Senior Security Engineer, Infrastructure Security
Juicyway
Who we are
There is a business owner in Lagos who woke up this morning and still hasn't received a payment she sent last week. She's not waiting because the money isn't there. She's waiting because the infrastructure that moves it was never built with her in mind.
Juicyway exists to fix that. We are building the financial rails that connect African businesses to the world — cross-border payments, FX conversions, and global liquidity — fast, transparent, and built for the people who have been underserved by every system that came before us. Our mission isn't a slide. It's the reason we come to work: every African should be able to participate in the global economy on equal footing.
We're not improving what exists. We're replacing it.
And the infrastructure doing the replacing moves real money, in real time, across multiple countries. Which means the security of what we build is not a compliance checkbox. It is the foundation on which the whole mission stands or falls.
The team you're joining
The Security and Infrastructure team protects Juicyway's technology, people, and products. We are technical in what we build but operational in how we work, and we are committed to supporting every product and every bold bet Juicyway makes. Our tenets are simple: prioritise for impact, prepare the foundations for transformative financial technology, and build a security culture that runs deeper than policy.
Tasks
The problem you'll be solving
Financial infrastructure is one of the most targeted surfaces on the internet. When you are moving money across African borders, navigating multi-cloud environments, multiple jurisdictions, and a threat landscape that does not stand still, the attack surface is wide and the consequences of getting it wrong are not theoretical.
InfraSec protects the foundations of Juicyway's production and experimental environments. That spans everything from bare-metal hardware and workforce devices to Kubernetes clusters and service meshes, from data storage to the access pathways for some of the most sensitive financial data on the continent.
This role exists to lead that function. Not to audit it from a distance. To actively harden it — building the controls, the tooling, and the instincts that make Juicyway's infrastructure genuinely difficult to compromise. You will be the senior security voice in a technical team that takes this seriously, working on infrastructure that processes real financial transactions for thousands of African businesses every day.
What you'll own
- Designing and building security controls across every layer of the stack; physical hardware, OS, Kubernetes, networks, and CI/CD pipelines - with sophisticated adversaries and insider threats as the design constraint
- Hardening our multi-cloud infrastructure end to end, network isolation, secret management, machine identity, checkpoint encryption, the unglamorous work that keeps real money safe
- Protecting our API services against common and emerging threats, from DDoS to the attacks that do not have names yet
- Securing and monitoring our distributed workforce device fleet; endpoint protection and robust IAM for a team that moves fast across multiple markets
- Partnering with engineering teams to deploy security enhancements at scale, embedding security into how we ship, not bolting it on after the fact
- Leading our compliance work; PCI DSS, SOC 1 and 2, routine penetration tests with external auditors, and making sure we don't just pass them, we believe in them
- Taking a generalist approach to emerging workloads, balancing deep security expertise with the broad technical range to adapt as the infrastructure evolves
- Building the security culture across the engineering org, not by policing, but by making secure instincts the default
Requirements
What we need
- Deep expertise in cloud security — AWS and/or Azure — including multi-cloud network design, infrastructure hardening, and cloud-agnostic system design
- Proven experience securing Kubernetes environments, container orchestration, and service meshes
- Solid track record with secret management, IAM, machine identity, and access control at scale
- Hands-on experience with compliance frameworks; PCI DSS and SOC 1 and 2 specifically
- Strong analytical instincts
- The communication skills to work across technical and non-technical stakeholders without losing precision
- Bonus: experience securing cryptocurrency systems; background in financial services or regulated industries; familiarity with endpoint protection tooling and workforce device management
Benefits
What we offer
- Competitive pay
- Meaningful equity at an early stage
- Real flexibility on hours, location, and how you do your best work
- A technical team that takes security seriously and will actually listen to you