Markit is how procurement teams across Europe buy IT products. Around 200 people, 50+ countries, one platform, and a growing share of enterprise and bank customers who audit us before they buy. Your job is to make sure we have the answers before they ask. You join a small platform team that runs Azure, Kubernetes, deployments, Microsoft 365 and on-call. This is a hands-on platform role first: you run the infrastructure with the team, day to day, and you are the second pair of hands the migration needs. On top of that you own the security side and build it into a practice with owners, tooling and evidence. Expect the split to move: more platform work while the migration runs, more security once the baseline is in. The context you walk into: fully on Azure with Microsoft 365 and Defender, Azure DevOps for code and pipelines, Kubernetes in production. We are moving from a monolith to services, with the first services live in 2026 and the legacy platform retired in stages. That migration is infrastructure work as much as application work: new clusters, pipelines, environments and observability, built while the old platform still serves customers. ISO 27001 certification is the target for next year and the technical controls behind it are yours. Penetration testing stays with an external partner; you scope it, run it and close the findings. 5+ years in platform/DevOps engineering, with hands-on Azure and Kubernetes in production: you have built clusters, pipelines and environments, run upgrades and carried on-call. Security engineering on top of that, owned rather than assisted, is what makes you a fit for this role. You have carried the technical side of ISO 27001 (or an equivalent framework) once already, or you have run vulnerability management end to end: finding, fix, verification, evidence an auditor accepts. You know the tooling by category rather than by logo: external attack surface monitoring, DAST, SAST, SCA, secrets and container scanning, cloud posture. You can pick the cheap option when it does the job and explain why. You script and automate by default. Bash, PowerShell or Python, infrastructure as code, and you treat a manual check as a bug. You write things down and can sit across from a customer’s security team or an auditor and answer plainly. Fluent English, Estonian or German is a plus. Run the platform with the team: Azure, AKS, deployments, upgrades, incident response and a share of on-call once you know the systems. Build and operate the infrastructure the migration needs: environments, CI/CD pipelines on Azure DevOps, infrastructure as code, monitoring and alerting that people act on. Own the external attack surface. Build and keep an inventory of every internet-facing asset with a named owner, run continuous outside-in monitoring, and close exposures fast. Build security into the delivery pipeline on Azure DevOps and Kubernetes: code, dependency, secrets, container and infrastructure-as-code scanning, with gates the team accepts because you introduced them together. Set and hold the Azure and Microsoft 365 security baseline: identity and access, MFA, cloud posture, Defender, and a written access process so access requests take hours. Run vulnerability management as a process, from customer finding or scanner result to fix and verified closure, and keep the evidence ISO 27001 asks for. Carry the technical controls of the ISO 27001 programme together with our compliance lead. Customer security questionnaires and audits run through the compliance lead and platform; you own the technical answers, keep them current, and join the call when a customer digs deeper. The challenge Platform operations, the migration and the security baseline run in parallel. You do all three, and you decide the order each week. Enterprise and bank customers audit their suppliers and expect answers in days. You are the person who answers. The list of things you could do is longer than one person can carry. Choosing what comes first, and saying what waits, is part of the job. Small team. Everything you build has to work when you are not there. You build the security practice from the ground up, with leadership backing and a customer base that is asking for it. What you set up in year one is what the certification runs on in year two. Headquarters is Tallinn, Estonia, and that is where most of the team sits. Remote from anywhere in the EU works for the right candidate. Moderate travel to Tallinn. A small, senior team. Decisions get made quickly and you are close to leadership. A product used by thousands of B2B buyers across Europe, with a broad supplier network behind every order.
Security Engineer II
Mapbox
ML & Agentic Systems Engineer [IC4]
Sourcegraph
AppSec and GRC Engineer — Cybersecurity and Defence
Complear
Staff Parser/Compiler Research Engineer
dottxt
Freelance Software Tester With Apple Vision Pro (Remote Worldwide)
Testlio
Remote Leadership and Impact Partner
Timetochanges