We are seeking a highly skilled DevOps Network Administrator with hands-on expertise in AWS Cloud Networking, Infrastructure as Code (Terraform), AWS RDS (Microsoft SQL Server), and Cybersecurity best practices. This role will design, automate, secure, and maintain AWS cloud infrastructure supporting mission-critical applications and databases. The ideal candidate combines deep knowledge of cloud networking and automation with strong cybersecurity awareness to ensure confidentiality, integrity, and availability across all systems. We are considering candidates currently based in Madrid or open to relocation to Madrid.
Details
Location: Madrid (preferred) or relocation to Madrid
Employment Type: Full-time
Start Date: ASAP
Language Requirements: English B2
The client is from Spain. Long-term project.
Project Description: A European fintech headquartered in Belgium, holding regulated licenses issued by the Belgian Central Bank. Initially operating as a walk-in remittance business, they evolved into a remittance + banking enablement platform.
Current Model
- Core business: international remittances
- Secondary model: providing platform + licensing to other financial institutions/banks to operate in the EU
- Future vision: expand into banking services — prepaid cards, wallets, accounts, full banking functionality
- Regulatory posture: regulated in Belgium; able to upgrade licenses to broaden services (e-money, custody, lending, etc.)
Requirements / Your Background
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience)
- 4–6+ years of experience in AWS cloud administration, networking, and security
- 2+ years of hands-on experience with Terraform for AWS automation
- Proven experience with AWS RDS (Microsoft SQL Server) — setup, maintenance, tuning
- Strong understanding of network security, IAM, and data protection in AWS
- Hands-on knowledge of TCP/IP, DNS, VPN, TLS/SSL, firewalls
- Experience integrating security tools into CI/CD pipelines
- Proficiency with Linux administration and scripting (Bash, Python, or PowerShell)
Key Responsibilities
1. Cloud Infrastructure & Automation
- Design, provision, and manage AWS infrastructure using Terraform
- Develop reusable Terraform modules (networking, RDS, compute)
- Manage Terraform state files, remote backends (S3 + DynamoDB), and CI/CD integrations
- Optimize for scalability, availability, and cost efficiency
2. AWS Networking
- Design and administer VPCs, subnets, routing, NAT, Transit Gateways
- Implement VPNs, PrivateLink, and hybrid cloud connectivity
- Configure Route 53, ELB, and Security Groups for secure segmentation
- Monitor network performance with CloudWatch, VPC Flow Logs, AWS Config
3. Database Infrastructure (RDS / MSSQL)
- Deploy and maintain AWS RDS for MS SQL Server using Terraform
- Manage patching, backups, parameter groups, multi-AZ setups
- Ensure encryption, IAM authentication, and replication
- Collaborate with DB teams for performance tuning
4. Cybersecurity & Compliance
- Apply security-by-design across AWS and Terraform
- Manage IAM policies and least-privilege access
- Configure AWS WAF, GuardDuty, Security Hub, Inspector
- Maintain encryption for data in transit and at rest
- Integrate security scanning into CI/CD (compliance, vulnerability scanning)
- Monitor and respond to security alerts and incidents
- Support ISO 27001, SOC 2, HIPAA, NIST initiatives
- Maintain audit trails and secure configuration baselines via Config & CloudTrail
5. Monitoring & Operations
- Implement centralized logging (CloudWatch, OpenSearch, SIEM)
- Automate health checks, backups, and patch processes
- Prepare documentation, diagrams, and runbooks
- Participate in a 24/7 incident response rotation and change management
Nice to Have
- AWS Certified Solutions Architect (Associate/Professional) or AWS Security Specialty
- Terraform Associate Certification
- Familiarity with SIEM tools (Splunk, ELK, AWS Security Hub)
- Experience with Kubernetes/EKS, Docker, or container security
- Knowledge of Zero Trust architecture and identity federation (SSO, SAML, OIDC)
- Understanding of DevSecOps and cloud compliance frameworks