DevSecOps / Platform Engineer

GönderAL Payment Services

Kâğıthane

Description

About Us

GönderAL is a financial technology company focused on building secure and scalable digital payment platforms. We design systems that support real-time transactions, robust infrastructure, and user-friendly interfaces tailored for modern financial operations. We operate in a dynamic, collaborative environment focused on secure, reliable, and customer-centered financial services.

We are looking for a hands-on DevSecOps Engineer to help us build, secure, and operate the infrastructure behind our payment services. You will work directly with our production systems and collaborate closely with software engineering, security, and infrastructure teams. The role covers the full operational lifecycle—from CI/CD and infrastructure automation to observability, incident response, and disaster recovery.

Responsibilities

  • Operate and continuously improve our bare-metal Kubernetes platform (Rancher), service mesh (Istio), certificate and secrets management infrastructure.
  • Design, build, and maintain GitLab CI/CD pipelines and GitLab Runner infrastructure to automate build, test, and deployment workflows.
  • Deploy, configure, and maintain highly available services including PostgreSQL, Redis, Kafka, RabbitMQ, Elasticsearch, and S3-compatible object storage.
  • Implement and improve Infrastructure as Code using Ansible roles, playbooks, and Helm charts for infrastructure provisioning and configuration.
  • Implement and maintain DevSecOps practices — security scanning, compliance checks, container-image scanning, and secrets management — across CI/CD workflows.
  • Track CVEs and work with the relevant teams to prioritize and remediate vulnerabilities.
  • Monitor, troubleshoot, and optimize system performance, logs, and alerts across our observability stack (Prometheus, Grafana, Alertmanager, APM, Fluent Bit, Logstash, ELK).
  • Manage secrets, certificates, and service-to-service security using a secrets management solution, cert-manager, and TLS/mTLS.
  • Maintain backup and disaster-recovery capabilities, failover/failback procedures for stateful services.
  • Support production deployments, aiming for minimal downtime and reliable recovery when failures occur.
  • Investigate production issues, perform root-cause analysis, and implement lasting technical improvements.
  • Participate in incident response, disaster-recovery exercises, and operational readiness reviews.
  • Work closely with software engineers to improve deployment processes, system performance, security, and reliability.
  • Maintain accurate technical documentation, runbooks, architecture records, and operational procedures.
  • Help prepare technical evidence and address findings for regulatory and external IT audits.
  • Support infrastructure and security controls required in a regulated electronic money and payments environment.

Technical Requirements

  • 5+ years of experience as a DevSecOps, Platform, or SRE Engineer, or in a related infrastructure role.
  • A degree in Computer Science, Engineering, or a related field, or equivalent professional experience.
  • Strong hands-on production experience with Kubernetes; bare-metal or Rancher experience preferred.
  • Practical experience with Ansible, Helm, and other Infrastructure as Code tools.
  • Solid experience building and maintaining CI/CD pipelines with GitLab CI/CD and GitLab Runners.
  • Experience operating databases, messaging platforms, or other distributed systems in high-availability or replication architectures.
  • Solid understanding of Linux systems, networking fundamentals, TLS/mTLS, PKI, and certificate management.
  • Experience with monitoring stacks such as Prometheus, Grafana, APM, and centralized logging/alerting (ELK, Loki, or similar).
  • Experience with vulnerability management, security testing within the SDLC, container security, and remediation.
  • Hands-on experience with a secrets management solution (e.g., HashiCorp Vault, AWS Secrets Manager, or similar).
  • Experience working with a service mesh (e.g., Istio, Linkerd, or similar).
  • Understanding of backup, disaster recovery, incident management, and production support processes.
  • Familiarity with Git, branching strategies, and SDLC processes.
  • Strong scripting ability in at least one language such as Python, Bash, or Powershell.
  • Strong troubleshooting and problem-solving skills, with a careful and detail-oriented approach.
  • Clear communication skills and the ability to work effectively across engineering teams.
  • Professional working proficiency in English.

Nice to Have

  • Experience in fintech, payments, banking, or another regulated environment is a strong plus.
  • Direct hands-on experience specifically with HashiCorp Vault, Istio, and cert-manager.
  • Experience with PostgreSQL HA technologies such as Patroni, Keepalived, and HAProxy.
  • Familiarity with PCI DSS or similar security standards.
  • Mobile CI/CD experience — including Android and iOS pipelines, code signing, certificate management, and store releases.
  • Understanding of ML/AI pipelines, model deployment (MLOps), or integrating AI-based tools into DevOps workflows is a plus.
  • Experience working with AI-driven monitoring, anomaly detection, or automation tools is considered an advantage.
  • Relevant technical or security certifications.