Wavelength Financial Technology Ltd is accepting applications for the position of
Software Developer II - DevSecOps
JOB SUMMARY
Responsibilities for this position include a full range of activities including but not limited to designing, implementing, and maintaining secure software delivery platforms and automated CI/CD pipelines that support the rapid and reliable deployment of business-critical applications. This role partners with software engineering, cybersecurity, cloud infrastructure, and compliance teams to embed security controls, governance requirements, and operational best practices throughout the software development lifecycle.
Responsibilities also include implementing automated security testing and compliance validation, managing code quality and vulnerability scanning solutions, securing cloud-native and infrastructure-as-code deployments, monitoring application and platform security posture, and supporting secure release management processes. The role assists developers and testers in diagnosing application and deployment issues, identify and remediate vulnerabilities, support security incident investigations, and drive continuous improvements in automation, resilience, and security across development and operational environments.
ESSENTIAL FUNCTIONS
Specific Role Responsibilities
- Understands business and security requirements and assists with the design and implementation of technical solutions that meet functional, operational, and regulatory objectives.
- Works closely with software engineering, cybersecurity, cloud infrastructure, and architecture teams to design and implement secure, scalable, and resilient application platforms.
- Designs, implements, and maintains secure CI/CD pipelines, ensuring appropriate automation of build, testing, security scanning, and deployment activities.
- Integrates and manages DevSecOps tooling, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets detection, and infrastructure-as-code security validation.
- Works with development, security, and IT operations teams to troubleshoot and resolve application, infrastructure, and security issues across cloud and on-premises environments.
- Identifies, analyses, and remediates vulnerabilities within application code, third-party dependencies, cloud infrastructure, containers, and supporting platforms.
- Establishes and maintains secure deployment standards, configuration baselines, and infrastructure-as-code practices to ensure consistency and compliance across environments.
- Collaborates with development and QA teams to incorporate security testing and validation into the software development lifecycle.
- Assists with monitoring application and infrastructure security posture, investigating security alerts, and supporting incident response and remediation activities.
- Ensures development and deployment practices comply with organizational policies, security standards, and applicable regulatory requirements.
- Identifies and resolves common deployment, configuration, and environment management issues while driving continuous improvement of deployment reliability and security controls.
- Contributes to disaster recovery, business continuity, and operational resilience initiatives related to application platforms and cloud services.
- Produces and maintains technical documentation, operational runbooks, security procedures, and platform standards.
- Mentors developers and technology teams on secure coding practices, DevSecOps principles, and cloud security best practices
At a minimum the position requires the following:
Qualifications:
A university graduate with Bachelor or Master degree in Computer Engineering or Computer Science or equivalent qualification
Experience:
2+ years of experience working in a similar role in the financial services industry. Experience must be related to business and include working on an international diversified team
TECHNICAL REQUIREMENTS
- Strong knowledge of software development, application architecture, and secure software engineering principles.
- Technical proficiency in the Microsoft .NET ecosystem, including C#, ASP.NET, IIS, and SQL Server.
- Experience maintaining and supporting enterprise applications across the Microsoft technology stack, including C#, SQL Server, IIS, ASP.NET MVC, APIs, and related technologies.
- Experience designing, implementing, and maintaining secure CI/CD pipelines using Azure DevOps and Git-based workflows.
- Experience implementing DevSecOps practices and integrating security controls throughout the software development lifecycle (SDLC).
- Hands-on experience with source control platforms and branching strategies, including Git and Azure Repos.
- Experience with automated build, deployment, and release management processes.
- Experience implementing and managing security scanning technologies, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secrets detection, and container security scanning.
- Proficiency with PowerShell and other scripting languages used for automation, deployment, and operational activities.
- Experience implementing Infrastructure as Code (IaC) using Bicep, Terraform, ARM Templates, or similar technologies.
- Strong understanding of Microsoft Azure cloud architecture, services, governance, and security best practices.
- Experience securing cloud solutions using Azure Key Vault, Managed Identities, Role-Based Access Control (RBAC), Private Endpoints, and network security controls.
- Knowledge of containerization technologies including Docker, Kubernetes, Helm, and container security best practices.
- Knowledge of authentication and authorization technologies, including Microsoft Entra ID, OAuth, OpenID Connect, SAML, and Multi-Factor Authentication (MFA).
- Strong understanding of data security principles, including encryption, key management, secrets management, data classification, data protection, and handling of Personally Identifiable Information (PII).
- Knowledge of common networking protocols and technologies, including TCP/IP, HTTP(S), DNS, TLS, VPNs, firewalls, load balancers, network segmentation, and zero-trust security concepts.
- Knowledge of Linux and Windows operating systems, including system administration, performance monitoring, security hardening, and troubleshooting.
- Experience managing virtualized and cloud-hosted infrastructure environments.
- Understanding of vulnerability management, threat detection, security monitoring, and remediation processes.
- Familiarity with security frameworks and compliance requirements applicable to financial services organizations, including SOC 1, SOC 2, ISO 27001, NIST CSF, CIS Controls, or equivalent standards.
- Strong knowledge of secure coding practices, application security principles, and common vulnerabilities such as those identified in the OWASP Top 10.
- Experience working within Agile and DevOps delivery methodologies.
- Understanding of disaster recovery, high availability, and business continuity concepts.
- Excellent troubleshooting, analytical, and problem-solving skills.
- Outstanding knowledge of cybersecurity principles, security architecture, and secure systems design (specific certifications in this area is a major asset).
- Experience with the CSLA .NET framework is considered an asset.
Knowledge:
An understanding of alternative investment products and the offshore financial services industry, including system technology, portfolio valuation, accounting, share transfer and registration, prime brokerage, financing, and custody, and the ability to apply the knowledge to support role functions would be beneficial
KNOWLEDGE, SKILLS & ABILITIES REQUIRED
- Excellent analytical, time management, planning, organizational and prioritization skills
- Self-driven attitude and a strong work ethic
- Excellent attention to detail
- Highly adaptable and ability to learn quickly
- Autonomous and dynamic
- Strong communication skills, both verbal and written
SALARY and BENEFITS
- Salary USD$ 85,000 to $ 100,000 per annum
- Vacation – 25 days
- Standard Sick & Compassionate per law
- Pension – standard per law of 5% up to cap
- Health – 100% of employee only cost on a premier plan
- Annual discretionary bonus
- Relevant professional qualifications subscriptions covered up to US$1,500 per annum.
- Working hours, Job type, and location
o Hours: 8:30am – 5:30pm Monday to Friday
o Job Type: Full-Time permanent position
o Location: Full time in office – Cayman Corporate Centre
This vacancy is listed on WORC, the Cayman Islands government job portal. Applications go through the official channel.
Open on the WORC portal →Schooner watches every job posted in Cayman, not just WORC — recruiters, employer career pages, classifieds. It scores each one against your background and drafts the application, in a chat thread. Free for seekers, private pilot for now.
Join Schooner's waitlistSchooner is in a private pilot. Leave your email or WhatsApp number and we'll invite you as we open more places.
This joins Schooner's pilot, not the application for the Software Engineer II – DevSec Ops role — that still goes through WORC.
That doesn't look like an email or a phone number — mind checking it?
We'll only use this to invite you to Schooner. Privacy
We'll be in touch as we open more places. One profile, every island — starting with yours.