Cloud Platform Developer (Golang)

ING Bank N.V.
Amsterdam, Netherlands
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Secure Shell (SSH) Active Directory Amazon S3 Apache HTTP Server Microsoft Azure Command-Line Interface Software as a Service Software Quality Computer Networks Databases Database Connection Linux
+24 more
File Systems Integrated Windows Authentication File Transfer Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) Microsoft SQL Server Windows Servers OpenShift Remote Desktop Services Prometheus Storage Virtualization VCloud Private Cloud Environment Data Logging Cloud Platform System Test-Driven Development (TDD) Cyberark Grafana Backend Integration Tests Kubernetes Hashicorp Api Design Terraform

Job description

Stepping Stone is the secure access platform for ING Private Cloud. It is the single hardened entry point engineers use to reach infrastructure inside the private cloud: interactive remote sessions over SSH and RDP through Apache Guacamole, and secure file transfer in and out of isolated environments. Everything that passes through it is controlled, logged, and built to stand up to audit. We are growing the team that builds and runs this platform, and we are looking for a Go engineer who wants to work on security-critical infrastructure that real engineers depend on every day. You will spend most of your time on the file transfer side of Stepping Stone: the services that move data safely across trust boundaries, backed by S3, with tenant isolation and full auditability built in. You will also work across the interactive access side (Guacamole for SSH and RDP) as the platform evolves. This is hands-on engineering. You will write production Go, drive it with tests, provision your own infrastructure as code, and own what you ship from the first commit to a running service on OpenShift. The team Stepping Stone sits within ING Private Cloud, part of Global Infrastructure. We run a productized, SaaS-style platform that serves consumers across the bank under a single approved reference architecture, with strict tenant isolation as a hard requirement rather than a nice-to-have. The platform is on the critical path for how work gets done safely in the private cloud, so reliability, security, and clean audit trails are not up for negotiation. You will work in a small, senior-leaning squad alongside engineers, a product owner, and security colleagues. We keep the feedback loop short, review each other’s code, and expect everyone to own both the build and the run. Roles and responsibilities Your focus is the secure file transfer service. Day to day, you will: · Build and maintain the file transfer platform in Go: services that move files in and out of isolated environments with tenant-scoped access and time-bound permissions. · Implement S3 access patterns: pre-signed URL generation with strict expiry, bucket and path isolation per tenant, and object lifecycle and retention. · Write and maintain custom Terraform providers in Go, so the whole stack is described, reviewed, and versioned as code rather than clicked together by hand. · Design and run the backend persistence layer on MSSQL, including Kerberos-based (integrated) authentication for database connections, schema design, and migrations. · Package and deploy services on OpenShift: deployments, services, configuration, secrets, and network policies that actually enforce the isolation model. · Work test-first. Write unit and integration tests before or alongside the code, keep coverage meaningful, and wire it into the pipeline so nothing ships untested. · Contribute to the interactive access side (Apache Guacamole for SSH and RDP): connection management, session handling, and configuration as the platform grows. · Automate the credential lifecycle: retrieval at session start, seeding, and reset at session stop. · Make sure session recording and logging are complete and land in the log repositories each tenant expects. · Build and maintain CI/CD pipelines in Azure DevOps covering provisioning, start, stop, and decommissioning. · Work with security colleagues each sprint to sharpen detection scenarios and keep control reporting accurate and audit-ready. · Take part in SLI and SLO measurement, write runbooks, and help handle incidents when they land. How to succeed We hire smart people like you for your potential. Our biggest expectation is that you will stay curious. Keep learning. Take on responsibility. In return, we will back you to grow into an even stronger version of yourself. Technology must-haves:

  • Solid Go. You write clean, tested, production-grade Go and are comfortable with concurrency, the standard library, and the built-in testing tooling.
  • Test-driven development as a default habit, not an afterthought you get to later.
  • Hands-on experience with OpenShift or Kubernetes: deployments, services, configuration, secrets, and networking.
  • Terraform, including writing or extending custom providers, which in practice means writing Go against the Terraform plugin framework.
  • Experience with MSSQL as an application backend, including Kerberos or integrated Windows authentication for database access. Working knowledge of S3-compatible object storage, MinIO in particular: pre-signed URLs, bucket policies, and API-based access.
  • Basic familiarity with Apache Guacamole or a similar remote desktop gateway (SSH and RDP), enough to work with connections and sessions and grow from there.
  • Comfortable Linux fundamentals: command line, networking, SSH, file systems, and process management.

Requirements

Deeper Guacamole experience: guacd, protocol handling, or custom extensions. Credential management tooling such as CyberArk or HashiCorp Vault. Active Directory, LDAP, or Kerberos beyond the database, and a feel for how they fit together. · Azure DevOps for pipelines, work items, and repositories. · Observability with Prometheus, Grafana, OpenTelemetry, or similar. · Exposure to regulated environments and frameworks such as DORA or NIS2. · VMware Cloud Foundation or vSAN exposure. · Windows Server and RDP administration basics. · An eye for code quality. Writing good code is something you actually enjoy.

Benefits & conditions

We want to make sure that it’s possible for you to strike the right balance between your career and your private life. The benefits of working with us at ING include:

  • 25-28 vacation days depending on contract
  • Pension scheme
  • 13th month salary
  • 8% Holiday payment
  • Hybrid working
  • Personal growth and challenging work with endless possibilities
  • An informal working environment with innovative colleagues

Stand-by shifts SteppingStone is business-critical infrastructure that has to be available around the clock. If your lead designates you for stand-by shifts to cover incidents outside your regular working hours, a stand-by compensation is awarded to make up for the inconvenience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.nl

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:48 min

Demonstrating architecture and floating platform integration patterns

Romano Roth Romano Roth · WWC 2025

1:12 min

Choosing TypeScript for complex backend applications

Maximilian Otto Maximilian Otto · WWC 2024

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

2:20 min

Moving from the .NET ecosystem to JavaScript and Go

Brian Morrison · Coffee With Developers

Videos

See all

Related articles

See all