Lead Platform Engineer
Own Kord’s AWS platform end to end — building secure, resilient infrastructure, observability and compliance foundations for trusted fintech products.
About Kord
Kord is an FCA-regulated fintech delivering KYC, Anti-Money Laundering (AML), identity verification and payments infrastructure to regulated businesses across the UK. We help companies verify who they are dealing with quickly and reliably.
Behind that sits a genuinely interesting engineering problem. Verification checks and payment flows have to be fast, correct and provable after the fact, on a platform growing on every axis at once: more clients, rising enquiry volumes, and payment systems arriving through acquisition. AWS and Terraform, EKS, a PostgreSQL, MySQL and Redis data layer, Java, Node.js and Laravel services on top, and event streaming on the horizon.
Why this role matters
Every check we run and every payment we process depends on the platform underneath it. Get that right and clients trust us, auditors are satisfied, and the engineering team ships without looking over its shoulder.
We should be clear about what this is. There is no DBA, no security team, no SRE rota and no tooling group who already solved observability. A fair amount of the stack is unowned. We are FCA-regulated and we handle identity and payments data, which means nothing here can be approximate. What you build has to hold up under an auditor, a client security review and a real incident, with you in the room accounting for it.
That is also what makes the role worth having. The decisions are still open, and they will be yours: the standards, the tooling, and the things we deliberately choose not to build. Very few engineers get to shape a regulated platform from the ground up and then watch a growing business run on it. If that is the kind of responsibility you have been looking for, this is it.
What you'll own
AWS and Terraform. The whole estate, infrastructure as code first, with no undocumented manual changes.
EKS. Running and scaling workloads securely, including RBAC, network policies, ingress and secrets.
The data layer. PostgreSQL, MySQL and Redis in production: replication, failover, tested restores and tuning under load.
Application runtime. Keeping Java, Node.js and Laravel or PHP services healthy alongside the engineers who write them.
CI/CD. Secure Bitbucket Pipelines with build isolation, artifact integrity and dependency control across npm and Composer.
Observability. Datadog end to end, including APM tracing, SLOs, and alerts people trust enough to act on.
Security and compliance. Zero trust, least-privilege IAM, secrets and key management, audit evidence, and answering auditors directly.
Incidents. Incident command, on-call health, and postmortems that actually change something.
Payments and legacy. Integrating acquired systems, including PCI scoping and segmentation.
The conversation about all of it. Regular progress reporting to the executive team, and working across engineering, product, compliance and risk.
What we actually need
Roughly 7+ years in infrastructure or platform engineering, including at least 3 years owning production AWS somewhere the consequences were real — regulated, handling payments, or otherwise audited.
We have split this deliberately. The must-haves are genuinely non-negotiable. Everything below that we will trade against strength elsewhere, and we would rather hire someone excellent in most of it than someone adequate in all of it.
Must have
AWS, in depth. VPCs, routing, private connectivity, least-privilege IAM.
Terraform, in depth. Module design, remote state, environment isolation, drift management.
Kubernetes in production. RBAC, network policies, secure ingress and egress, secrets. EKS specifically is a plus, not a requirement.
Production relational databases you have personally been responsible for. Replication, failover, restores you have actually performed, and tuning under load. PostgreSQL or MySQL — we run both, and we assume whichever you know less well you will pick up.
Security and compliance you have been accountable for. Defence in depth, least-privilege IAM, secrets management (Secrets Manager or Vault), KMS, TLS everywhere. You have personally answered auditor and client security questionnaires and stood behind the answers — not forwarded them to someone else.
Senior stakeholder communication. You can hold a room with founders, executives, auditors and client security teams. You have a track record of reporting progress on a regular cadence to people who are not engineers, and of getting alignment across teams without formal authority.
You have done this without specialist teams to hand work to. You have built a platform or security function somewhere small or scaling, owned a system over years including upgrades, on-call, backlog, cost and technical debt — and you can say clearly what you chose not to do, and why.
Strong advantage
Fintech or payments; FCA regulation or an equivalent regime in another jurisdiction
ISO 27001, UK GDPR or PCI DSS hands-on, with audit logging and traceability
Operating JVM services in production — diagnosing heap, GC, thread and connection pool problems alongside the engineers who own the code
Node.js and/or Laravel/PHP in production
Redis in production
Supply-chain-hardened pipelines: build isolation, artifact integrity, version pinning, reproducible builds
SAST, DAST and dependency scanning implemented as gates engineers actually trust rather than route around
Distributed tracing and SLOs you have used to resolve real incidents, not just to build dashboards — Datadog, or Prometheus/Grafana/Honeycomb/OpenTelemetry equivalents
Kafka, Kinesis, MSK or similar event streaming in production
Integrating acquired systems; hybrid on-prem and cloud
Cloudflare; image and runtime scanning
AWS Security Specialty, CKA or CKS
We will teach you
Datadog specifically, Bitbucket Pipelines specifically, our Laravel and PHP estate, and our compliance calendar. If you are strong on the must-haves, none of these are worth screening you out over.
The hiring process:
Screening call with HR, online
Call with the hiring manager, online
Take-home task
In-person interview, including a presentation of your task
Culture fit interview
Kord is an equal opportunities employer. We welcome applications from all backgrounds and are committed to building a diverse and inclusive team.
- Department
- Engineering
- Role
- Lead Platform Engineer
- Locations
- Kord HQ
- Remote status
- Hybrid
- Employment type
- Full-time
About Kord
Kord is a London-based fintech helping regulated businesses including law firms, conveyancers, and estate and lettings agents manage identity checks, compliance, client onboarding, and payments from one platform
Founded in 2019 by James Owusu, Kord (formerly known as Checkboard) was built to bring together processes that are often handled by separate systems and teams, cutting out manual work and reducing the risk of fraud along the way.
We work with firms handling high-value, high-stakes transactions, particularly in property and legal services, giving them the tools to onboard clients and process payments quickly, securely, and with confidence.
It's a fast-moving space, and we're growing quickly alongside it, which means plenty of opportunity for the people who join us to make a real impact.