Skip to content

Meet us in Lisbon. The VIALET team will be at SBC Summit Lisbon. Let’s discuss how we can serve your business.

Senior Platform Engineer

  • Location

    Lithuania, Vilnius
  • Remote status

    Hybrid
Build the future of FinTech at VIALET

VIALET is a Lithuanian EMI building a specialized financial platform for target industries – ranked among the country’s top EMIs by client funds, turnover, and revenue, and scaling into new markets.

Why VIALET?
  • Impact: Own the efficiency, security, and scalability of the platform our engineering teams build on.

  • Growth: Join a fast-scaling FinTech at the point where the core platform is being defined.

  • Ownership: Take real ownership – from architecture and ADRs to operations and developer experience.

  • Expertise: Work with a small, high-bar team setting the standard for platform engineering here.

Why now

Engineering is mid-pivot: from a cloud of functions (Lambda + API Gateway, some ECS) to an in-house platform on Kubernetes. Serverless got us to market fast; it won’t carry mission-critical 24/7 systems. The new platform is greenfield, built in parallel to the legacy estate – nothing breaks on launch, services migrate when ready. It’s young but seriously planned: account strategy, networking, orchestration, IAM, and repo strategy were argued out in ADRs before any code. The hard calls are written down. Large surfaces are still open.

How we work
  • Platform as a product, not a project. Shaped by the engineers who use it. Never “done.”

  • Paved paths with explicit escape hatches. Security, observability, and quality come by default – best practice is the path of least resistance.

  • No human gatekeepers. Deterministic automation is the gate. Self-service within guardrails.

  • Decisions are written and argued. ADR culture is real here, not ceremonial.

The role

Senior Platform Engineer on the Foundations team. Hands-on, with genuine architectural say – not a ticket queue.

You’d own and evolve real surfaces: the @platform/* components, CI/CD, network and security policy, the observability stack, cost governance, and developer experience itself.

First stretch: get the first real services onto the platform – standing up observability, closing developer-experience and training gaps, and building the CI templates that make deployment configuration rather than engineering. This is the Pilot → Automate → GA arc of our build.

The contract

The platform is not a hand-off model – both sides have skin in the game.

  • We own: a ready AWS account (networking, DNS, IAM, EKS) with TLS, secrets, mTLS, and a security baseline by default; non-breaking cluster upgrades with runbooks; self-service onboarding; being the escalation path for infra incidents, not the first line.

  • Developers own: resource requests/limits, probes, graceful shutdown, their service-specific infra as code, and first response to their own incidents.

  • Off-path is allowed: a team can step off the paved road, but takes on the operational and security burden explicitly.

The team – lite by design

A deliberately small group (2–3) accountable for the platform side of that contract. It works because platform is a capability team – we scale by enabling product teams to run their own services, not by absorbing their work. No on-call today, and it isn’t being smuggled in. The platform is built so it isn’t the thing that pages you at 3am: managed data (Aurora), observability kept off our own infra where possible. Small team, high bar, real pace – that’s the appeal, and the tension is named in the platform vision, not hidden.

What you’ll bring
  • 4+ years of strong Platform / DevOps / SRE experience with a track record of owning infrastructure.

  • Strong, hands-on Kubernetes in production (AWS EKS preferred).

  • Solid cloud networking (VPCs, security groups, routing, load balancers).

  • Infrastructure as Code, and a genuine platform-as-a-product mindset.

  • Security-first instincts in a regulated environment.

  • Bonus: FinTech, PCI-DSS, ISO 27001, eBPF/Cilium, Istio, Pulumi.

Tech stack

Everything is TypeScript – infrastructure included.

Layer What we use

IaC Pulumi (replaces CDK)

Cloud AWS multi-account org, SCP guardrails, CloudTrail + GuardDuty

Identity IAM Identity Center SSO, GitHub OIDC hub-and-spoke, EKS Pod Identity

Network Transit Gateway hub-and-spoke, four-tier VPCs, Cilium (eBPF) + Hubble

Compute Amazon EKS, Karpenter autoscaling, self-hosted Actions runners on-cluster

Mesh Istio ambient + cert-manager, AWS Load Balancer Controller, NLB ingress

Data Aurora PostgreSQL, MongoDB Atlas

Delivery ArgoCD GitOps + ECR + GitHub Actions

Secrets / TLS External Secrets Operator ← AWS Secrets Manager, cert-manager

What’s not built yet – the senior surface area
  • Observability – the big one. Largely greenfield; a placeholder today. The intent: an OpenTelemetry pipeline to a SaaS backend, RED/USE dashboards, distributed tracing. Could be your first major ADR and build.

  • Policy-as-code (Kyverno), cross-region DR runbook, cost governance, and the Cilium audit → enforce rollout.

  • Legacy retrofit of the CDK/Lambda/ECS estate – patterns built per service as we go.

Straight talk
Regulated environment (Bank of Lithuania, Visa/MC, PSD2, AML) – constraints are design inputs, not walls to route around. The legacy estate still runs; migration is a longer process. Running EKS means real ownership – cluster upgrades, the network/security layer, the paved road – scoped deliberately not to be a pager treadmill.
What we offer
  • Competitive compensation: 6000-8000 euros gross, based on your experience and knowledge, with room for negotiation for an exceptional candidate.

  • Health insurance: Comprehensive health coverage after 3 months.

  • Work-life balance: Flexible work arrangements, including hybrid and remote options (after the probation period), and a relaxed approach to work hours.

  • Professional development: Up to 1000 euros annual reimbursement for work-related training and courses, with potential for more based on individual needs.

  • Inspiring workspace: Modern office on the top floor of Vilnius’ highest office building, offering stunning city views. A convenient parking space is available.

  • Wellness benefits: Gym membership to support your physical well-being.

  • Vibrant company culture: Regular company events, including monthly city-wide gatherings, bi-annual company-wide adventures, and team-based activities.

  • Collaborative environment: A flat hierarchy where you can freely communicate with anyone and make decisions quickly.

  • Ambitious culture: Join a team of driven professionals committed to building a leading FinTech platform.

Building the platform that powers the future of finance sounds like your kind of problem? Apply now.

Ready to Join the Team?

We hire people, not just resumes. We’d love to hear your story and get to know the person behind the CV. Share your details and let’s see if we can #do.it.right together.

* The Company reserves the right to contact only those candidates whose experience and qualifications meet the requirements of the position.

Thank you!

We’ve received your submission. If needed, we’ll follow up using the contact details you provided.

Test your knowledge on fraud prevention

Digital banking makes life easier — but also riskier. Take this short quiz to test your fraud awareness and learn simple ways to protect yourself online.

Please find test answers below and good luck!

  1. 1.

    What is the best practice for creating a strong password for your online account?

    1. 1.

      Use your birthdate and a simple word

    2. 2.

      Use a combination of letters, numbers, and special characters

    3. 3.

      Use the same password for all your accounts for convenience

    4. 4.

      Use only numbers

  2. 2.

    What is a recommended step when using public Wi-Fi to access your financial accounts?

    1. 1.

      Log in to your accounts only if you are using a VPN

    2. 2.

      Avoid accessing any financial accounts on public Wi-Fi

    3. 3.

      Use a public Wi-Fi network even if it is unsecured

    4. 4.

      Only use public Wi-Fi for non-sensitive transactions

  3. 3.

    What is a common indicator of a phishing attempt?

    1. 1.

      An email from a known contact asking for verification

    2. 2.

      An email with urgent language asking you to confirm your account details

    3. 3.

      A phone call from your bank asking you to update your information

    4. 4.

      A notification from your bank’s app about a new feature

  4. 4.

    Which of the following actions is a sign that your account may be compromised?

    1. 1.

      Receiving a confirmation email for a transaction you didn’t make

    2. 2.

      Regularly receiving marketing emails from your bank

    3. 3.

      Seeing advertisements for products you recently searched online

    4. 4.

      Noticing minor changes in the colour scheme of your bank’s website

  5. 5.

    Which of the following is a good practice for managing your account security?

    1. 1.

      Sharing your account password with close friends for convenience

    2. 2.

      Regularly updating your security questions and answers

    3. 3.

      Using the same security questions for multiple accounts

    4. 4.

      Keeping your password written down near your computer for easy access

  6. 6.

    What should you do if you suspect your account details have been stolen?

    1. 1.

      Immediately call your bank to report the issue and freeze your account

    2. 2.

      Wait and see if any suspicious activity occurs

    3. 3.

      Change your password and continue using the account as usual

    4. 4.

      Post about the issue on social media to warn others

  7. 7.

    What is two-factor authentication (2FA)?

    1. 1.

      A method to recover a forgotten password

    2. 2.

      A security process that requires two separate forms of identification

    3. 3.

      A way to encrypt your emails

    4. 4.

      A feature that automatically logs you out after inactivity

  8. 8.

    Why is it important to keep your software and apps up to date?

    1. 1.

      To access new features and improve performance

    2. 2.

      To ensure compatibility with your device

    3. 3.

      To protect against vulnerabilities and security threats

    4. 4.

      To avoid advertisements

  9. 9.

    How should you respond to unexpected account alerts or notifications?

    1. 1.

      Ignore them if you are not expecting any changes

    2. 2.

      Verify the alert by contacting your bank using the phone number on their official website

    3. 3.

      Click on any links in the alert to follow instructions

    4. 4.

      Forward the alert to your friends to check if they received similar notifications

  10. 10.

    What should you do if you receive an email from your bank with a link to a login page?

    1. 1.

      Click the link to check if it leads to your bank’s official site

    2. 2.

      Copy the link and paste it into your browser to verify its authenticity

    3. 3.

      Visit your bank’s website directly by typing the URL into your browser and log in from there

    4. 4.

      Open the link in an incognito window to avoid detection of fraud

If you have any questions about the quiz or need more information, don’t hesitate to reach out to us. You can contact us at support@vialet.eu for personalised assistance. If you didn’t pass the quiz, don’t worry – you can learn more about the key topics on our website.