At Centrifuge, we're not just talking about tokenization; we're making it real. In the past year alone, we've partnered with S&P Dow Jones Indices, announced the first tokenized S&P 500 Index Fund, brought Janus Henderson's AAA CLO strategy onchain, and crossed $1.7B in TVL. We're also well-funded, backed by leading investors such as ParaFi Capital, Greenfield, Circle Ventures, and Coinbase. We're live across more than ten blockchains and building the open infrastructure for real-world assets at scale. We're looking for a hands-on IT & Automation Engineer to own the systems a fast-moving 20 person team runs on. You'll own identity, access, and IT operations across our entire SaaS and cloud stack, and your mandate is to automate the repetitive parts away. This is not a ticket mill: expect 2 to 3 requests a day, high trust, high stakes, and the freedom to build the tooling that makes your own queue smaller. You'll work directly with our DevOps & Security lead, in a company where the security bar is set by a live fintech protocol.
\n
The roleYou'll be the person who keeps IT and operations running for a real production fintech company: access requests, user lifecycle, SaaS administration, and the routine deployments and infrastructure tasks the engineering org depends on. The queue is the job, and automation makes the queue smaller. In your first months you'll build self-service workflows (Slack bots, Terraform for Google Workspace, small API integrations) that remove a meaningful slice of the recurring requests for good.
You'll also work hands-on across our GCP and Cloudflare stack with increasing autonomy: routine deployments, DNS changes, CI fixes, and larger infrastructure changes that you prepare and our security lead reviews. Over time the role grows in two directions: deeper into security operations (access governance, compliance engineering, working through SOC 2 hands-on) and deeper into automation, owning the tooling the company runs on. Bigger infrastructure changes you prepare together with our security lead, who owns the architecture. If you're process-oriented, like owning systems end to end, and get satisfaction from replacing manual work with something you built, this is the role.
Essential Job Functions
- Respond to and resolve daily support requests from the team (Slack, tickets): the fast-turnaround work that keeps everyone unblocked.
- Manage user access and identity across the stack: Google Workspace, GitHub, Notion, 1Password, and other SaaS. Handle onboarding, offboarding, seats, licenses, permissions, and the roles and policies behind each platform.
- Administer SaaS and tooling: account provisioning, license management, vendor tool vetting, and the integrations that connect our tools to each other.
- Automate your own processes: user lifecycle via Terraform or API-driven Python scripts, small API integrations that make tools easier to manage, Slack self-service workflows, and monitoring snippets and bots that surface issues before people report them.
- Support security operations: hardware key (YubiKey) setup and onboarding, access reviews, and day-to-day security policy questions, working with our security lead.
- Execute deployments and keep CI/CD pipelines healthy (GitHub Actions across our repos).
- Operate across our cloud stack on GCP (Cloud Run, IAM, Cloud Functions, Cloud SQL) and Cloudflare (DNS, WAF, Access) with increasing autonomy: routine changes you own outright, bigger changes you prepare for review.
- Create and maintain operational documentation and runbooks so common tasks are repeatable.
- Learn Web3/blockchain operations hands-on.
- Work across European and US timezones in a fully remote, high-compliance environment where security and quality standards are high.
Tech stack: Google Workspace, GitHub, GCP, Cloudflare, GitHub Actions, Docker, Terraform, Python/Bash, Slack APIs, plus Web3 tooling.
Education and experience
- 3+ years in IT engineering, systems administration, IT operations, or MSP roles (in-house IT at a tech company or an MSP escalation role is a great fit; DevOps backgrounds are welcome if the support half of the role genuinely appeals to you).
- Scripting you can show: Python/Go/JS or Bash automation you built to remove repetitive work, not just scripts you ran.
- Hands-on experience running real workloads on a public cloud. GCP is ideal, but any major provider counts.
- Strong Linux/Unix fundamentals.
- Experience administering Google Workspace (or an equivalent identity platform) and a multi-SaaS stack: roles, policies, permissions, licenses.
- Solid Git/GitHub and comfort with CI/CD concepts.
- Excellent written English and a documentation-first, process-oriented mindset.
- Comfortable working with AI-assisted tooling to move faster (we lean on it heavily).
- Nice to have: deep GCP experience, Terraform/IaC, Cloudflare, exposure to compliance frameworks (SOC2, ISO 27001), and curiosity about Web3/blockchain. Prior Web3 experience is a plus, not a requirement.
Working conditionsThis is a full-time, permanent role. We work fully remote with a European base, generally around 09:00 to 17:00 local time, with the flexibility to overlap US hours when something needs it. There's an annual learning budget for courses, conferences, and certifications, and the occasional out-of-hours moment when a production incident needs attention, typically only a handful of times a year and always with escalation support behind you.
Reasons to joinYou'd own the entire IT and access surface of a live fintech protocol with over $1B in real assets onchain: one company instead of thirty clients, crypto-grade security practices, and no change-approval bureaucracy between you and a better setup. You'll work directly with a senior DevOps & Security engineer, with real room to grow. It's hands-on experience you won't get in many places, in a small, fast-moving, well-funded team, fully remote, with real autonomy over the systems you look after.
\n
€50,000 - €60,000 a year
\n