Skip to main content
M

DevSecOps Engineer

Markit
5 days ago
Full-time
Remote
Web Development
Description

Markit is how procurement teams across Europe buy IT products. Around 200 people, 50+ countries, one platform, and a growing share of enterprise and bank customers who audit us before they buy. Your job is to make sure we have the answers before they ask. 

You join a small platform team that runs Azure, Kubernetes, deployments, Microsoft 365 and on-call. This is a hands-on platform role first: you run the infrastructure with the team, day to day, and you are the second pair of hands the migration needs. On top of that you own the security side and build it into a practice with owners, tooling and evidence. Expect the split to move: more platform work while the migration runs, more security once the baseline is in. 

The context you walk into: fully on Azure with Microsoft 365 and Defender, Azure DevOps for code and pipelines, Kubernetes in production. We are moving from a monolith to services, with the first services live in 2026 and the legacy platform retired in stages. That migration is infrastructure work as much as application work: new clusters, pipelines, environments and observability, built while the old platform still serves customers. ISO 27001 certification is the target for next year and the technical controls behind it are yours. Penetration testing stays with an external partner; you scope it, run it and close the findings. 

Requirements

  • 5+ years in platform/DevOps engineering, with hands-on Azure and Kubernetes in production: you have built clusters, pipelines and environments, run upgrades and carried on-call. Security engineering on top of that, owned rather than assisted, is what makes you a fit for this role. 
  • You have carried the technical side of ISO 27001 (or an equivalent framework) once already, or you have run vulnerability management end to end: finding, fix, verification, evidence an auditor accepts. 
  • You know the tooling by category rather than by logo: external attack surface monitoring, DAST, SAST, SCA, secrets and container scanning, cloud posture. You can pick the cheap option when it does the job and explain why. 
  • You script and automate by default. Bash, PowerShell or Python, infrastructure as code, and you treat a manual check as a bug. 
  • You write things down and can sit across from a customer’s security team or an auditor and answer plainly. 
  • Fluent English, Estonian or German is a plus.