FinRay Technologies

Senior IT Infrastructure and Security Engineer

$$$$
Product

Swiss fintech licensed by FINMA under Art. 1b of the Banking Act, building and operating a corporate accounts and payments platform from Zürich. Run a modern cloud-hosted core banking landscape (AWS Swiss region) connected to the Swiss interbank payment infrastructure, complemented by our own hardware footprint in Swiss datacenters.

 

The role

In this role you take operational management of our entire ICT landscape. The role requires strong technical and engineering skills and the ability to properly document the results of your work. The role reports directly to the CTO, sits in the first line of defence of our governance model and is formally anchored in our Information Security Policy and Operational Risk Policy. You keep the platform secure, patched, inventoried, backed up and documented - and provably so: producing audit-ready evidence is part of the job, not an afterthought. For information-security control matters you also report to the CCRO (second line).

What you will do

  • Software testing and acceptance: Review and accept the software developed by third-party providers, ensuring compliance with set technical, functional and security requirements. Testing and validation of the software (security, vulnerability, functional). Proper documenting of testing and acceptance results. 
  • ICT system and data security: Assessment that IT environments comply with the required security standards: validation and proper documentation as required by the Company’s policies. Endpoint security: issue, harden, encrypt and track corporate devices; keep endpoint protection current; manage device returns and secure data wipes. Ensure that security standards are implemented at the following levels: (1) critical data security on terminal devices; (2) security during transfer of critical data; (3) security on stored critical data (servers, databases and backups).
  • Cybersecurity: Assist in developing cybersecurity strategy. Development of threat landscape. Assistance in implementing cyber-related BCP tests. 
  • Identity and access management: operate the full joiner/mover/leaver lifecycle: create, modify and deactivate accounts on documented, approved requests only; enforce least privilege and need-to-know; administer MFA and the corporate password manager; run periodic access recertifications with system owners.
  • Network and remote access: administer network segmentation, IPSec appliances and direct-connect gateways; keep secure remote access reliable for a distributed team.
  • Systems and applications: patch systems and applications against known vulnerabilities; track vendor advisories; administer the cloud-hosted core banking application landscape across multiple availability zones; coordinate application-level fixes with our software maintenance partner; support periodic penetration tests and drive remediation.
  • Backups and disaster recovery: run and test backup cycles, verify integrity, perform restore and RTO tests; own the technical side of business continuity and the disaster recovery plan.
  • Monitoring, logging and incident response: maintain security logging and alerting, triage security events, act in the incident response team, and report incidents to the CTO and CCRO without delay.
  • ICT inventory and change management: keep the ICT inventory complete and current (systems, criticality, providers, hosting) and apply formal change management to every ICT change. Document the entire change management lifecycle according to the set procedure. 
  • Assistance in provider oversight: technically monitor our ICT service providers (cloud, software maintenance, connectivity, security hardware): service levels, security commitments, certificates and due-diligence refreshes, in support of the outsourcing framework.
  • Payment-infrastructure operations: support the CTO hands-on with our datacenter presence: racks, switches and connectivity, plus logistics for security and network hardware (transport, racking, cabling, vendor RMA). Cryptographic key ceremonies remain with the appointed Security Officers - this role covers the physical and logistical side.
  • User support and training: technical onboarding of new employees (accounts, devices, MFA) and organisational support of the annual information-security training.
  • Reporting: regular reporting on ICT operations, patching status, incidents and open risks to the CTO and, for information-security control matters, to the CCRO; contribute control evidence to our internal control system.

What we expect

  • Solid hands-on experience (typically 5+ years) administering infrastructure and security in production - ideally in a Swiss bank, fintech or another regulated, high-assurance environment.
  • Strong practical AWS administration (IAM, networking, monitoring, multi-AZ) and comfort with hybrid setups that reach into physical datacenters.
  • Strong documentation skills and the discipline to work to written policies and produce audit-ready evidence. 
  • Awareness of FINMA Circular 2023/1 "Operational risks and resilience – banks", Circular 2018/3 "Outsourcing - banks and insurers", FINMA Guidance 03/2024, FINMA Guidance 08/2024. 
  • Working knowledge across the security stack: identity and access, endpoint protection, patch and vulnerability management, logging and alerting, backup and restore.
  • A hands-on attitude: racking a server, cabling a switch or escorting hardware to a datacenter is part of the job.
  • Professional English required; German is a plus.
  • Nice to have: exposure to payment infrastructures (SIC/SWIFT), HSM operations, ISAE 3402 / ISO 27001 environments, infrastructure-as-code.

What we offer

  • A rare build-phase role: the infrastructure of a licensed Swiss fintech — small enough that your name is on everything, serious enough to face regulatory audit.
  • Direct daily work with the CTO and CEO - no layers.
  • Modern stack and real hardware: cloud, datacenters and Swiss payment-system connectivity in one role.
  • Central Zürich office (Bleicherweg 7) and competitive compensation aligned with experience.

Note

This posting is a public summary. The full job description - complete scope of responsibilities, authorities and reporting lines - is shared with shortlisted candidates under NDA.

Required languages

English C1 - Advanced
Published 20 August
6 views
·
0 applications
To apply for this and other jobs on Djinni login or signup.
Loading...