Lead DevSecOps Engineer
Liquid Thought
Remote
Location: Cape Town (Hybrid)
Our client is a well-established and fast-growing fintech company operating in the payments space. With a lean, high-performing team of just over 50 people, they punch well above their weight, combining the agility of a startup with the rigour of a regulated financial services environment. They are looking for a hands-on Lead DevSecOps Engineer to own their security infrastructure and drive a proactive security culture across the business.
The Role
This is a builder's role, not a vendor management position. You will serve as the primary security architect, unifying a defence-in-depth strategy and moving the organisation away from reactive compliance toward genuine system resilience. The split is approximately 80% deep technical architecture and 20% team leadership, with dedicated mentorship support for your growth in people management.
Key Responsibilities
- Transform the SIEM platform into a true Security Nerve Centre, moving beyond log ingestion into Detection Engineering, with intelligent dashboards that baseline normal API behaviour
- Build automated threat response systems that trigger on unusual payloads or IOCs, rather than relying on manual next-day alerts
- Implement a standardised rate-limiting strategy across all endpoints and lead Chaos Engineering exercises to simulate DDoS and heavy load scenarios
- Shift security left by integrating vulnerability and intrusion detection insights directly into CI/CD pipelines using Policy-as-Code Security Gates, if a vulnerable configuration or dependency is introduced, the build fails automatically
- Mentor junior SecOps team members, evolving them beyond manual PCI audits toward proactive, technically deep security practice
What You Bring
- A degree in Computer Science, Engineering, or a related technical field
- 10+ years of hands-on experience in DevSecOps, Cloud Security, or Systems Engineering
- Deep expertise in AWS and Heroku, with strong IaC experience
- Solid knowledge of AWS networking and compute: VPCs, EC2, Auto Scaling, Load Balancers, CloudFront, ECS
- Hands-on experience with security tooling such as Sumo Logic, CrowdStrike, Snyk, Dependabot, AWS WAF, or Cloudflare
- A startup mindset, comfortable working across the stack and making decisions in ambiguity
- Familiarity with Angular/React and Ruby on Rails is a bonus
What's On Offer
- Competitive salary + discretionary annual bonus
- 30 days annual leave + 3 mental health days
- Medical aid contribution of up to R2,000/month
- Apple MacBook and necessary equipment
- Flexible hybrid working, you choose office or remote based on what makes sense
- Paid parking when in office
- A genuinely great team and culture