At a Glance
- Tasks: Secure our innovative open banking platform and automate security processes.
- Company: Yapily, a leader in open banking infrastructure with a focus on innovation.
- Benefits: Competitive salary, equity, generous time off, and hybrid working options.
- Why this job: Join a high-impact team and shape the future of financial technology.
- Qualifications: Experience in cloud security, Kubernetes, and automation scripting required.
- Other info: Enjoy a vibrant culture with monthly socials, snacks, and a dog-friendly office.
The predicted salary is between 48000 - 84000 ÂŁ per year.
Who are Yapily? Why we exist, and where weâre headed:
Our Mission: Redefining how the world interacts with value.
Our Vision: A world without financial friction.
Our Purpose: To empower everyone to access and move value.
At Yapily, weâre building a powerful, scalable, and secure open banking infrastructure that redefines how the world interacts with value. Our open banking platform powers leading companies, such as Adyen, Intuit QuickBooks, and Google. By delivering payment initiation, bank data access, and pre-built products, we enable businesses to innovate fast and push the boundaries of financial technology. As an early pioneer of open banking, weâre actively shaping the future of this industry with unrivalled expertise and a relentless focus on innovation.
What We Are Looking For
As a Senior DevSecOps Engineer, you will be a key driver in integrating security into every phase of our Software Development Lifecycle (SDLC). You will join a high-impact team, responsible for securing our highly available, multi-tenant platform built primarily on GCP and Kubernetes. This role requires a proactive and automated approach to securityâyou will be laying down the foundational security posture, automating compliance checks, and ensuring we not only meet but exceed the security requirements necessary for regulated financial services.
Responsibilities:
- Secure Infrastructure & Compliance: Owning Security Tooling: Selecting, integrating, and maintaining security tooling both within our environments and in our CI/CD pipelines.
- Engineering Security Guardrails: Designing, implementing, and enforcing automated security guardrails and policies across our entire cloud estate and CI/CD pipeline.
- GCP Security Focus: Hardening and securing our Google Cloud Platform environment, including IAM policies, network security and resource configuration management.
- Compliance Automation: Working closely with compliance and governance teams to translate requirements into automated, verifiable infrastructure and deployment practices.
- Vulnerability & Patch Management: Automating and managing the end-to-end process for identifying, triaging, and working with the engineering teams to remediate security vulnerabilities in infrastructure, applications, and third-party dependencies.
- Developer Empowerment: Building and maintaining 'golden path' templates for secure service deployment, enabling feature teams to confidently and safely push code without compromising security.
- Incident Response: Contributing expertise to the security incident response team, helping to swiftly and effectively manage and resolve security events.
What You Bring (Essential Skills)
- Cloud Architecture & Security: Deep, practical experience designing, managing, and securing high-availability infrastructure within GCP.
- API Security: Proficient in reviewing, providing patterns and upskilling engineers to provide a secure API interface.
- Kubernetes Security Proficiency: Expert knowledge of deploying, operating, and hardening Kubernetes (GKE) clusters, including network policies, container runtime security, and secrets management.
- Infrastructure as Code (IaC): Solid skills in writing, securing, and testing configuration using Terraform or OpenTofu.
- Security Tooling Expertise: Hands-on experience deploying and managing key security tools (e.g., Aqua Security, Falco, Prisma Cloud, or similar CSPM/CWPP/CNAPP solutions).
- Automation & Scripting: Proficient in at least one relevant language (Python, Golang, or Shell) for developing security automation and workflow tooling.
- CI/CD Guardrails: Proven ability to build secure, repeatable, and robust deployment pipelines (e.g., GitLab CI, GitHub Actions) that integrate mandatory security checks.
Impress Us More By Having (Desirable)
- Proven experience working with and adhering to FinTech-related certifications, standards, or frameworks such as SOC2, ISO 27001, PCI DSS, DORA or similar regulated environments.
- Relevant certifications such as Google Cloud Professional Security Engineer, CKS (Certified Kubernetes Security Specialist), or CISSP.
Why Youâll Love Working With Us
- Competitive Pay & Equity â We offer a great base salary plus equity, so youâll own a part of what weâre building together.
- Generous Time Off â Enjoy 25 days of holiday each year (plus bank holidays if youâre in the UK), and earn an extra day each year after your first, up to 5 more!
- Hybrid Working â Lifeâs about balance. You can work from home up to 3 days a week, eligibility criteria applies.
- Nomad Working â Feel like a change of scenery? Work from anywhere for up to 20 days each year.
- Family First â We offer enhanced Maternity and Paternity leave because your family matters.
- Private Medical Insurance â Youâll get top-notch cover through BUPA, because your health is a priority.
- Mental Health Support â Access personalised mental wellness support through our award-winning partner.
- Future-Ready Perks â Including a solid company pension, life assurance, and income protection.
- Learn & Grow â A ÂŁ200 annual budget for learning and personal development. Invest in you!
- Cycle to Work Scheme â Commute the healthy way with support from our cycle to work programme.
- Refer a Friend â Bring someone great onboard and earn ÂŁ1,000 with our referral scheme.
- Team Vibes â Monthly socials, team lunches, and a budget to hang out and have fun (yes, pizza included đ).
- Office Snacks & Doggies â Daily snacks to keep you going, and yes â weâre proudly a dog-friendly office đž.
Our Values
- We obsess about quality. Our customers have entrusted us with a critical function in a regulated industryâŚand we take that responsibility seriously. We always assume ownership and hold ourselves accountable.
- We are curious. Our innovation is powered by our collective growth mindset. Weâre lifelong learners who challenge assumptions, experiment, and iterate.
- We act with integrity. Weâre guided by our mission and earn and maintain trust by doing whatâs right, even when itâs not easy.
- We are do-ers. We reject indifference and agility is our strength. Weâre motivated by challenges, and biased towards action.
- We problem-solve together. Weâre diverse people in diverse places, and know the best solutions are born out of collaboration. We win, lose, and learnâŚtogether.
Senior DevSecOps Engineer employer: Yapily
Contact Detail:
Yapily Recruiting Team
StudySmarter Expert Advice đ¤Ť
We think this is how you could land Senior DevSecOps Engineer
â¨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with current employees at Yapily. A friendly chat can sometimes lead to opportunities that arenât even advertised!
â¨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your DevSecOps projects. This gives you a chance to demonstrate your expertise in GCP, Kubernetes, and security tooling directly to the hiring team.
â¨Tip Number 3
Prepare for the interview by brushing up on common DevSecOps scenarios. Think about how you would handle security incidents or automate compliance checks. We want to see your problem-solving skills in action!
â¨Tip Number 4
Donât forget to apply through our website! Itâs the best way to ensure your application gets seen by the right people. Plus, it shows youâre genuinely interested in being part of the Yapily team.
We think you need these skills to ace Senior DevSecOps Engineer
Some tips for your application đŤĄ
Tailor Your CV: Make sure your CV is tailored to the Senior DevSecOps Engineer role. Highlight your experience with GCP, Kubernetes, and security tooling. We want to see how your skills align with our mission of redefining financial interactions!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Share your passion for open banking and how you can contribute to our vision. Let us know why youâre excited about the role and what makes you a great fit for Yapily.
Showcase Your Projects: If you've worked on relevant projects, donât hold back! Include links or descriptions of your work that demonstrate your expertise in security automation and CI/CD pipelines. We love seeing practical examples of your skills in action.
Apply Through Our Website: We encourage you to apply directly through our website. Itâs the best way for us to receive your application and ensures youâre considered for the role. Plus, it shows youâre keen on joining our team at Yapily!
How to prepare for a job interview at Yapily
â¨Know Your Tech Inside Out
Make sure youâre well-versed in the technologies mentioned in the job description, especially GCP, Kubernetes, and security tooling. Brush up on your knowledge of API security and Infrastructure as Code (IaC) practices, as these will likely come up during technical discussions.
â¨Showcase Your Problem-Solving Skills
Prepare to discuss specific challenges you've faced in previous roles, particularly around security incidents or compliance automation. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight how you tackled these issues effectively.
â¨Demonstrate Your Collaborative Spirit
Yapily values teamwork, so be ready to share examples of how youâve worked with cross-functional teams. Discuss how youâve empowered developers with security guardrails or contributed to incident response efforts, showcasing your ability to work together towards a common goal.
â¨Ask Insightful Questions
Prepare thoughtful questions that show your interest in Yapilyâs mission and vision. Inquire about their approach to innovation in open banking or how they handle security challenges in a multi-tenant environment. This not only demonstrates your enthusiasm but also helps you gauge if the company aligns with your values.