline security gating with genuine triage, policy-as-code, supply-chain signing and provenance, Kubernetes hardening, cloud network security. We do not expect all of these. We do expect several of them to be things you have built and operated, not evaluated

  • Experience working somewhere controls have to be evidenced rather than asserted, and the patience that goes with it

  • Experience with at least two of Kafka, CloudSQL (PostgreSQL & MySQL), and GitHub Actions

  • Deep understanding of CI/CD pipelines, DevOps best practices, and DevSecOps

  • Solid experience with monitoring, observability, and incident management at scale

  • Strong collaboration and communication skills across all organisational levels, including with the people whose job is to challenge your design

  • You regularly use GenAI tools, stay up to date with new ones, and encourage the team to use them to speed up delivery and improve how everyone works

  • A keen eye for detail while always keeping the big picture in mind

  • Track record of driving organisation-wide improvements and strategic initiatives

Nice to have
  • Practical experience of DORA, ISO 27001 or a comparable regime, ideally from the engineering side rather than the documentation side

  • Policy-as-code tooling (OPA, Conftest, Gatekeeper or equivalent) and cloud security posture management

  • Supply-chain security in practice: SBOM formats, cosign or Sigstore, SLSA-style provenance

  • Key and crypto management on a cloud KMS, including rotation and separation of duties

  • Threat modelling alongside product teams

  • Experience with serverless cloud technologies like Cloud Run and Cloud Functions

  • Experience with RabbitMQ and Cassandra

  • Working experience with Google PubSub and VertexAI

  • Ability to understand and work with Java/Kotlin code in Spring Boot applications

  • Understanding of financial services and neobroker business models

  • Certifications such as CKS or Google Professional Cloud Security Engineer, which we read as a signal rather than a requirement

Why join BUX as a Senior DevSecOps Engineer?

  • You will have space to share your ideas and be encouraged to express your voice

  • You will be one of the most skilled infrastructure experts in the room, with the authority to make strategic decisions on cloud architecture

  • You will be challenged to design and maintain critical infrastructure that handles high-volume trading data in real-time, ensuring reliability and security for millions of users

  • You will lead the technical direction of BUX's cloud infrastructure and shape DevOps practice across the entire engineering organisation

  • You will get to build security into the platform rather than inspect it afterwards, with the mandate, the budget and the time to do it properly

  • You will work with cutting-edge cloud technologies (GCP, Kubernetes, Terraform) and have the freedom to evaluate and champion adoption of new tools that provide strategic value

  • Lastly, the business domain is interesting. You will learn how the financial system works on the inside, and you will treat the strict requirements of financial services as a design constraint to engineer around rather than a form to fill in