Project Orbit - Platform Engineer
Project Orbit - Platform Engineer- NextGen
Big Bank Funding, FinTech Thinking.
Our Technology teams work closely with our global businesses to design and build digital services that allow millions of our customers around the world to bank quickly, simply and securely. We run and manage our technology infrastructure, cloud and core banking systems that power the world's leading international bank, with one of the largest technology estates in the industry.
At HSBC we're redefining Identity and Access Management (IAM) on a global scale and launching a transformational programme to bridge modern IDAM technology and solutions with big bank scale and complexity. The IAM Transformation program is forecast to be 5 years plus with'significant change to be designed, planned and implemented globally. The transformation encompasses all aspects of IAM from Authentication through to elevated access and will cover human and non-human identities.
Department: Identity and Access Management (IAM)
HSBC Role Overview
The Platform Engineer will play a key role in delivering and operating enterprise Identity & Access Management (IAM) capabilities. Design, build, automate and operate the cloud platform that underpins the IDAM Next Generation programme, providing secure, resilient and scalable infrastructure and platform services to enable engineering teams to deliver identity capabilities efficiently and consistently.
The position works closely with IAM architects, business stakeholders and technology partners.
HSBC are undergoing a transformation of its Identity and Access Management practices including the delivery of a set of net new tools to overhaul how IAM is carried out in the industry. We are seeking experienced and dynamic Platform Engineer who have an excellent understanding of Identity Management, with a successful track record of working in complex global organisations at fast pace.
In this role, you will:
- Build and maintain cloud-native platform services supporting the IDAM 2.0 programme.
- Design, deploy and manage Kubernetes clusters and supporting platform components.
- Develop Infrastructure as Code (IaC) for repeatable, automated deployments.
- Implement and maintain CI/CD pipelines and GitOps deployment workflows.
- Manage cloud networking, connectivity and platform security.
- Implement platform observability including logging, monitoring, metrics and distributed tracing.
- Automate platform provisioning, configuration management and operational tasks.
- Support deployment and operation of identity platform components and supporting services.
- Implement secure secrets management and certificate life cycle automation.
- Configure service mesh technologies and secure service-to-service communication.
- Manage ingress, API gateways and network routing components.
- Implement platform resilience, backup, disaster recovery and high availability capabilities.
- Support workload identity and platform authentication mechanisms.
- Ensure platform compliance with enterprise security, governance and regulatory requirements.
- Optimise platform performance, scalability and cost efficiency.
- Develop operational tooling, scripts and self-service capabilities.
- Support incident management, troubleshooting and root cause analysis.
- Collaborate with Security, Architecture and Engineering teams to deliver secure platform services.
- Contribute to platform standards, operational documentation and runbooks.
- Support environment management across development, test, pilot and production environments.
- Drive continuous improvement through automation and platform engineering best practices.
To be successful in this role, you should meet the following requirements:
Key Skills & Experience
Essential Skills
- Cloud Platform Engineering (GCP)
- Kubernetes Administration
- Infrastructure as Code (Terraform or equivalent)
- CI/CD Pipelines
- GitOps
- Linux Administration
- Networking and Load Balancing
- Service Mesh Technologies (Istio/Envoy)
- Container Platforms
- Secrets Management
- PKI and Certificate Management
- Workload Identity
- Observability (Logging, Monitoring and Tracing)
- Scripting and Automation
- DevSecOps
- Site Reliability Engineering (SRE)
- Performance and Capacity Management
- Operational Support
- Global Deployment Strategies
- Positive can-do attitude adept at solutionising in large, complex organisations