Staff Platform Engineer

Job not on LinkedIn

🔥 57 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Shine

Shine

201 - 500 employees

💳 Fintech

🏦 Banking

☁️ SaaS

Fintech • Banking • SaaS

Shine is a European fintech that combines banking, accounting, payroll, and tax filing into a single SaaS platform designed to simplify financial administration for small businesses and entrepreneurs. Originating from an accounting marketplace, Shine has grown into an integrated financial ecosystem used by over 300,000 small businesses across multiple European countries, offering business banking, automated bookkeeping, payroll, invoicing, and tax services.

📋 Description

• Define and implement security architecture for the Azure estate, including policy guardrails, network security, encryption, identity hardening, and secure defaults • Own the security of the Azure landing zone and ensure workloads migrate onto a secure foundation • Own Entra ID security, including conditional access, Privileged Identity Management, workload identity governance, federation hardening with Okta, and tenant security • Co-own onboarding and configuration of the CNAPP platform, including posture management policies, finding prioritisation, and workflow integration • Build and maintain security controls as code using Terraform and Azure Policy, integrated into CI/CD • Ensure on-premises-to-Azure migrations happen securely through risk assessment, controls, and post-migration posture validation • Conduct threat modelling for Azure infrastructure designs and prioritise controls based on actual risk • Automate compliance evidence collection for ISO 27001, GDPR, and DORA • Align Azure security patterns with AWS and GCP for a coherent multi-cloud security posture • Enable cloud teams through security design reviews, paved-road patterns, documentation, and office hours • Assess Azure security posture, define landing-zone architecture, onboard CNAPP, deploy controls, harden Entra ID, improve detection, align cross-cloud standards, and enable team self-service

🎯 Requirements

• 8+ years of infrastructure or security engineering experience • Deep hands-on Azure security expertise at production scale • Staff-level technical authority, cross-team influence, and sound judgment • Strong Entra ID security expertise, including conditional access, PIM, workload identity, and federation hardening • Experience with Defender for Cloud, Sentinel, Azure Policy, network security, and Key Vault • Terraform infrastructure-as-code for security, policy-as-code, security modules, and CI/CD integration • Threat modelling capability covering cloud attack paths, privilege escalation, and lateral movement • Practical implementation of ISO 27001, GDPR, DORA, or similar compliance frameworks • CNAPP/CSPM tooling experience, such as Wiz, Cortex Cloud, Orca, Prisma Cloud, or Defender CSPM • Familiarity with observability platforms • Working knowledge of AWS or GCP security • Security detection experience with a SIEM, such as CrowdStrike, Splunk, Elastic, Sentinel, or Google Security Operations • Ability to influence without authority and set standards across teams • Excellent technical communication in English • Preferred: fintech, banking, or regulated financial services experience • Preferred: Okta and Entra ID federation security • Preferred: post-acquisition security integration experience • Preferred: DORA implementation experience • Preferred: GCP security experience • Preferred: on-premises or hybrid security experience • Preferred: supply-chain or CI/CD pipeline security • Relevant certifications preferred: AZ-500, SC-300, AZ-305

🏖️ Benefits

• Full remote in one of the European hubs, or hybrid in one of the hubs • Supportive and transparent hiring experience • Opportunity to work with a multicultural European team • Professional development through technical leadership, security design reviews, documentation, and office hours • Opportunity to contribute to cross-cloud security strategy • Equal treatment and non-discrimination in employment

Apply Now

Similar Jobs

🕒 July 24

Jedox

501 - 1000

☁️ SaaS

💸 Finance

🏢 Enterprise

AI Platform Engineer developing enterprise AI systems transforming data interaction at Jedox. Building scalable AI services, managing platforms, and ensuring compliance.

AWS

Azure

Cloud

Docker

Python