Devops Engineer L1
Summary
Build and maintain a secure DevSecOps platform for digital banking, using Terraform, CI/CD, and multi-cloud automation to enable teams to deploy software safely and consistently.
- Part of the DevSecOps Execution & Support function, partnering with development teams to deliver secure, high-quality software — for individuals with a strong will to learn, who are open and collaborative, and who want to make a meaningful impact on the future of digital banking and financial services.
- Contribute to building and maintaining the DevSecOps platform and tool chain — the internal, self-service platform that gives teams across ITG one consistent, secure, and auditable way to build, deploy, and operate software on any cloud.
- Build and maintain reusable infrastructure-as-code and pipeline components, under guidance and to the team's standards.
- Grow into DevSecOps and cloud-engineering practices, developing hands‑on capability across the tool chain.
- Enterprise Cloud Automation (ECA): contribute to building, hardening, and scaling the platform, including business‑unit onboarding.
- DevSecOps Adoption: support teams adopting the platform — tool chain standardization and hands‑on support to consuming squads
- Build and maintain reusable infrastructure-as-code modules (Terraform) and golden patterns, to established standards.
- Implement and extend platform components across AWS, Azure, and GCP, following the platform's architecture and standards.
- Help implement policy-as-code and automated guardrails so teams can provision within approved boundaries.
- Support and help quality‑assure vendor‑executed work against the platform's standards.
- Provide hands‑on support to squads consuming the platform — pipeline onboarding, basic troubleshooting, and small enhancements under guidance.
Requirements
- Working exposure to at least one public cloud — AWS, Azure, or GCP.
- Infrastructure-as-code — Terraform — working knowledge, willing to deepen.
- CI/CD — GitHub / GitHub Actions; containers — Docker and basic Kubernetes (EKS / AKS / GKE).
- Exposure to pipeline security tooling — SAST / DAST / SCA, container/image scanning (e.g. Trivy, Qualys), secrets management.
- Basic observability and monitoring; scripting (e.g. Python, Bash).
- Git-based workflows and code review.