Senior DevSecOps Engineer

Senior DevSecOps Engineer

Full-Time 70000 - 90000 £ / year (est.) No home office possible
Teya Services Ltd

At a Glance

  • Tasks: Embed automated security controls into CI/CD pipelines and developer workflows.
  • Company: Join Teya, a forward-thinking tech company focused on security and innovation.
  • Benefits: Enjoy flexible hours, health insurance, 25 days annual leave, and hybrid work options.
  • Other info: Be part of a diverse team that values collaboration and continuous improvement.
  • Why this job: Make a real impact by enhancing security in cutting-edge tech environments.
  • Qualifications: 5+ years in security engineering with hands-on CI/CD security integration experience.

The predicted salary is between 70000 - 90000 £ per year.

Your Mission As a Senior DevSecOps Engineer (Security Tooling & Enablement), you will be responsible for embedding automated security controls and guardrails into our CI/CD pipelines, cloud platforms, and developer workflows. You'll build and operate internal security tooling and integrations that enable secure delivery at scale—focusing on automation, low-friction developer experience, and high-quality security feedback loops. You will partner closely with platform, cloud, AppSec, and SecOps teams to deliver scalable, reliable, and friction-reducing security capabilities across the engineering organization.

Responsibilities

  • Security in CI/CD & Delivery Workflows: Integrate and maintain security checks (SAST, DAST, SCA, secrets scanning) into CI/CD pipelines. Provide fast, actionable, low-noise feedback to developers. Embed infrastructure and application scanning into automated deployments.
  • Security Tooling & Platform Engineering: Design, build, and operate internal security services, APIs, CLIs, and automation workflows. Apply strong software engineering practices to security tooling (testing, observability, version control). Treat security tooling as a product with clear documentation and support.
  • Policy-as-Code & Guardrails: Implement and maintain policy-as-code guardrails for IaC, Kubernetes manifests, cloud accounts and identity configurations. Work with platform teams to define secure defaults and self-service patterns.
  • Platform Security & Detection Pipelines: Support vulnerability scanning platforms and security telemetry pipelines. Ensure high-quality structured security data flows to SIEM/log platforms. Enable automated response actions via integrations and runbooks.
  • DevSecOps Culture & Enablement: Champion secure engineering practices and a shared responsibility mindset. Drive enablement activities (office hours, guides, training) to improve adoption of secure patterns. Contribute to blameless post-incident reviews and continuous improvement.
  • Automation, AI & Operational Metrics: Leverage automation and AI to reduce manual toil and enrich security findings. Define and track metrics such as time-to-feedback, signal-to-noise, and tooling adoption.

Requirements

  • 5+ years in security engineering, DevSecOps, or platform engineering with significant security integration experience.
  • Hands-on experience embedding security into CI/CD (SAST/DAST/SCA, container scanning, secrets detection).
  • Proficiency with CI/CD platforms (e.g., GitHub Actions, GitLab CI, Jenkins) and IaC (e.g., Terraform).
  • Strong software engineering and automation skills (Python, Go, Bash, or similar).
  • Deep cloud-native experience (AWS preferred), including IAM, networking, and logging.
  • Experience designing and implementing policy-as-code and security guardrails.
  • Ability to collaborate cross-functionally, balancing security with delivery velocity.

Nice-to-Haves

  • Experience in fintech or regulated environments.
  • Familiarity with WAF/DDoS tools, Zero Trust, and vulnerability management programmes.
  • Exposure to SOAR or security automation platforms.
  • Relevant certifications (AWS Security, Kubernetes Security, GIAC, CISSP, etc.).

Ways of Working

  • Extreme ownership: You take end-to-end responsibility for outcomes, not just findings or tooling output.
  • Pragmatic and delivery-aware: You balance risk reduction with product velocity, focusing on changes that materially reduce risk.
  • Low-ego and collaborative: You build trust with engineers, product, and operations teams, influencing through credibility and partnership.
  • Impact-driven: You measure success through outcomes – risk reduction, adoption, and time-to-remediate – not activity.
  • Data-informed: You use metrics and trends to guide priorities and demonstrate impact.
  • High bar for craft: You produce clear documentation, reusable patterns, and automation that scale across teams.
  • AI-first mindset: You actively look for opportunities to use automation and AI to improve security outcomes.

The Perks

  • We trust you, so we offer flexible working hours, as long it suits both you and your team.
  • Health Insurance.
  • Physical and mental health support through our partnership with MyFitness.
  • 25 days of Annual leave (+ Bank Holidays).
  • Possibility to visit other Teya offices to meet colleagues in instances when travel is safe and appropriate.
  • Friday lunch in the office.
  • Friendly, comfortable and high-end work equipment and informal office environment.
  • Hybrid work mode policy.

Teya is proud to be an equal opportunity employer. We are committed to creating an inclusive environment where everyone regardless of race, ethnicity, gender identity or expression, sexual orientation, age, disability, religion, or background can thrive and do their best work. We believe that a diverse team leads to better ideas, stronger outcomes, and a more supportive workplace for all. If you require any reasonable adjustments at any stage of the recruitment process whether for interviews, assessments, or other parts of the application - we encourage you to let us know. We are committed to ensuring that every candidate has a fair and accessible experience with us.

Senior DevSecOps Engineer employer: Teya Services Ltd

At Teya, we pride ourselves on fostering a collaborative and inclusive work culture that empowers our employees to take ownership of their projects while balancing security with delivery velocity. With flexible working hours, comprehensive health support, and opportunities for professional growth, our Senior DevSecOps Engineers can thrive in an environment that values innovation and teamwork, all while enjoying the perks of a hybrid work model and a friendly office atmosphere.
Teya Services Ltd

Contact Detail:

Teya Services Ltd Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior DevSecOps Engineer

✨Tip Number 1

Network like a pro! Reach out to folks in your industry on LinkedIn or at meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repo showcasing your projects, especially those related to security tooling and CI/CD. It’s a great way to demonstrate your expertise without saying a word.

✨Tip Number 3

Prepare for interviews by practicing common DevSecOps questions. Think about how you’d explain your experience with SAST, DAST, and policy-as-code. Confidence is key!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive.

We think you need these skills to ace Senior DevSecOps Engineer

Security Engineering
DevSecOps
CI/CD Integration
SAST
DAST
SCA
Container Scanning
Secrets Detection
CI/CD Platforms (e.g., GitHub Actions, GitLab CI, Jenkins)
Infrastructure as Code (IaC) (e.g., Terraform)
Software Engineering
Automation Skills (Python, Go, Bash)
Cloud-Native Experience (AWS preferred)
Policy-as-Code Implementation
Cross-Functional Collaboration

Some tips for your application 🫡

Tailor Your CV: Make sure your CV reflects the skills and experiences that align with the Senior DevSecOps Engineer role. Highlight your experience with CI/CD, security tooling, and any relevant programming languages like Python or Go.

Craft a Compelling Cover Letter: Use your cover letter to tell us why you're passionate about security engineering and how you can contribute to our team. Share specific examples of past projects where you've successfully integrated security into workflows.

Showcase Your Collaboration Skills: Since this role involves working closely with various teams, emphasise your ability to collaborate and communicate effectively. Mention any cross-functional projects you've been part of and how you balanced security with delivery speed.

Apply Through Our Website: We encourage you to apply directly through our website for a smoother application process. This way, we can ensure your application gets the attention it deserves and you can easily track your progress!

How to prepare for a job interview at Teya Services Ltd

✨Know Your Tools Inside Out

Make sure you’re well-versed in the CI/CD platforms mentioned in the job description, like GitHub Actions or Jenkins. Be ready to discuss how you've integrated security checks like SAST and DAST into these pipelines in your previous roles.

✨Showcase Your Automation Skills

Prepare examples of how you've used automation to enhance security processes. Whether it's through scripting in Python or Go, or implementing policy-as-code, be ready to demonstrate your hands-on experience and the impact it had on your team's efficiency.

✨Emphasise Collaboration

This role requires working closely with various teams. Think of specific instances where you’ve successfully collaborated with platform, cloud, or AppSec teams to deliver secure solutions. Highlight your ability to balance security needs with delivery velocity.

✨Be Ready for Scenario Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Prepare to discuss how you would handle vulnerabilities in a CI/CD pipeline or how you would implement security guardrails in a cloud environment. Use metrics to back up your strategies.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>