At ThetaRay, our purpose is to make the world a safer place by protecting the integrity of the global financial system.
We do this by putting AI at the core of both our technology and our way of working. Our AI-driven solutions help banks and fintech companies worldwide detect and stop serious financial crime, from human trafficking and terrorist financing to sophisticated money laundering, while advanced technology, automation, and AI-driven tools help our teams collaborate smarter, move faster, and continuously improve how we build, deliver, and innovate.
About the role:
We are looking for a DevSecOps Engineer to turn expertise, initiative, and bold thinking into real impact on the next generation of AI-driven financial crime detection.
If you combine strong security engineering and DevOps capabilities with hands-on experience in Kubernetes environments, vulnerability management, and secure CI/CD practices, and if you are motivated by strengthening the security and compliance posture of a cloud-native platform trusted by global financial institutions, ThetaRay could be your next challenge.
Responsibilities:
- Identify, analyze, prioritize, and remediate security vulnerabilities, including CVEs in containers, application dependencies, and infrastructure components.
- Work closely with engineering and DevOps teams to fix vulnerabilities across CI/CD pipelines, container images, Kubernetes workloads, and cloud infrastructure.
- Support and secure Kubernetes environments, preferably Azure Kubernetes Service (AKS), with experience in OpenShift Container Platform (OCP) considered an advantage.
- Implement and maintain security controls across cloud-native platforms, including container security, image scanning, runtime security, and Kubernetes hardening.
- Work with Static Code Analysis / SAST tools to identify code-level security risks and help development teams remediate findings.
- Work with CSPM tools to detect and resolve cloud security misconfigurations.
- Automate security, compliance, and operational tasks using Bash and other scripting tools.
- Support secure software delivery processes, including CI/CD security gates, vulnerability scans, policy enforcement, and compliance checks.
- Collaborate with global teams across different time zones to support security initiatives, incident response, and platform improvements.
- Promote DevSecOps best practices and help embed security into the software development lifecycle.