Staff Platform Engineer
We usually respond within a week
Shine is the financial copilot for entrepreneurs and small business owners.
Founded by serial entrepreneurs Rico Andersen and Martin Hegelund, Shine is a leading European fintech unicorn on a mission to restore the joy of running a business, by ending wasted time on financial admin. Shine offers a connected solution for invoicing, accounting, payroll, business accounts, payments, and financing, meaning business owners can focus their energy on growing a healthy business, not held back by manual admin.
Part of something bigger
Today we're part of Cegid, a European leader in cloud software for finance and accounting. Together we're building Europe's leading financial copilot for small businesses and their accountants.
Shine already supports more than 400,000 small businesses. As part of Cegid, we now reach over one million small businesses and 15,000 accountants across Europe.
We're a multicultural team working from France, Germany, Denmark and the Netherlands, Spain,Portugal
Your hiring experience matters
Just as we respect our customers' time, we respect yours. Your experience with Shine and Cegid should feel simple, transparent and genuinely supportive.
If this sounds like somewhere you want to grow, we'd love to hear from you.
The Infrastructure & IT unit at Shine
Our Infrastructure & IT unit builds and operates the cloud platforms, developer tooling, and IT services that underpin every product Shine ships. We run multiple cloud teams (AWS, GCP, Azure), Engineering Efficiency, and IT operations. Infrastructure security is a dedicated function within this unit — senior engineers who own the security posture of our cloud estate as a traversal role across all teams.
Your role as a Staff Platform Engineer (Infrastructure Security)
We're looking for a Staff Platform Engineer to own the security of our Azure cloud environment and contribute to multi-cloud security strategy. Azure is a strategic platform for the group, driven by recent acquisitions, and it needs the same security depth we are already building on AWS.
This is a hands-on, senior IC role. You will define security architecture, build controls as code, harden identity, implement detection, and partner with platform teams to make secure defaults the path of least resistance. You work alongside a peer Staff Platform Engineer who covers AWS and IT, sharing cross-cloud strategy while owning separate execution domains.
Your responsibilities will include:
Define and implement the security architecture for our Azure estate — policy guardrails, network security, encryption, identity hardening, and secure defaults.
Own the security of our Azure landing zone — the platform teams build it, you ensure it's built securely and that workloads migrate onto a secure foundation.
Own Entra ID security — conditional access, Privileged Identity Management, workload identity governance, federation hardening with Okta, and tenant security.
Co-own the onboarding and configuration of our CNAPP platform (e.g. Wiz, Cortex Cloud, Orca, or FortiCNAPP) — posture management policies, finding prioritisation, and workflow integration.
Build and maintain security controls as code using Terraform and Azure Policy — CIS baselines, automated remediation, integrated into CI/CD.
Ensure on-prem → Azure migrations happen securely — risk assessment pre-migration, controls during, posture validation post.
Conduct threat modelling for Azure infrastructure designs. Identify attack paths and prioritise controls based on actual risk.
Automate compliance evidence collection for ISO 27001, GDPR, and DORA.
Align Azure security patterns with AWS and GCP to maintain a coherent multi-cloud security posture. GCP security coverage will be shared with your peer as it matures.
Enable teams: security design reviews, paved-road patterns, documentation, and office hours so cloud teams can self-serve securely.
🏡 Full remote in one of our European hubs (Germany, Netherlands, Denmark, Spain, Protugal), or Hybrid in one of our Hubs (Berlin, Amsterdam, Copenhagen, Madrid, Porto)
About you
Required
8+ years of infrastructure or security engineering experience, with deep hands-on Azure security expertise at production scale.
Ability to operate at staff level — technical authority, cross-team influence, and sound judgment. Prior staff/principal title not required, but you must demonstrate this level of impact.
Strong Entra ID security expertise: conditional access, PIM, workload identity, federation hardening.
Proven experience implementing Azure security controls: Defender for Cloud, Sentinel, Azure Policy, network security, Key Vault.
Infrastructure-as-code for security (Terraform) — policy-as-code, security modules, CI/CD integration.
Threat modelling capability — reasoning about cloud attack paths, privilege escalation, and lateral movement.
Practical compliance framework implementation (ISO 27001, GDPR, DORA, or similar) — actual control automation, not just awareness.
CNAPP/CSPM tooling experience (Wiz, Cortex Cloud, Orca, Prisma Cloud, Defender CSPM, or similar).
Familiarity with observability platforms.
Working knowledge of at least one other CSP (AWS or GCP) from a security perspective.
Security detection experience with a SIEM (e.g. CrowdStrike, Splunk, Elastic, or native solutions like Sentinel or Google Security Operations).
Ability to influence without authority — setting standards across teams.
Excellent technical communication in English.
Preferred
Experience in fintech, banking, or regulated financial services.
Okta + Entra ID federation security and cross-IdP governance.
Post-acquisition security integration experience (tenant consolidation, inherited risk).
DORA implementation experience.
GCP security experience (future expansion area).
On-prem / hybrid security experience.
Supply chain security / CI/CD pipeline security.
Relevant certifications: AZ-500, SC-300, AZ-305.
Ways of Working
Senior IC who leads through code, designs, reviews, and enablement — not standalone documents.
Traversal role across all cloud teams — you partner with them, not sit above them.
Tight collaboration with the Azure platform teams: you build a secure platform with them.
Pragmatic: the secure path should be the easy path. Controls that teams bypass are not controls.
Peer relationship with the AWS/IT Staff Engineer: shared strategy, separate domains.
Success is measured by teams making good security decisions without you — build capability, not dependency.
What Success Looks Like
90 Days: Assessed the current Azure security posture across all subscriptions. Defined the security architecture for the landing zone. Started CNAPP onboarding and initial policy configuration. First security controls deployed. Relationships built with all cloud teams.
6 Months: Landing zone security live — workloads migrating securely. CNAPP operationalised. Entra ID hardened. Security detection covering critical attack paths. Cross-cloud security standards aligned with AWS. Cloud teams self-serving on T2/T3 security decisions.
12 Months: Azure security at parity with AWS. Multiple workloads migrated securely. CNAPP providing continuous posture management. Compliance evidence automated. Teams making fewer security decisions that need your involvement. Contributing to GCP security expansion.
Equal Opportunity Employer
We follow the principle of equal treatment to consider all job applicants and do not discriminate based on their gender, sexual orientation, color, racial or ethnic origin, religion, disability, etc. as per applicable law.
Our recruitment process
1️⃣ Recruiter screen, have a initial conversation with Talent Acquisition
2️⃣ Hiring manager interview, dive deeper into the technical challenges of the team
3️⃣ Case interview, show your skills to one of your peers
4️⃣ Stakeholder interview, get a better idea of the collaborative environment
5️⃣ A personality assessment to round things off.
- Department
- Product & Technology
- Role
- Platform
- Locations
- Remote Hub, Amsterdam, Berlin, Copenhagen, Madrid, Porto