Platform / DevOps Engineer
EC Markets LTD · London Borough of Islington, England, United Kingdom
Financial Services · 51-200 employees
About the role
The role involves managing infrastructure-as-code using Terraform and AWS CDK to ensure reliable, automated deployments. You will be responsible for building and hardening CI/CD pipelines, managing AWS and Snowflake environments, and ensuring system observability and security.
What they look for
Requirements
Candidates must have at least 8 years of hands-on experience in DevOps or Platform engineering with a strong background in AWS and networking. A degree in Computer Science or a related field is required, along with proficiency in automation, security frameworks, and infrastructure-as-code tools.
Benefits
Full description
Role and Company Overview
EC Markets runs a UK markets business on top of a real engineering estate: trading apps, a CRM, AI services, websites, and data platforms. We move quickly and ship often and our infrastructure has to keep up without breaking things.
We're looking for a Platform / DevOps Lead: a hands-on engineer who codes their infrastructure, automates the manual stuff, and sets the standard for shipping trusted changes. You'll own infrastructure-as-code end to end Terraform first, with our existing AWS CDK stacks alongside it and you'll have the mandate to fix what's slow or fragile.
This is a doer's role with real ownership. You write the Terraform, you build the pipelines, you carry the standard. Your flagship first project is already waiting: stand up a cleanly separated production environment with a credible Devroy promotion path.
Key Responsibilities
- Own infrastructure-as-code across the estate. Terraform is the primary tool managing both AWS and Snowflake from a single, version-controlled source of truth and you'll also own the AWS CDK (TypeScript) stacks. Drive the estate toward consistent, reusable, well-tested IaC.
- Stand up a real production environment. Build a clean separation between development and production and a safe, repeatable promotion path between them. This is the headline gap and your first big win.
- Build and harden CI/CD. GitHub Actions with OIDC, matrix container builds to ECR, plan-on-pull-request with deliberate applies, and multi-environment staging production promotion. Make deploys predictable and reversible.
- Automate away the toil. Secret provisioning and rotation, state-lock hygiene, drift detection, safe-apply guardrails. Every manual runbook step is a candidate for a pipeline.
- Run the AWS footprint. VPC and networking, ECS Fargate, DMS, S3, IAM, Secrets Manager, EventBridge provisioned as code, sized sensibly, and cost-aware (you'll make the calls on things like NAT vs VPC endpoints).
- Own observability and reliability. CloudWatch alarms and dashboards, SNS alerting, data freshness and quality signals, and automated recovery for the pipelines that need it. When something breaks at 2am, you've already built the thing that catches it.
- Manage Snowflake as code. Storage and notification integrations, Snowpipe ingestion, role-based access control, SSO via Entra ID (SAML/SCIM), and data masking / PII governance.
- Set the bar for trusted code. Code review, tests, repeatable deploys, clean rollbacks. Partner with product and data engineers so they can move fast without fear and so what ships is what was reviewed.
What we're looking for
- Deep Terraform. Multi-provider setups, reusable modules, remote state and locking, and a healthy respect for what a bad plan can do in production.
- Strong AWS. Hands-on across networking, containers (ECS/Fargate), IAM, S3, Secrets Manager, and event-driven scheduling built as code, not clicked in the console.
- CI/CD you've actually built. GitHub Actions (or equivalent), OIDC-based cloud auth, container builds, and multi-environment delivery pipelines.
- Docker fluency building, slimming, tagging, and shipping images through a registry.
- Deep understanding in VPC, Subnets, Routing, Gateways, trust boundaries.
- Comfortable in Python and Bash to glue systems together and automate operations.
- Security instincts. Sound secrets management and least-privilege IAM as a default, not an afterthought.
- Polyglot comfort. You can read across Python, TypeScript, and Java well enough to unblock a build or debug a pipeline you don't need to own those apps, just keep them shipping.
- A bias to ship and automate. You'd rather write the automation once than do the manual step twice. You finish things.
Essential Requirements
- Degree in Computer Science, Data Engineering, or related field.
- 8+ years of hands-on experience as a Devops or Platform engineer
- Excellent understanding of networking andA WS cloud.
- Knowledge of security frameworks (ISO 27001, NIST) applied in practice.
- Experience with DevOps tooling, automation, and secure system design.
- Certifications such as CISSP, CISM, CCSP, or cloud security certifications are desirable.
Desirable
- AWS CDK (TypeScript)
- AWS DMS / change-data-capture, Kinesis Firehose, or other streaming-ingest tooling
- Entra ID (Azure AD) SSO and SCIM provisioning
- FinOps / cloud cost optimisation
- A background working with regulated or financial-services data
Location:
1 day a week remote and 4 days in office @ 30 City Rd, London
How we work
- Iterate fast, deploy safely. Small changes, often — backed by plan-on-PR, deliberate applies, and easy rollbacks.
- Everything is code. Infrastructure, pipelines, access, and policy all live in version control and ship through review.
- Observability first. If we run it, we can see it — and we get told before our users do.
- You own what you ship. Strong ownership, low ceremony. We trust the people closest to the work to make the call.
Benefits
- Competitive salary and performance-based bonus
- Pension scheme
- Discretionary bonus
- Professional development and certification support
- Opportunity to work within a growing global financial services organisation