Senior DevSecOps Engineer
Vivid Money Group is a European fintech providing personal and business financial services through digital accounts. Its offerings include payments, cards, cashback, interest accounts, international transfers, bookkeeping tools, and investment services for individuals, freelancers, companies, and enterprises.
Maintainer signals as of 8/23/2026
About Vivid Money Group
Vivid Money Group operates a digital financial platform serving individuals, freelancers, SMEs, and larger businesses across Europe. Its services include business and personal accounts, unlimited IBANs, Visa cards, cashback, SEPA and SWIFT transfers, international payments, online payment acceptance, invoicing, bookkeeping integrations, tax filing, business travel, and team spending controls. The group also provides interest accounts, model portfolios, brokerage services, stocks, ETFs, money market funds, and cryptocurrency services through regulated Vivid entities in Luxembourg and the Netherlands.
Skills
About the Role
Join Vivid’s security and engineering teams to strengthen security practices across a fully cloud-native AWS environment. Improve cloud and Kubernetes security, vulnerability management, infrastructure and application security reviews, and AI-aware security controls.
Requirements
- 5+ years of hands-on experience in DevSecOps, Cloud Security, or related fields
- Strong hands-on experience operating AWS and Kubernetes in production environments
- Experience implementing security in Infrastructure as Code and CI/CD workflows
- Solid understanding of cloud security fundamentals such as access control, secrets management, network security, and encryption
- Familiarity with container security and common application security risks
- Deep understanding of AI/LLM security risks and hands-on experience securing AI infrastructure components such as LLM gateways, MCP servers, or agent-based workflows
- Comfortable with scripting and working in Git-based development environments
- Good communication skills and ability to work effectively with engineering and product teams
- Comfortable communicating clearly in English, both written and spoken
- Experience scaling security practices in fast-growing or regulated environments is a nice to have
- Experience building internal security tooling or automation from scratch is a nice to have
Responsibilities
- Continuously improve the security of AWS and Kubernetes platforms
- Strengthen IAM, RBAC, encryption, secrets management, and network controls through secure-by-default policy-as-code
- Manage edge security, including traffic filtering, WAF configuration, and external exposure management
- Perform security reviews of new services, architectural changes, and platform components
- Embed automated security controls into SDLC and CI/CD, including SAST, dependency and container scanning, and policy enforcement
- Lead vulnerability management processes, including detection, assessment, prioritization, and reporting
- Integrate automation and AI-assisted tooling to enhance security reviews and reduce manual effort
- Define and implement security controls for AI infrastructure components, including gateways, MCP servers, and model proxies
- Identify and mitigate AI-specific risks such as prompt injection, data leakage, and agent privilege escalation
Benefits
- Hybrid model in Limassol office, or fully remote outside office locations
- Relocation support to Cyprus, including visa and package, when needed
- Learning and development budget
- Fully paid vacation and sick leave
- Sports compensation
- Real growth prospects and significant responsibility
