Platform Engineer

Finastra
Hybrid

About The Position

You will build and run the platform that engineering teams deploy onto — a multi-tenant, cloud-native SaaS environment supporting the modernisation of a large-scale financial system from on-premises to Kubernetes-based microservices. This is a senior software engineering role first, and a DevOps/platform role second: you write production-grade code for the tooling and automation you own, not just scripts and YAML, and you understand the Spring Boot services running on top of the platform well enough to debug deployment issues at the application layer, not just the infrastructure layer.

Requirements

  • 7+ years professional software engineering experience
  • Strong general-purpose programming (Java and/or Go or Python), not solely scripting
  • Comfortable extending or contributing to shared Spring Boot libraries and starter packs consumed by other engineering teams
  • Understands software design fundamentals — API design, concurrency, error handling, backward compatibility — well enough to be a credible reviewer on both infra and application pull requests
  • Deep GitHub Actions expertise — authoring reusable/composite workflows, matrix builds, self-hosted runners, caching strategies, and secure secret handling in CI
  • Expertise in repository governance at scale — branch protection rules, required status checks, CODEOWNERS, merge queue strategy across many repos or a monorepo
  • Expertise in GitHub Advanced Security — secret scanning and push protection, code scanning (CodeQL), Dependabot policy and triage
  • Experience with GitHub Apps and fine-grained access tokens for internal automation — building bots/integrations against the GitHub API rather than relying on personal access tokens
  • Experience with GitHub Environments — deployment protection rules, required reviewers, and environment-scoped secrets as a promotion gate into staging/production
  • Experience with organisation and team permission design — least-privilege access across engineering teams, audit logging, SSO/SAML integration
  • Production experience with GitOps tooling — ArgoCD or Flux — managing declarative, Git-driven deployments across multiple environments and clusters
  • Infrastructure as Code — Terraform for cloud provisioning
  • Experience with Helm charts / Kustomize for Kubernetes manifests
  • Experience with progressive delivery — canary and blue-green rollout mechanics, automated rollback triggers tied to health signals
  • Experience with secrets management integrated into pipelines — Vault, Sealed Secrets, or cloud-native secret stores
  • Kubernetes at depth — deployments, StatefulSets, ConfigMaps, Secrets, resource quotas, autoscaling (HPA/VPA), network policies
  • Experience with multi-tenant cluster design — namespace isolation, per-tenant resource boundaries, workload scheduling
  • Cloud platform experience (AWS, Azure, or GCP) — networking, IAM, managed Kubernetes (EKS/AKS/GKE), managed databases
  • Experience with container image strategy — multi-stage Docker builds, base image hardening, registry and vulnerability scanning
  • Builds and maintains observability stack — structured logging, distributed tracing, metrics (Prometheus/Grafana or equivalent)
  • Defines SLIs/SLOs and alerting thresholds in partnership with engineering teams
  • Experience with incident response — on-call practices, runbooks, postmortems that lead to platform-level fixes, not just fire-fighting

Nice To Haves

  • Experience migrating workloads from on-premises / JBoss-style deployments into Kubernetes
  • Kafka or RabbitMQ operations — cluster management, topic/queue scaling, consumer lag monitoring
  • Policy-as-code experience — OPA/Gatekeeper, admission controllers, compliance-as-code for regulated environments
  • Exposure to the financial services domain — awareness of the audit, resiliency, and change-control expectations that come with banking customers

Responsibilities

  • Writes and reviews production-grade code for internal platform tooling — CLIs, operators, controllers, automation services — with the same rigour as application code: tests, code review, versioning
  • Extends or contributes to shared Spring Boot libraries and starter packs consumed by other engineering teams
  • Debugs across the full stack — from a Kubernetes scheduling failure down to a Spring Boot stack trace or a Hibernate query plan
  • Authors reusable/composite GitHub Actions workflows, matrix builds, self-hosted runners, caching strategies, and secure secret handling in CI
  • Manages repository governance at scale — branch protection rules, required status checks, CODEOWNERS, merge queue strategy across many repos or a monorepo
  • Manages GitHub Advanced Security — secret scanning and push protection, code scanning (CodeQL), Dependabot policy and triage
  • Builds bots/integrations against the GitHub API using GitHub Apps and fine-grained access tokens for internal automation
  • Configures GitHub Environments — deployment protection rules, required reviewers, and environment-scoped secrets as a promotion gate into staging/production
  • Designs organisation and team permission — least-privilege access across engineering teams, audit logging, SSO/SAML integration
  • Manages declarative, Git-driven deployments across multiple environments and clusters using GitOps tooling (ArgoCD or Flux)
  • Provisions cloud infrastructure using Terraform
  • Manages Kubernetes manifests using Helm charts / Kustomize
  • Implements progressive delivery — canary and blue-green rollout mechanics, automated rollback triggers tied to health signals
  • Integrates secrets management into pipelines (Vault, Sealed Secrets, or cloud-native secret stores)
  • Manages Kubernetes at depth — deployments, StatefulSets, ConfigMaps, Secrets, resource quotas, autoscaling (HPA/VPA), network policies
  • Designs multi-tenant clusters — namespace isolation, per-tenant resource boundaries, workload scheduling
  • Manages cloud platform resources (AWS, Azure, or GCP) — networking, IAM, managed Kubernetes (EKS/AKS/GKE), managed databases
  • Implements container image strategy — multi-stage Docker builds, base image hardening, registry and vulnerability scanning
  • Builds and maintains observability stack — structured logging, distributed tracing, metrics (Prometheus/Grafana or equivalent)
  • Defines SLIs/SLOs and alerting thresholds in partnership with engineering teams
  • Participates in incident response — on-call practices, runbooks, postmortems that lead to platform-level fixes
  • Treats the platform as a product — self-service, documented, and reliable enough that application teams rarely need to escalate
  • Writes platform tooling as real software — tested, versioned, code-reviewed
  • Designs deployment and rollback paths that reduce customer-facing risk by default
  • Partners with engineering teams during design, flagging operability, security, and scaling concerns before code is written
  • Mentors other engineers on CI/CD and platform practices
  • Acts as a credible voice in architecture discussions beyond just infrastructure

Benefits

  • Unlimited vacation, subject to local regulations and business priorities
  • Hybrid working arrangements
  • Paid time off for voting, bereavement, and sick leave
  • Confidential one‑to‑one support through our Employee Assistance Program
  • Network of Wellbeing Champions and Gather Groups
  • Monthly events and initiatives designed to help you thrive
  • Medical, life and disability insurance
  • Retirement plans
  • Lifestyle, and other benefits
  • Paid time off for volunteering
  • Donation‑matching opportunities
  • Inclusion communities, such as Count Me In, Culture@Finastra, Proud@Finastra, Disabilities@Finastra, and Women@Finastra
  • Online learning and accredited courses through our Skills & Career Navigator tool
  • Global recognition program, Finastra Celebrates
  • Employee surveys that help shape our culture and ways of working
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service