Senior Site Reliability Engineer

Reapglobal β€” Hong Kong Sar Β· Posted ~3 hours ago

Senior Full-time

Skills

Site Reliability Engineering AWS PCI DSS financial systems operations distributed systems cloud infrastructure

πŸ”“ Log in to save this job, tailor your resume & track your apply process β€” 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Join a growing Site Reliability Engineering practice responsible for highly available financial infrastructure operating across multiple cloud regions. You will help run regulated, high-scale systems spanning payments, foreign exchange, card services, and digital-asset settlement, with a strong focus on reliability, security, and operational excellence.

Highlights

Central SRE role supporting high-scale financial infrastructure across multiple cloud regions, with exposure to regulated systems, payments, foreign exchange, and digital-asset settlement.

Description

About Reap Reap is a global financial technology company headquartered in Hong Kong with employees across multiple countries. We enable financial connectivity and access for businesses worldwide by combining traditional finance with stablecoins for efficient money movement. Through our stablecoin-powered corporate cards, payments, and expense management tools, we streamline financial operations and help businesses scale. Our APIs enable businesses to integrate stablecoin-enabled finance into their own products and services β€” from issuing Visa cards to facilitating cross-border payments. Backed by leading investors including Index Ventures and HashKey Capital, Reap is building the future of borderless, stablecoin-enabled finance. About The Role Reap is building a Site Reliability Engineering practice, and this role is central to it. We run card issuing, payouts, FX and stablecoin settlement across multiple AWS regions, under PCI DSS and financial regulation. The platform is growing quickly β€” into new markets, new products, and now agent-initiated payments β€” and the infrastructure underneath it needs to grow up with it. That means real service ownership, reliability measured in SLIs and SLOs rather than intuition, and a platform that engineering teams can serve themselves from instead of queueing for. That work is largely still ahead of us, which is the appeal. You will help decide what reliability means at Reap, what the platform looks like, and what good engineering practice is in this domain β€” rather than inheriting someone else's answers. This is a deeply hands-on senior individual contributor role. We expect you to lead by example and drive technical excellence through the systems you build, the standards you set, and the way you help the engineers around you level up. The team is deliberately flat and distributed across time zones. Technologies You'll Use Cloud: AWS, multi-account across multiple regions β€” Transit Gateway, PrivateLink, site-to-site VPN, WAF, KMSCompute: ECS/Fargate, Lambda and EKSInfrastructure as Code: Terraform and CloudFormationCI/CD: GitHub Actions, Argo CDDatabases: Aurora PostgreSQL, ElastiCache/RedisMessaging and streaming: SQS, EventBridge, KafkaObservability: New Relic, CloudWatchLanguages and scripting: Python, Go and Bash What You'll Do As a Senior Site Reliability Engineer at Reap, you will join a team of experienced engineers transitioning a DevOps organisation into Site Reliability Engineering. You will own the reliability of a payments platform while rebuilding the foundation it runs on β€” the lights stay on while the platform gets replaced underneath them. We treat repetitive manual work as a bug in the platform, not a chore for a human, and your job is to delete whole categories of it rather than absorb them faster. Define what reliability means here: set SLIs and SLOs with product and engineering teams, introduce error budgets, and make "ship or stabilise?" a matter of arithmetic rather than argumentTake part in our on-call rotation, and help build the incident response and blameless postmortem practice around itDrive Reap to full Infrastructure as Code coverage: bring the remaining legacy infrastructure under IaC, and get to no manual provisioning, no drift, and every resource defined, versioned and reproducibleConsolidate our Terraform estate into a coherent, well-structured codebase with module standards, governance and automated drift detectionAutomate account provisioning and environment setup so that new regions and services can be stood up repeatably and consistentlyBuild the golden paths and self-service interfaces that let product and engineering teams provision, deploy and observe without filing a ticket, with escape hatches for the cases they do not coverDesign and implement an ephemeral environment platform so any developer, and any coding agent, can get an isolated production-like environment on demand and have it cleaned up automaticallyImplement industry-standard observability across logging, metrics and distributed tracing, with alerting that is actionable and trustedOwn cloud operations for PCI DSS and regulated financial systems β€” uptime, failover, capacity, disaster recovery and incident responseEmbed security into the infrastructure layer: secrets management, least-privilege IAM, network segmentation and compliance controlsBuild infrastructure that lets AI assistants and agents operate safely: sane blast radius, strong isolation, auditable actionsPartner with product and engineering teams so that reliability work is negotiated rather than imposed β€” we treat the platform as a product and our engineering teams as its customers Skills We're Looking For Real SRE practice, not just the vocabulary: you have defined SLOs, run error budgets, or built an incident and postmortem process that people actually usedStrong Linux and computer-systems fundamentals: internals, networking, and administration. This work rests on themDeep Terraform: state management, module design, and enforcing standards across a team. You have owned a full IaC migration or a greenfield buildout at scaleStrong AWS across multi-account, multi-region estates: Control Tower, IAM, networking, RDS, and cost managementContainers and orchestration: comfortable operating ECS and Fargate, and able to build and run production Kubernetes at scale β€” cluster lifecycle and upgrades, autoscaling, resource limits and multi-tenant workload isolationServerless and event-driven systems: Lambda, SQS and EventBridge in production, including the failure modes that only show up at scale β€” retries, poison messages, ordering and idempotencyGitOps and delivery: Argo CD or equivalent, and CI/CD pipelines with GitHub Actions that engineers actually enjoy usingObservability in practice: logging, metrics and tracing with tools such as New Relic, CloudWatch, Datadog or Prometheus β€” and getting standards adopted, not just publishedPython, Go or Bash for automation and toolingFull-lifecycle ownership: you own a service across its whole life β€” from understanding the need, through design and delivery, to observability, incident response, capacity, upgrades and security patchingExperience operating in a regulated environment, and comfort with the constraints that come with PCI DSS and financial complianceSelf-management and cross-team influence: you can run your own projects and build alignment without authority. Nobody will sequence your work for youCommunication as a first-class skill, weighted equally with technical depth. You can take a problem, explain your approach in plain language, and decompose it into work β€” for a person or for an agentAI-assisted engineering: you already use AI tools seriously for code, review, automation, incident analysis and documentation, and you have opinions about where they work and where they do notGenuine comfort with production incidents. In payments, high blast-radius incidents preempt everything Bonus Skills Significant experience in SRE, DevOps or infrastructure engineering, including time in an organisation with a mature SRE practice β€” defined SLOs, self-service deploys, and real on-callExperience in fintech, payments, card issuing or another regulated environmentHands-on PCI DSS work: designing cardholder-data environments, or reducing scopeKubernetes or EKS inside a PCI DSS environment: isolating the cardholder-data environment through namespace and network-policy segmentation, dedicated node groups, admission control and pod security standards β€” and the audit logging that makes it provableHaving designed and operated ephemeral or on-demand environment platforms, including the hard parts β€” database seeding, service dependencies and secrets in short-lived environmentsHaving built an internal developer platform, account factory or landing zone from scratchConfiguration management with Ansible or similarAWS certificationsCuriosity about stablecoins and the Web2 / Web3 intersection After submitting your application, please check your inbox for a confirmation email. If you don't see it, kindly check your spam or junk folder and adjust your settings to ensure future communication reaches your inbox. You can follow the steps here.