Lupa Hire
Back to all positions

Overview

At Lupa, we're hiring a Senior DevSecOps Engineer to join a fast-growing, world-class fintech platform that's redefining how people invest — from seamless stock trading and gold investment to Murabaha, IPO subscriptions, and more. This is a mission-critical role built around one philosophy: Security Everywhere.

You'll be securing the entire fabric of a high-throughput trading platform serving nearly a million active customers. If you get excited about architecting systems where the "path of least resistance" is also the most secure path — and you want to do it inside a genuinely international, high-performance team spanning multiple continents — this is a rare opportunity.

This is a remote, full-time contractor role. Because the platform's core product is US trading, you'll be aligned with New York market hours, giving you meaningful ownership during the most crucial trading windows while collaborating with an experienced, distributed engineering organization.

What You'll Do

Identity, Access & Zero Trust (IAM)

  • Architect and manage robust Role-Based (RBAC) and Attribute-Based (ABAC) access control across cloud (Oracle OCI and others), Kubernetes, and internal tools.

  • Implement Privileged Access Management with just-in-time (JIT) access to production infrastructure (Teleport, HashiCorp Boundary, or similar).

  • Eliminate long-lived SSH keys and enforce MFA, SSO (JumpCloud, Okta/Auth0), and strong identity policies org-wide.

Comprehensive Infrastructure Security

  • Harden Kubernetes: secure container lifecycles, enforce Pod Security Standards, and manage Network Policies for strict environment isolation.

  • Design network segmentation, WAF/firewalls, and DDoS protection suitable for high-throughput trading APIs.

  • Own the full lifecycle of secrets (API keys, certificates, credentials) using Oracle Key Management.

Secure CI/CD & Software Supply Chain

  • Embed automated security gates (SAST, DAST, SCA) into pipelines (GitLab/Jenkins/GitHub) to block vulnerabilities before production.

  • Implement image signing (Cosign/Notary) so only trusted, verified code runs in clusters.

Compliance, Auditing & Monitoring

  • Ensure all infrastructure access and changes are logged, immutable, and auditable to meet SOC2, ISO 27001, and financial regulatory standards.

  • Integrate security alerts into the monitoring stack (Prometheus, Grafana, ELK) to detect anomalies and unauthorized access in real time.

Operate with Autonomy

  • Because of the time-zone alignment, you'll frequently work independently during peak trading hours — resolving issues, making decisions on the spot, and keeping systems healthy without immediate hands-on support from other teams.

Who You Are

Must-Haves

  • 8+ years in DevOps, Cloud Security, or SRE roles, with at least 4 years focused on DevSecOps or security.

  • Experience in high-traffic or regulated financial environments (trading, fintech, or banking).

  • A strong "Security as Code" mindset — you automate security rather than relying on manual checklists.

  • Deep understanding of cloud IAM (OCI, AWS, GCP, or Azure equivalents), OIDC/SAML, and modern access tools (Teleport, StrongDM).

  • Expert-level Kubernetes security: security contexts, admission controllers (OPA Gatekeeper/Kyverno), and service mesh (Istio/Linkerd) for mTLS.

  • Proficiency in Infrastructure as Code (Terraform/Ansible), writing secure modules with tools like Checkov or tfsec.

  • Deep Linux kernel security (SELinux/AppArmor) and networking knowledge (TCP/IP, DNS, BGP, TLS).

  • Excellent English communication skills — you'll collaborate daily across a multinational team.

Nice-to-Haves

  • Experience with financial compliance audits (SEC, FINRA, GDPR).

  • Background in cryptography (PKI management, encryption standards).

  • Experience with Chaos Engineering for security — testing system resilience against attacks.

What's In It For You

  • Compensation: USD $8,000 – $10,000 per month, paid as a full-time contractor.

  • Work setup: Fully remote from Latin America.

  • Schedule: Aligned to US/New York trading hours (roughly standard daytime business hours in Latin America).

  • Payments: International contractor payments handled reliably.

  • Impact & growth: Own security architecture at a market-leading fintech during a pivotal scaling phase — your work directly shapes how the platform reaches its next level.

  • Culture: Join a genuinely global, senior-heavy team that values autonomy, directness, and strong engineering craft.

Application

Ready to build security into the DNA of a high-growth fintech platform? We'd love to hear from you. Apply through Lupa and one of our specialist technical recruiters will reach out to walk you through the process, answer your questions, and set up next steps. We move with urgency but focus on finding the right fit — so if this sounds like you, don't wait to apply.

Other Open Positions