DevSecOps Engineer
Listed on 2026-02-28
-
IT/Tech
Cybersecurity, Systems Engineer, Security Manager
Hello! We're Teya.
Teya is a payment and software service provider, headquartered in London serving small, local businesses across Europe. Founded in 2019, we build easy to use, integrated tools that enable our members to accept payments and boost business performance.
At Teya we believe small, local businesses are the lifeblood of our communities.
We’re here because we don’t believe there’s a level playing field that gives small businesses with a fighting chance against the giants of the high street.
We’re here because we see banks and legacy service providers making things harder for them. We don’t think the best technology or the best service should be reserved for those with the biggest headquarters.
We’re here to fight for a future where small, local businesses can thrive, and to commit the same dedication they offer all of us.
Become a part of our story.
We’re looking for exceptional talent to join our mission. We offer a chance to create impact in a high-energy and connected culture, while benefiting from continuous learning opportunities, a supportive community which is proud to serve our mission, and comprehensive benefits.
Your MissionAs a Senior Dev Sec Ops Engineer (Security Tooling & Enablement), you will be responsible for embedding automated security controls and guardrails into our CI/CD pipelines, cloud platforms, and developer workflows. You’ll build and operate internal security tooling and integrations that enable secure delivery at scale—focusing on automation, low-friction developer experience, and high-quality security feedback loops. You will partner closely with platform, cloud, App Sec, and Sec Ops teams to deliver scalable, reliable, and friction-reducing security capabilities across the engineering organisation.
ResponsibilitiesSecurity in CI/CD & Delivery Workflows
Integrate and maintain security checks (SAST, DAST, SCA, secrets scanning) into CI/CD pipelines.
Provide fast, actionable, low-noise feedback to developers.
Embed infrastructure and application scanning into automated deployments.
Security Tooling & Platform Engineering
Design, build, and operate internal security services, APIs, CLIs, and automation workflows.
Apply strong software engineering practices to security tooling (testing, observability, version control).
Treat security tooling as a product with clear documentation and support.
Policy-as-Code & Guardrails
Implement and maintain policy-as-code guardrails for IaC, Kubernetes manifests, cloud accounts and identity configurations.
Work with platform teams to define secure defaults and self-service patterns.
Platform Security & Detection Pipelines
Support vulnerability scanning platforms and security telemetry pipelines.
Ensure high-quality structured security data flows to SIEM/log platforms.
Enable automated response actions via integrations and runbooks.
Dev Sec Ops Culture & Enablement
Champion secure engineering practices and a shared responsibility mindset.
Drive enablement activities (office hours, guides, training) to improve adoption of secure patterns.
Contribute to blameless post-incident reviews and continuous improvement.
Automation, AI & Operational Metrics
Leverage automation and AI to reduce manual toil and enrich security findings.
Define and track metrics such as time-to-feedback, signal-to-noise, and tooling adoption.
5+ years in security engineering, Dev Sec Ops , or platform engineering with significant security integration experience.
Hands‑on experience embedding security into CI/CD (SAST/DAST/SCA, container scanning, secrets detection).
Proficiency with CI/CD platforms (e.g., Git Hub Actions, Git Lab CI, Jenkins) and IaC (e.g., Terraform).
Strong software engineering and automation skills (Python, Go, Bash, or similar).
Deep cloud‑native experience (AWS preferred), including IAM, networking, and logging.
Experience designing and implementing policy‑as‑code and security guardrails.
Ability to collaborate cross‑functionally, balancing security with delivery velocity.
Nice-to-Haves
Experience in fintech or regulated environments.
Familiarity with WAF/DDoS tools, Zero Trust, and vulnerability management programmes.
Exposure to SOAR or security…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: