Description
About Ryft
Ryft is a high-growth fintech start-up building the payments platform that powers marketplaces and merchants globally.
We handle the secure processing, splitting, and movement of money at scale, so our customers can focus on their business instead of the complexity of payments.
We're growing fast, and every hire has a real impact on our trajectory.
About the Role
We're looking for an experienced Senior Platform Engineer to join a newly established, dedicated Platform Team and lay the foundation of our cloud infrastructure, edge protections, and developer enablement.
You'll own how we build, deploy, and run our systems on AWS, defining our infrastructure as code with AWS CDK and making it easy for our engineers to ship safely and fast.
Reporting directly to the CTO, you will work side-by-side with our Lead Security Engineer to own our infrastructure-as-code (IaC), deployment automation, and multi-account AWS topology.
You will build automated guardrails that make shipping compliant, highly resilient software second nature for our product engineers.
This is a hands-on, high-ownership role.
As a senior member of the team, you'll set standards for infrastructure, automation, and operational excellence as we scale, in an environment where security and reliability are non-negotiable.
You'll be comfortable working autonomously in a remote-first setup while staying closely connected to the engineering team.
Key Responsibilities
Multi-Account AWS Architecture & Infrastructure-as-Code
Architect, standardize, and maintain our multi-account AWS environment (AWS Organizations, Control Tower, Service Catalog, IAM Identity Center).Model 100% of core cloud infrastructure using AWS CDK with TypeScript, establishing clean, modular constructs for product engineering teams.Enforce granular, least-privilege IAM policies and roles across services and accounts, eliminating cross-account security vulnerabilities.Manage container lifecycles utilizing Amazon ECS and Amazon ECR, including image vulnerability scanning, caching, and immutable tag deployments.Dedicated Edge Layer & Network Security Partnership
Design, deploy, and maintain a dedicated, hardened Edge Layer utilizing AWS WAF, CloudFront/ALB, and rate-limiting rules to shield payment processing APIs from DDoS attacks, malicious bots, and OWASP Top 10 exploits.Partner closely with the Lead Security Engineer and engineering leads to define, architect, and enforce secure, compliant cloud networks (VPC peering, Transit Gateway routing, ingress/egress filtering, and DirectConnect/VPN tunnels) to strictly isolate PCI-DSS in-scope cardholder data environments (CDE).CI/CD & Developer Enablement ("The Paved Road")
Design, build, and optimize enterprise-grade CI/CD workflows using GitHub Actions (reusable workflows, custom actions, OIDC authentication to AWS via IAM roles).Provide the tooling, guardrails, and self-service mechanics that let engineering squads move quickly and independently.Observability, Reliability & Hybrid Infrastructure Context
Implement native telemetry, logging, and distributed tracing across payment services using AWS tooling (CloudWatch, Container Insights, X-Ray) alongside Prometheus and OpenTelemetry.Bring foundational data center and networking context (physical networking fundamentals) to collaborate seamlessly on cloud and hybrid connectivity.
Technical Skills and Responsibilities
Core AWS Services Mastery: Deep production experience with ECS, ECR, SNS, SQS, IAM, and AWS WAF.Advanced AWS CDK (TypeScript): Strong proficiency in TypeScript and experience building enterprise CDK constructs, custom resources, and pipeline abstractions.Dedicated Edge & Security Collaboration: Proven track record of configuring edge protections (AWS WAF, CloudFront) and partnering with security teams to implement segmented, compliant cloud networks.Multi-Account AWS Topologies: Experience managing multi-account structures, IAM cross-account roles, Control Tower, SCPs, and complex networking.GitHub Actions Mastery: Advanced knowledge of GitHub Actions workflows, matrix builds, custom actions, and secret-less OIDC authentication to AWS.
Nice to Have
PCI/Regulated Environments: Experience operating infrastructure in PCI-DSS or similarly regulated/audited environments.Payments/Fintech & Security: Exposure to tokenization architectures, HSM/KMS key management, and payment gateway infrastructure.Physical Infrastructure: Prior exposure or familiarity with data center networking, co-location, or direct interconnect mechanics.
Why Ryft?
If you're excited about working in a fast-paced, collaborative environment and want to build the infrastructure that powers the future of fintech, we'd love to hear from you.
We value engineers who take ownership, automate relentlessly, and care as much about reliability and security as they do about speed.
Right to Work: Applicants must have the right to work in the UK.