Job Summary:
The Software Engineer II – DevSecOps is responsible for designing, implementing, and maintaining secure software delivery platforms and automated CI/CD pipelines that support the rapid and reliable deployment of business-critical applications. This role partners with software engineering, cybersecurity, cloud infrastructure, and compliance teams to embed security controls, governance requirements, and operational best practices throughout the software development lifecycle.
Responsibilities also include implementing automated security testing and compliance validation, managing code quality and vulnerability scanning solutions, securing cloud-native and infrastructure-as-code deployments, monitoring application and platform security posture, and supporting secure release management processes. The role assists developers and testers in diagnosing application and deployment issues, identify and remediate vulnerabilities, support security incident investigations, and drive continuous improvements in automation, resilience, and security across development and operational environments.
Essential Functions
Specific Role Responsibilities
- Understands business and security requirements and assists with the design and implementation of technical solutions that meet functional, operational, and regulatory objectives.
- Works closely with software engineering, cybersecurity, cloud infrastructure, and architecture teams to design and implement secure, scalable, and resilient application platforms.
- Designs, implements, and maintains secure CI/CD pipelines, ensuring appropriate automation of build, testing, security scanning, and deployment activities.
- Integrates and manages DevSecOps tooling, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets detection, and infrastructure-as-code security validation.
- Works with development, security, and IT operations teams to troubleshoot and resolve application, infrastructure, and security issues across cloud and on-premises environments.
- Identifies, analyses, and remediates vulnerabilities within application code, third-party dependencies, cloud infrastructure, containers, and supporting platforms.
- Establishes and maintains secure deployment standards, configuration baselines, and infrastructure-as-code practices to ensure consistency and compliance across environments.
- Collaborates with development and QA teams to incorporate security testing and validation into the software development lifecycle.
- Assists with monitoring application and infrastructure security posture, investigating security alerts, and supporting incident response and remediation activities.
- Ensures development and deployment practices comply with organizational policies, security standards, and applicable regulatory requirements.
- Identifies and resolves common deployment, configuration, and environment management issues while driving continuous improvement of deployment reliability and security controls.
- Contributes to disaster recovery, business continuity, and operational resilience initiatives related to application platforms and cloud services.
- Produces and maintains technical documentation, operational runbooks, security procedures, and platform standards
- Mentors developers and technology teams on secure coding practices, DevSecOps principles, and cloud security best practices
Managerial Responsibilities
- Assist with training of Associate level personnel in all aspects of their role
Other Responsibilities
- Supports team members with their work
- Other job functions as required
Job Qualifications
- Qualifications: A college or university graduate with Bachelor or Master degree in Computer Engineering or Computer Science or equivalent qualification
- Experience: 2+ years of experience working in a similar role in the financial services industry. Experience must be related to business and include working on an international diversified team
- Knowledge: An understanding of alternative investment products and the offshore financial services industry, including system technology, portfolio valuation, accounting, share transfer and registration, prime brokerage, financing, and custody, and the ability to apply the knowledge to support role functions would be beneficial
TECHNICAL REQUIREMENTS
- Strong knowledge of software development, application architecture, and secure software engineering principles.
- Technical proficiency in the Microsoft .NET ecosystem, including C#, ASP.NET, IIS, and SQL Server.
- Experience maintaining and supporting enterprise applications across the Microsoft technology stack, including C#, SQL Server, IIS, ASP.NET MVC, APIs, and related technologies.
- Experience designing, implementing, and maintaining secure CI/CD pipelines using Azure DevOps and Git-based workflows.
- Experience implementing DevSecOps practices and integrating security controls throughout the software development lifecycle (SDLC).
- Hands-on experience with source control platforms and branching strategies, including Git and Azure Repos.
- Experience with automated build, deployment, and release management processes.
- Experience implementing and managing security scanning technologies, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secrets detection, and container security scanning.
- Proficiency with PowerShell and other scripting languages used for automation, deployment, and operational activities.
- Experience implementing Infrastructure as Code (IaC) using Bicep, Terraform, ARM Templates, or similar technologies.
- Strong understanding of Microsoft Azure cloud architecture, services, governance, and security best practices.
- Experience securing cloud solutions using Azure Key Vault, Managed Identities, Role-Based Access Control (RBAC), Private Endpoints, and network security controls.
- Knowledge of containerization technologies including Docker, Kubernetes, Helm, and container security best practices.
- Knowledge of authentication and authorization technologies, including Microsoft Entra ID, OAuth, OpenID Connect, SAML, and Multi-Factor Authentication (MFA).
- Strong understanding of data security principles, including encryption, key management, secrets management, data classification, data protection, and handling of Personally Identifiable Information (PII).
- Knowledge of common networking protocols and technologies, including TCP/IP, HTTP(S), DNS, TLS, VPNs, firewalls, load balancers, network segmentation, and zero-trust security concepts.
- Knowledge of Linux and Windows operating systems, including system administration, performance monitoring, security hardening, and troubleshooting.
- Experience managing virtualized and cloud-hosted infrastructure environments.
- Understanding of vulnerability management, threat detection, security monitoring, and remediation processes.
- Familiarity with security frameworks and compliance requirements applicable to financial services organizations, including SOC 1, SOC 2, ISO 27001, NIST CSF, CIS Controls, or equivalent standards.
- Strong knowledge of secure coding practices, application security principles, and common vulnerabilities such as those identified in the OWASP Top 10.
- Experience working within Agile and DevOps delivery methodologies.
- Understanding of disaster recovery, high availability, and business continuity concepts.
- Excellent troubleshooting, analytical, and problem-solving skills.
- Outstanding knowledge of cybersecurity principles, security architecture, and secure systems design (specific certifications in this area is a major asset).
- Experience with the CSLA .NET framework is considered an asset.
GENERAL SKILLS & ABILITIES REQUIRED
- Strong Communication Skills: Demonstrates clear and effective verbal and written communication, active listening, and the ability to adapt messages to diverse audiences. Creates clear, accurate documentation, communicates differing perspectives effectively, and provides and receives constructive feedback to support collaboration and business outcomes
- Workflow and Problem-Solving Acumen: Applies analytical thinking and a proactive problem-solving approach to identify issues, evaluate options, and recommend effective solutions. Demonstrate initiative, sound judgment, and a strong work ethic in supporting business objectives
- Self-Driven Productivity: Demonstrates intrinsic motivation and perseverance, managing workloads independently while maintaining consistent quality and meeting objectives without external prompting
- Meticulous Attention to Detail: Produces accurate, high-quality work by applying a thorough and detail-oriented approach to analysis, documentation, and deliverables while maintaining a focus on quality and accuracy
- Relationship and Client Orientation: Builds and sustains professional connections, interprets stakeholder expectations, and responds with empathy, respect, and service-minded adaptability
- Time Management and Prioritization Skills: Demonstrates strong organizational abilities and effectively manages multiple priorities in a fast-paced environment. Plans and organizes work efficiently, adapts to changing demands, and consistently delivers results within established deadlines
- Interpersonal and Sociable Engagement: Demonstrates maturity, confidence, and professionalism in interactions with others while working effectively both independently and as part of a team. Consistently demonstrates integrity, accountability, and ethical decision-making in all interactions and business activities
- Adaptability and Flexibility: Quickly adjusts to changes in workflows, client needs, or organizational priorities while maintaining performance, resilience, and solution-oriented focus
- Analytical Thinking and Problem Solving: Applies strong analytical and conceptual thinking skills to understand business needs, evaluate information, and identify effective solutions. Demonstrates the ability to simplify and communicate complex concepts to non-technical stakeholders, supporting business understanding and successful outcomes
Terms
- Full-Time Role
- This is not a hybrid role - attendance is required full time on-site at our Cayman office
- Compensation commensurate with qualifications and experience
Skills Required
- Bachelor’s or master’s degree in Computer Engineering, Computer Science, or equivalent qualification
- At least 2 years of experience in a similar role
- Experience in the financial services industry
- Experience working on an international, diversified team
- Knowledge of alternative investment products and offshore financial services, including portfolio valuation, accounting, share transfer, prime brokerage, financing, and custody
- Strong knowledge of software development, application architecture, and secure software engineering
- Proficiency with C#, ASP.NET, IIS, SQL Server, ASP.NET MVC, APIs, and the Microsoft .NET ecosystem
- Experience designing and maintaining secure CI/CD pipelines using Azure DevOps and Git workflows
- Experience implementing DevSecOps practices and integrating security controls into the SDLC
- Experience with Git, Azure Repos, source control, and branching strategies
- Experience with automated build, deployment, and release management
- Experience managing SAST, DAST, SCA, secrets detection, and container security scanning
- Proficiency with PowerShell or comparable automation scripting languages
- Experience implementing Infrastructure as Code with Bicep, Terraform, ARM Templates, or similar technologies
- Strong understanding of Microsoft Azure architecture, services, governance, and security
- Experience with Azure Key Vault, Managed Identities, RBAC, Private Endpoints, and network security controls
- Knowledge of Docker, Kubernetes, Helm, and container security
- Knowledge of Microsoft Entra ID, OAuth, OpenID Connect, SAML, and MFA
- Understanding of encryption, key management, secrets management, data classification, data protection, and PII handling
- Knowledge of networking protocols and technologies including TCP/IP, HTTP(S), DNS, TLS, VPNs, firewalls, load balancers, segmentation, and zero trust
- Knowledge of Linux and Windows administration, monitoring, hardening, and troubleshooting
- Experience managing virtualized and cloud-hosted infrastructure
- Understanding of vulnerability management, threat detection, security monitoring, and remediation
- Familiarity with SOC 1, SOC 2, ISO 27001, NIST CSF, CIS Controls, or equivalent financial-services standards
- Strong knowledge of secure coding, application security, and OWASP Top 10 vulnerabilities
- Experience with Agile and DevOps delivery methodologies
- Understanding of disaster recovery, high availability, and business continuity
- Strong troubleshooting, analytical, problem-solving, communication, documentation, collaboration, and time-management skills
- Cybersecurity certifications
- Experience with the CSLA .NET framework
What We Do
Harmonic is an independent financial services firm specializing in the global alternative investments industry. We began with a vision of independent, non-conflicted fund services which would be client and investor driven. We embraced technology and paid particular attention to creating an institutional infrastructure while avoiding the pitfalls of a commoditized service sometimes accompanied with size. Harmonic attracts service-oriented professionals who are motivated, technically savvy, innovative, and thrive in a collegial environment. We foster a culture of performance and specialization, while our flat, cross-functional hierarchy promotes internal and external collaboration. Our software platform, FM3, serves client needs by delivering unconstrained flexibility and possibility. It was built to support the range of services we offer and provides a unified front to back office platform for asset managers. Developers are embedded in our production environment and are integral to our client relationships. With our unique approach, we accept engagements with challenges that others may be unwilling or unable to undertake. Harmonic is one of the largest independent fund administrators, delivering a range of services and technology to hedge funds, fund of funds, private equity funds, private banks, pension funds and family offices. With our experienced professionals and technology, we support a dynamic and complex industry characterized by new financial products, trading strategies and markets, shifting investor demographics, and an ever evolving regulatory landscape.






