About the Position
We are looking for a DevSecOps Engineer to maintain and evolve these foundations within a long term program. You will own cloud infrastructure, CI/CD pipelines, and security controls for one or more program workstreams. You will participate in release planning and own deployment runbooks and rollback procedures.
The role requires working from the office three days per week. The candidate should be based in either Cluj Napoca or Bucharest.
About the Project
DataArt supports cloud infrastructure across reference data platforms, fixed income analytics, desktop application migrations, and financial data platforms, primarily on AWS. The target deployment architecture is Kubernetes on AWS. The role focuses on extending existing solutions rather than rebuilding them from scratch. Teams are distributed across the EU and work fully remotely.
Responsibilities
- Maintain and extend AWS infrastructure that supports zero impact release patterns.
- Write and maintain Infrastructure as Code using Terraform, CloudFormation, and Ansible.
- Operate and improve CI/CD pipelines (GitHub Actions or Jenkins), and implement automated quality gates.
- Manage Kubernetes clusters (AWS EKS), and support microservice deployments and namespace management.
- Embed security controls, including SAST and DAST within pipelines, SBOM generation, dependency scanning, and secrets rotation.
- Own monitoring and alerting using Datadog, Grafana, and Prometheus.
- Own deployment runbooks and rollback procedures.
Requirements
- 5+ years of experience in DevOps or platform engineering, with significant AWS production experience.
- Experience with AWS services, including EKS, EC2, Lambda, S3, Aurora, API Gateway, and Route 53.
- Experience with Infrastructure as Code using Terraform and/or CloudFormation.
- Experience with containers and orchestration, including Kubernetes cluster operations, namespace management, and Helm.
- Experience authoring CI/CD pipelines using GitHub Actions or Jenkins.
- Experience with security tooling, including SAST, DAST, dependency scanning, SBOMs, and AWS Secrets Manager or HashiCorp Vault.
- Scripting experience with Linux (Ubuntu/RHEL), Bash, and Python.
- Experience with monitoring tools such as Datadog, Prometheus, and Grafana.
- Proficient English for technical communication (B2+).
Nice to Have
- GCP experience.
- Aurora PostgreSQL administration and Liquibase schema migrations.
- Experience with enterprise job scheduling tools, such as BMC Control M.
- Background in financial services or capital markets infrastructure.