DevSecOps Manager
About Us 🚀
Bridgit is a leading non-bank lender transforming the way Australians access property equity. Purpose-built to make property transactions faster and easier, we pioneered the Buy Now, Sell Later solution – empowering homeowners to unlock their property equity and move on their terms. With a simple digital application, fast approvals, and flexible loan options, we’re making property finance seamless and stress-free.
We’re now five years old and making huge strides. We have accredited over three quarters of Australia’s broker network, and launched white label solutions with Australia’s largest aggregators – Connective, Aussie Home Loans, Finsure, and Loan Market Group – and we’re just getting started.
Our momentum has been recognised with awards such as Best Growth Story at the 2025 Fintech Awards, 2025 Finder People’s Choice Award for Lending Innovation, the finalist for Excellence in Lending (Business & Consumer) at the 2025 Finnies, Deloitte's tech fast 50 2025 and finally; being recognised as one of LinkedIn’s top 20 Start Up’s in Australia 2025.
The difference you’ll make
We’re looking for a talented and driven DevSecOps Engineer to help shape the foundation that powers our products and developer experience. In this role, you’ll play a key part in building a self-service internal platform that empowers engineers to ship features faster, more reliably, and with greater autonomy.
You’ll be joining a high impact team focused on simplifying infrastructure, improving scalability, and enabling seamless delivery across the business. Based in Sydney (hybrid), this is an opportunity to work at the intersection of software engineering and infrastructure; influencing how development happens across the company and driving operational excellence in everything we build.
What you'll do;
Improve CI/CD pipelines and developer tooling to reduce friction, accelerate delivery, and make secure delivery the default.
Define, maintain, and continuously improve infrastructure standards using Infrastructure as Code tools such as Terraform.
Embed security controls into the software delivery lifecycle, including automated security scanning, dependency checks, secret detection, and policy enforcement.
Partner with engineering teams to shift security left, helping developers identify and resolve risks early in the development process.
Champion observability, reliability, and operational excellence, ensuring systems are well-instrumented, monitored, and easy to support in production.
Build and maintain secure cloud infrastructure patterns across networking, identity, permissions, logging, encryption, and workload isolation.
Support secure containerisation and deployment practices across Kubernetes or ECS, including image scanning, runtime security, least-privilege access, and secure configuration.
Improve incident response readiness by strengthening alerting, logging, runbooks, and operational processes.
Collaborate closely with product and software engineers to create a world-class developer experience without compromising security or compliance.
Promote best practices across automation, infrastructure design, DevOps culture, cloud security, and secure engineering.
Help define guardrails, standards, and reusable templates that allow teams to move quickly while staying aligned to security and compliance expectations.
Continuously evaluate and improve tooling across CI/CD, cloud infrastructure, observability, vulnerability management, and developer workflows.
What you’ll bring:
Strong experience with AWS and cloud-native architecture.
Proficiency with Infrastructure as Code tools such as Terraform.
Deep understanding of Kubernetes or ECS/container orchestration.
Proven experience with CI/CD systems such as GitHub Actions, CircleCI, ArgoCD, Buildkite, or similar.
Experience embedding security into CI/CD pipelines, including SAST, dependency scanning, container image scanning, secret scanning, and infrastructure policy checks.
Strong understanding of cloud security fundamentals, including IAM, networking, encryption, logging, workload isolation, and least-privilege access.
Experience managing secrets securely using tools such as AWS Secrets Manager, SSM Parameter Store, Vault, or equivalent.
Familiarity with vulnerability management, patching workflows, security monitoring, and remediation processes.
Experience with observability platforms such as Datadog, CloudWatch, Grafana, Prometheus, OpenTelemetry, or similar.
Practical understanding of container security, including secure base images, image scanning, runtime permissions, and deployment hardening.
A passion for improving developer experience and creating reliable, scalable, and secure systems.
Excellent communication skills and a collaborative, solution-oriented mindset.
Ability to work closely with engineering teams to balance speed, reliability, security, and operational maturity.
A pragmatic approach to security, focused on building sensible guardrails rather than unnecessary blockers.
Our Culture and Benefits
Bridgit values its team, they are the heart of how we build this business. Along with competitive remuneration, slick offices and the chance to be part of an innovative, agile fintech, we also offer:
Extra Leave – We offer birthday leave + an additional day of paid leave to be used for life events, celebrations, or just a mental health reset.
Two Weeks from Anywhere – We encourage employees to work remotely from a location of their choice for two weeks each year.
Learning and Development – All employees are encouraged and empowered to engage in professional development, including a number of learning initiatives run internally.
Social Events – We have a jam-packed social scene, with events throughout the year to bring the team together!
Ready to Make an Impact?
If you’re excited about reshaping the lending industry and want to be part of a company that values authenticity and innovation, we’d love to chat. Apply now and let’s build the future of finance together! 🚀
- Department
- Tech Team
- Locations
- Sydney
- Remote status
- Hybrid