Description
About Us
At Xelix, we work with some of the world’s largest companies to automate and strengthen their financial controls.
Our AI solutions redefine how Accounts Payable teams operate – moving from manual processes to automated, intelligent workflows.
Xelix is a fast-paced scale-up – things move fast and expectations are high.
We raised our Series B with Insight Partners in June 2025 and are expanding aggressively.
We have a team of over 150 talented people pulling together to achieve our goals.
Everyone is trusted to take ownership, move fast and have a meaningful impact.
We prioritise personal and professional growth, keep things fun, and love to celebrate a milestone together.
In this role you’ll grow, be challenged and help shape the future of Xelix.
If you’re excited about building something special with us, we’d love to hear from you.
About The Role
We are looking for a mid-level DevOps Engineer to help operate and evolve our AWS-based infrastructure.
You’ll work at the intersection of infrastructure automation, application delivery, database operations, and security — using Terraform and GitOps workflows to manage cloud resources, GitHub Actions to power CI/CD, and Python to build the tooling that ties it all together.
This role also plays a key part in our DevSecOps maturity, contributing to a cloud security improvement program and a software supply chain security initiative.
What You'll Be Doing
Design, provision, and maintain AWS infrastructure using Terraform, following GitOps principles (infrastructure changes proposed, reviewed, and merged via pull request, then applied through automated pipelines).Own and evolve our GitHub Actions CI/CD pipelines, including build, test, security scanning, and deployment workflows across multiple environments.Manage relational database infrastructure on RDS and Aurora, including provisioning, performance tuning, backup/restore strategy, patching, and failover testing.Write Python-based tooling, automation scripts, and internal services to reduce manual toil and support platform operations.Participate in on-call rotation, incident response, and post-incident reviews, driving toward blameless root-cause analysis and durable fixes.Implement and maintain observability across infrastructure and applications (metrics, logs, traces, dashboards, and alerting).Apply DevSecOps practices by embedding security checks into the development lifecycle (SAST/DAST, dependency scanning, container/image scanning, IaC scanning) rather than treating security as a separate gate.Contribute to a cloud security improvement program: hardening IAM policies, reviewing network architecture and security groups, addressing findings from tools like AWS Security Hub/GuardDuty, and tracking remediation to closure.Support a software supply chain security effort, including SBOM generation, dependency and artifact provenance, signing/verification of build artifacts, and vetting of third-party actions/images used in pipelines.Help engineering teams to define infrastructure and deployment standards, and act as a resource for developers adopting IaC and CI/CD best practices.Maintain clear documentation of infrastructure, runbooks, and security procedures.
What You’ll Bring
3–5 years of experience in a DevOps, Site Reliability Engineering, or Cloud Infrastructure role.Strong hands-on experience with the AWS stack (e.g., EC2, VPC, IAM, S3, Lambda, ECS/EKS, CloudWatch, Route 53).Proven experience managing infrastructure as code with Terraform in a team/GitOps workflow (PR-based review, remote state, modules, workspaces).Practical experience with GitOps tooling and patterns (e.g., Argo CD, Flux, or equivalent PR-driven deployment models).Proficiency in Python for automation, tooling, and scripting; Django experience is a plus.Experience building and maintaining CI/CD pipelines in GitHub Actions (reusable workflows, custom actions, secrets management, environment gating).Working knowledge of containerization and orchestration (Docker; ECS, EKS, or Kubernetes).Familiarity with DevSecOps practices — shifting security left, integrating scanning tools into pipelines, and treating security findings as actionable engineering work.Solid understanding of networking fundamentals (DNS, TLS, load balancing, VPC peering/routing).Strong troubleshooting skills and comfort operating in a Linux environment.
Preferred / Nice To Have
Experience with supply chain security practices and tooling.Experience with cloud security posture management and tools such as AWS Security Hub, GuardDuty, Config, or third-party equivalents (Wiz, Prisma Cloud, etc.).Familiarity with secrets management solutions (AWS Secrets Manager, HashiCorp Vault, SOPS)Understanding of compliance frameworks relevant to cloud environments and experience with policy-as-code frameworks for automated compliance and guardrails.Exposure to observability platforms such as Datadog, Prometheus/Grafana, or the OpenTelemetry ecosystem.Experience with container image hardening and scanning (Trivy, Grype, or similar).Experience with using AI tooling as well as a familiarity with security concerns around same.Contributions to internal developer platforms or self-service infrastructure tooling.Direct experience with scaling and supporting a production platform through a growth phase.Relevant certifications (AWS Certified DevOps Engineer, AWS Certified Security – Specialty, HashiCorp Terraform Associate) are a plus but not required.
Soft Skills & Working Style
Comfortable balancing competing priorities across platform reliability, feature delivery, and security remediation.Strong written communication for documentation, incident write-ups, and cross-team collaboration.A pragmatic, risk-aware approach to security — able to prioritise fixes by actual impact rather than treating every finding as equally urgent.Collaborative mindset; willing to pair with developers to make secure, automated paths the easiest paths.Curious and current on evolving DevOps and cloud-security practices, with a bias toward automation over manual process.
What Success Looks Like
Infrastructure changes flow through a reliable, auditable GitOps process with minimal manual intervention.CI/CD pipelines are fast, secure, and trusted by engineering teams.Database resources are reliable, well-monitored, and recoverable, with tested backup/restore procedures.Measurable progress against the cloud security improvement program’s roadmap (e.g., reduced high/critical findings, tightened IAM posture).A maturing software supply chain security posture, with SBOMs, provenance, and artifact integrity checks integrated into standard delivery pipelines.
What We Offer In Return
💰 Competitive salary of £45,000 - £55,000 depending on experience
🏝️ 27 days of annual leave (including 3 days Christmas closing), with the option to roll over 3 days
🏡 Hybrid working with three days a week from our dog-friendly Hoxton office and on-site gym
🏥 Comprehensive private medical & dental cover with Vitality
🍼 Enhanced parental leave pay
📚 Learning & development culture – £1,000 personal annual budget
🌍 We’re carbon-neutral and are working towards ambitious carbon reduction goals
🎯 Lots of team socials & activities
☀️ Annual team retreat
Want to learn more?
About usXelix blogXelix newsXelix glassdoor
We believe that people from diverse backgrounds, with different identities and experiences make our company and product better.
No matter your background, we'd love to hear from you! And if you have a disability, please let us know if there's any way we can make the interview process better for you - we're happy to accommodate!
If you're a recruiting agency - we have an existing list of agencies we work with and we are not currently planning on expanding the list.
Neither the Talent team nor hiring managers or the Support team will respond to cold outreach.