About this DevSecOps Engineer role at ThinkMarkets
ThinkMarkets is a global financial technology company, specializing in providing multi-asset trading solutions to thousands of clients around the world. With our flagship ThinkTrader platform, we make it available for our clients to trade the world 24-hours a day. Our mission is to bridge the gap between traders, investors, and platforms by allowing access to global markets and thousands of products thus providing our clients the ability to trade the world in the palm of their hand. We use the latest technologies to give traders seamless access to our proprietary trading platforms.
We are looking for a hands-on DevSecOps Engineer to own, secure, and scale our infrastructure and deployment pipelines. You will work directly with our engineering team to embed security into our CI/CD workflows, manage vulnerabilities, and ensure our financial trading systems are resilient, compliant, and highly available.
Key Responsibilities
Pipeline Security & Automation
- Design, maintain, and harden CI/CD pipelines across our delivery lifecycle.
- Integrate automated security testing tools, including SAST, DAST, dependency scanning, and container scanning, directly into development workflows.
- Proactively suggest automation improvements to reduce manual overhead and accelerate secure software delivery.
Vulnerability & Risk Management
- Lead end-to-end vulnerability management, including triage, remediation tracking, and cross-team reporting.
- Audit existing infrastructure and deployment workflows to identify gaps, risks, or inefficiencies.
- Contribute to disaster recovery (DR), business continuity (BC), and robust change management processes to guarantee platform resilience.
Compliance & Data Protection
- Support the secure handling of sensitive and regulated financial data across all environments.
- Work closely with the Compliance team to implement security controls and collect evidence for external audits.
- Document all security architecture, pipeline logic, and automated rules for team handoff and future maintenance.
- Promote a security-aware engineering culture through modern tooling, clear documentation, and proactive knowledge sharing.
Requirements
- 3+ years of demonstrable experience in a DevOps, SRE, or DevSecOps role within a production environment for financial services.
- Proven experience building, maintaining, and hardening CI/CD tooling and infrastructure as code.
- Deep understanding of relevant security frameworks and standards (e.g., ISO 27001, PCI DSS, SOC 2).
- Practical exposure to database high availability tooling and managed datastore operations.
- Strong understanding of modern data models, containerization, and cloud security architecture.
- Excellent English communication skills — you will work closely with global teams and document critical infrastructure logic.
- Relevant industry certifications (e.g., AWS Certified Security, Certified DevSecOps Professional, CISSP, or equivalent) are highly preferred.
- Background in financial technology, SaaS environments, or secure cloud-native infrastructure best practices.