Senior DevSecOps Engineer
zocks
Budapest
Posted Apr 8, 2026
- Full-time
Job description
**Company Overview:** Zocks is an AI platform transforming how financial advisors work. Starting in the US financial services market, we're building technology that supports advisors across their entire workflow - from sales and meeting preparation to note-taking, follow-ups, scheduling, email, document intelligence, reporting, and integrations with the systems they use every day. Our goal is to take repetitive, manual work out of the advisor-client relationship and turn conversations, documents, and data into actions automatically. As our platform expands across more workflows, customers, and use cases, we're solving increasingly complex challenges around AI, real-time systems, data, security, integrations, and scale. Zocks is headquartered in San Francisco, while our **entire R&D organization - Engineering, Product, Design, Data, and Infrastructure - is based in Budapest**. This means **our Budapest teams don't just execute on a product built elsewhere: they're directly responsible for shaping the product, technology, and how we build them as we grow**. **Location: Budapest, XI., Science Park (On-site Monday to Thursday, Remote on Fridays)** **Why we're hiring for this role:** We're rapidly expanding, and with that comes an increasing urgency to mature our security posture. Compliance readiness, and proactive risk management are becoming equally critical — this role will be a key driver of those efforts alongside infrastructure ownership. This could be a unique opportunity to have a big impact in owning security initiatives and establishing a strong security baseline at Zocks. ### Key challenges you will work on every day: - Owning the full cloud infrastructure lifecycle across multi-region environments - Owning and hardening the security perimeter across cloud and network boundaries - Triaging and remediating findings from penetration tests and vulnerability scans in collaboration with external security partners - Creating and maintaining our delivery pipeline from developer machines to production, including automated security checkpoints, secrets scanning, and dependency auditing. - Supporting compliance initiatives (e.g. SOC 2, ISO 27001, NIST) through infrastructure controls, audit logging, and evidence collection - Optimizing network topology for the best possible connectivity, latency and throughput for end users ### What you need: - 6+ years relevant experience (DevOps/Security) - Deep understanding of AWS security services (IAM, Security Hub, GuardDuty, SCPs, network ACLs) - Strong knowledge of cloud security best practices - Experience with network security (VPNs, firewalls, zero-trust architecture, ingress/egress protection) - Linux hardening experience - Experience with secrets management (Vault, AWS Secrets Manager) - Knowledge of PKI / certificate lifecycle management - Experience with compliance and audit requirements (SOC2, ISO27001, CIS Benchmarks) - Ability to understand penetration testing findings and coordinate remediation efforts - Experience with security incident response and risk prioritization - Fluent English and Hungarian language knowledge ### Bonus points for: - Kubernetes security experience - Familiarity with runtime security tooling (Falco, Wiz, Crowdstrike) - Experience reviewing Terraform / IaC security configurations - Exposure to Azure or GCP security - Python or Go scripting skills - Experience with container security scanning tools - Threat modeling experience - Security automation experience