We are a leading trading platform that is ambitiously expanding to the four corners of the globe. Our top-rated products have won prestigious industry awards for their cutting-edge technology and seamless client experience. We deliver only the best, so we are always in search of the best people to join our ever-growing talent team.
📊 Capital.com is a global trading platform offering clients to invest in Gold, Oil, Apple, Tesla and 6,500+ other world-renowned markets. We are enhancing our Technical Team and looking for great Engineers with an interest in trading to join our Team!a
🔎 We are seeking a skilled DevSecOps professional to secure and optimize our trading platform's infrastructure, integrating security into the CI/CD pipeline while ensuring compliance and performance
-
Designing Secure CI/CD Pipelines: Develop and maintain automated CI/CD pipelines (preferable Gitlab) with a focus on security best practices, including SAST/DAST/SCA, vulnerability assessment,
-
Infrastructure Security: Implement and maintain infrastructure as code using Terraform / CloudFormation / Ansible, ensuring secure configuration and compliance with industry standards and regulatory requirements,
-
Security Monitoring and Incident Response: Set up and manage security monitoring tools to detect and respond to security incidents promptly. Develop incident response playbooks and collaborate with relevant teams to address security incidents effectively
-
Security Compliance: Ensure compliance with industry regulations (PCI DSS, GDPR, local financial regulation) and internal security policies. Conduct regular security assessments and audits to identify and address compliance gaps,
-
Security Tooling and Automation: Evaluate, deploy, and manage security tools and technologies to automate security processes and enhance overall security posture.
-
Secrets Management: Design, implement, and maintain robust secrets management solutions and processes using Hashicorp Vault and AWS SM / KMS
-
Collaboration and Knowledge Sharing: Work closely with development, operations, and product teams to embed security into the software development lifecycle. Provide security training and guidance to team members to increase awareness and promote a security-first culture. Maintain comprehensive documentation and playbooks for configuring, operating, and troubleshooting security solutions
-
Risk Management: Participate in risk assessments and threat modelling exercises to identify potential security risks and vulnerabilities. Develop and implement risk mitigation strategies to minimise exposure to security threats.
- Proven experience in DevOps, software engineering, or related roles, with a focus on security
- Hands-on experience with cloud platforms (AWS, Azure, GCP), containerization technologies (Docker, Kubernetes), configuration management (Ansible)
- Proficiency in scripting and automation using languages such as Python or Bash
- Strong understanding of security principles, protocols, and standards (e.g., OWASP Top 10, NIST Cybersecurity Framework, CIS Benchmarks)
- Experience with security testing tools (e.g., Tryvi, Prowler, ScoutSuite, SonarQube, OWASP ZAP, Nessus) and vulnerability management processes
- Excellent communication and collaboration skills, with the ability to work effectively in a cross-functional team environment
- Knowledge of financial industry regulations and compliance requirements is a plus
- Demonstrated ability to adapt to a fast-paced, dynamic environment and drive initiatives independently
-
Communication: Effective communication skills, especially with teams responsible for security, operations and product
-
Analytical thinking: Ability to tackle and investigate complicated problems and convert it to the task
-
Adaptability to Rapid Changes: Demonstrated capability to adjust to quick technological shifts and evolving business requirements
-
Ownership and Accountability: Readiness to take ownership of tasks, issues as well as demonstrate accountability of the results and outcome
- You will join the company, that cares about work and life balance
- Annual Bonus based on the performance review cycle
- Generous Annual Leave Policy
- Medical Insurance and Pension fund, with additional benefit packages based on the location
- Flexible work options: choose between a hybrid model or fully remote work across your country of employment
- Workation Policy with 30 additional days working remotely from anywhere in the world
- Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts
Be a key player at the forefront of the digital assets movement, propelling your career to new heights!
Join a dynamic and rapidly expanding company that values and rewards talent, initiative, and creativity.
Work alongside one of the most brilliant teams in the industry.