Summary
A hands-on Platform and DevOps Lead position for an engineer who writes infrastructure code, automates operational work, and sets standards for reliable software delivery. The role centers on Terraform, cloud infrastructure, deployment pipelines, and establishing a clean production environment with a robust promotion path.
Highlights
A hands-on engineering leadership role with substantial ownership of infrastructure and deployment standards. You will build infrastructure as code, automate manual processes, create reliable deployment pipelines, and lead improvements to speed, resilience, and production readiness.
Description
Role and Company Overview
EC Markets runs a UK markets business on top of a real engineering estate: trading apps, a CRM, AI services, websites, and data platforms.
We move quickly and ship often and our infrastructure has to keep up without breaking things.
We're looking for a Platform / DevOps Lead: a hands-on engineer who codes their infrastructure, automates the manual stuff, and sets the standard for shipping trusted changes.
You'll own infrastructure-as-code end to end Terraform first, with our existing AWS CDK stacks alongside it and you'll have the mandate to fix what's slow or fragile.
This is a doer's role with real ownership.
You write the Terraform, you build the pipelines, you carry the standard.
Your flagship first project is already waiting: stand up a cleanly separated production environment with a credible Devroy promotion path.
Key Responsibilities
Own infrastructure-as-code across the estate.
Terraform is the primary tool managing both AWS and Snowflake from a single, version-controlled source of truth and you'll also own the AWS CDK (TypeScript) stacks.
Drive the estate toward consistent, reusable, well-tested IaC.Stand up a real production environment.
Build a clean separation between development and production and a safe, repeatable promotion path between them.
This is the headline gap and your first big win.Build and harden CI/CD.
GitHub Actions with OIDC, matrix container builds to ECR, plan-on-pull-request with deliberate applies, and multi-environment staging production promotion.
Make deploys predictable and reversible.Automate away the toil.
Secret provisioning and rotation, state-lock hygiene, drift detection, safe-apply guardrails.
Every manual runbook step is a candidate for a pipeline.Run the AWS footprint.
VPC and networking, ECS Fargate, DMS, S3, IAM, Secrets Manager, EventBridge provisioned as code, sized sensibly, and cost-aware (you'll make the calls on things like NAT vs VPC endpoints).Own observability and reliability.
CloudWatch alarms and dashboards, SNS alerting, data freshness and quality signals, and automated recovery for the pipelines that need it.
When something breaks at 2am, you've already built the thing that catches it.Manage Snowflake as code.
Storage and notification integrations, Snowpipe ingestion, role-based access control, SSO via Entra ID (SAML/SCIM), and data masking / PII governance.Set the bar for trusted code.
Code review, tests, repeatable deploys, clean rollbacks.
Partner with product and data engineers so they can move fast without fear and so what ships is what was reviewed.What we're looking for
Deep Terraform.
Multi-provider setups, reusable modules, remote state and locking, and a healthy respect for what a bad plan can do in production.Strong AWS.
Hands-on across networking, containers (ECS/Fargate), IAM, S3, Secrets Manager, and event-driven scheduling built as code, not clicked in the console.CI/CD you've actually built.
GitHub Actions (or equivalent), OIDC-based cloud auth, container builds, and multi-environment delivery pipelines.Docker fluency building, slimming, tagging, and shipping images through a registry.Deep understanding in VPC, Subnets, Routing, Gateways, trust boundaries.Comfortable in Python and Bash to glue systems together and automate operations.Security instincts.
Sound secrets management and least-privilege IAM as a default, not an afterthought.Polyglot comfort.
You can read across Python, TypeScript, and Java well enough to unblock a build or debug a pipeline you don't need to own those apps, just keep them shipping.A bias to ship and automate.
You'd rather write the automation once than do the manual step twice.
You finish things.Essential Requirements
Degree in Computer Science, Data Engineering, or related field.8+ years of hands-on experience as a Devops or Platform engineerExcellent understanding of networking andA WS cloud.Knowledge of security frameworks (ISO 27001, NIST) applied in practice.Experience with DevOps tooling, automation, and secure system design.Certifications such as CISSP, CISM, CCSP, or cloud security certifications are desirable.Desirable
AWS CDK (TypeScript)AWS DMS / change-data-capture, Kinesis Firehose, or other streaming-ingest toolingEntra ID (Azure AD) SSO and SCIM provisioningFinOps / cloud cost optimisationA background working with regulated or financial-services dataLocation:
1 day a week remote and 4 days in office @ 30 City Rd, London
How we work
Iterate fast, deploy safely.
Small changes, often โ backed by plan-on-PR, deliberate applies, and easy rollbacks.Everything is code.
Infrastructure, pipelines, access, and policy all live in version control and ship through review.Observability first.
If we run it, we can see it โ and we get told before our users do.You own what you ship.
Strong ownership, low ceremony.
We trust the people closest to the work to make the call.
Benefits
Competitive salary and performance-based bonusPension schemeDiscretionary bonusProfessional development and certification supportOpportunity to work within a growing global financial services organisation