Senior DevSecOps Engineer

Vivid is a European financial-services company offering digital business and personal accounts, cards, transfers, payment acceptance, and investment products.

Maintainer signals as of 8/23/2026

Luxembourg, LU
About Vivid

Vivid provides an all-in-one digital financial platform for companies, freelancers, and personal users. Its services include business accounts with multiple IBANs and sub-accounts, Visa cards and cashback, SEPA Instant and international payments, invoicing, bookkeeping integrations, payment links, POS terminals, and business travel tools. It also offers investment products such as interest accounts, model portfolios, and business brokerage for money market funds, ETFs, stocks, bonds, and crypto assets. Payment services are provided by Vivid Money S.A. in Luxembourg, while investment and crypto services are provided by Vivid Money B.V. in Amsterdam.

View jobs by Vivid

Skills

About the Role

Join Vivid’s security and engineering teams to strengthen security practices across a fully cloud-native AWS environment. Improve cloud and Kubernetes security, vulnerability management, infrastructure and application security reviews, and AI-aware security controls.

Requirements

  • 5+ years of hands-on experience in DevSecOps, Cloud Security, or related fields
  • Strong hands-on experience operating AWS and Kubernetes in production environments
  • Experience implementing security in Infrastructure as Code and CI/CD workflows
  • Solid understanding of cloud security fundamentals such as access control, secrets management, network security, and encryption
  • Familiarity with container security and common application security risks
  • Deep understanding of AI/LLM security risks and hands-on experience securing AI infrastructure components such as LLM gateways, MCP servers, or agent-based workflows
  • Comfortable with scripting and working in Git-based development environments
  • Good communication skills and ability to work effectively with engineering and product teams
  • Comfortable communicating clearly in English, both written and spoken
  • Experience scaling security practices in fast-growing or regulated environments is a nice to have
  • Experience building internal security tooling or automation from scratch is a nice to have

Responsibilities

  • Continuously improve the security of AWS and Kubernetes platforms
  • Strengthen IAM, RBAC, encryption, secrets management, and network controls through secure-by-default policy-as-code
  • Manage edge security, including traffic filtering, WAF configuration, and external exposure management
  • Perform security reviews of new services, architectural changes, and platform components
  • Embed automated security controls into SDLC and CI/CD, including SAST, dependency and container scanning, and policy enforcement
  • Lead vulnerability management processes, including detection, assessment, prioritization, and reporting
  • Integrate automation and AI-assisted tooling to enhance security reviews and reduce manual effort
  • Define and implement security controls for AI infrastructure components, including gateways, MCP servers, and model proxies
  • Identify and mitigate AI-specific risks such as prompt injection, data leakage, and agent privilege escalation

Benefits

  • Hybrid model in Limassol office, or fully remote outside office locations
  • Relocation support to Cyprus, including visa and package, when needed
  • Learning and development budget
  • Fully paid vacation and sick leave
  • Sports compensation
  • Real growth prospects and significant responsibility