Kite - DevOps & Security Specialist (IC)
Location: India or Indonesia
Type: Full-time | Early Team
About Kite
Kite is a global neobank reimagining cross-border finance stating with South East Asia. Kite provides dollar account, debit card and secure wallet for fast & compliant payments with near-zero fees & without the usual friction, hidden FX costs, or confusing flows.
About the Role
This is a hands-on individual contributor role owning reliability first (SRE/DevOps) to stabilise environments and deployments, then shifting quickly into security hardening before go-live.
Role & Responsibilities
Reliability & DevOps
- Own production infrastructure on GCP and Kubernetes (GKE): cluster setup, networking, RBAC, upgrades, scaling, and runtime security.
- Build and maintain CI/CD pipelines (GitHub Actions) for backend + web + mobile release workflows (working with engineering on iOS/Android release needs).
- Set up observability end-to-end: metrics (Prometheus), dashboards (Grafana), logs/traces (GCP), alerting, and meaningful SLOs.
- Establish incident response basics: alert routing (Slack + Zenduty), runbooks, postmortems, and reliability improvements.
- Set budget guardrails and alerts, autoscaling policies, rightsizing cadence, and cost dashboards to keep infra efficient as we scale.
- Own operational setup for:
- Postgres (Cloud SQL or AlloyDB), Redis/Memorystore, and messaging (Pub/Sub/Kafka) where applicable
- Backups, restores, and environment hygiene
- Define and track RPO/RTO and disaster recovery practices
Security
- Implement security fundamentals: least-privilege IAM, secret management, environment isolation, audit logging, vulnerability scanning, patching cadence.
- Secure production access: strong RBAC, break-glass processes, and operational controls.
- Build security posture aligned toward SOC 2 / ISO 27001 / PCI DSS readiness (pragmatic controls and evidence collection).
- Help enforce secure release processes (signing keys, build integrity, secrets handling in pipelines).
- Partner with mobile engineers to ensure:
- Jailbreak/root detection
- Certificate pinning
- Device integrity (e.g., Play Integrity / App Attest)