As a Senior Platform Engineer - DevSecOps at Rosterfy, you will be the hands-on security engineering owner for the cloud infrastructure that powers Rosterfy across AWS (our primary platform, running the main app and web app) and GCP (our data layer). You will take ownership of the platform security working with the broader engineering team to embed continuous, shift-left security as a paved road for every squad rather than a gate that slows them down.
You will be central to how we scale Rosterfy (event-driven architecture and domain-driven design), working across Kubernetes (EKS), CI/CD pipelines (BuildKite and GitHub), observability tooling, and infrastructure as code. Security is built into all of it: you will own secret management, identity and access, policy-as-code guardrails, vulnerability management, and the technical evidence behind our SOC 2, ISO 27001, & GDPR obligations, working alongside Engineering.
You will improve developer experience through better local workflows, automation, and consistent environments, and you will help us safely enable AI at scale: not just standing up LLM, RAG, and vector workloads, but securing them against prompt injection, data leakage, and supply-chain risk, and governing how AI coding assistants are used across the team. You will play a key role down the line as to how we evolve the platform to support our data and ML ambitions across BigQuery, Vertex AI, and real-time event processing.
In your first 90 days you will document our security architecture and key operational runbooks, ensuring this critical knowledge is captured and resilient as the team grows.