SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior DevSecOps Engineer

Yapily - London, England, United Kingdom - Hybrid - posted 2026-09-17

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Yapily is an open banking infrastructure platform powering leading companies like Adyen, Intuit QuickBooks, and Google. The company's mission is to redefine how the world interacts with value by eliminating financial friction and enabling secure, scalable access to financial services. As a Senior DevSecOps Engineer, you will be a key driver in integrating security into every phase of the Software Development Lifecycle (SDLC). You will join a high-impact team responsible for securing Yapily's highly available, multi-tenant platform built primarily on Google Cloud Platform (GCP) and Kubernetes. This role requires a proactive, automated approach to security—you will establish foundational security posture, automate compliance checks, and ensure the platform meets and exceeds security requirements for regulated financial services. Key Responsibilities: - Own security tooling selection, integration, and maintenance across environments and CI/CD pipelines - Design and implement automated security guardrails and policies across the entire cloud estate and deployment pipeline - Harden and secure the GCP environment, including IAM policies, network security, and resource configuration management - Work with compliance and governance teams to translate regulatory requirements into automated, verifiable infrastructure and deployment practices - Automate and manage vulnerability identification, triage, and remediation across infrastructure, applications, and third-party dependencies - Build and maintain "golden path" templates for secure service deployment, enabling feature teams to deploy safely without compromising security - Contribute expertise to the security incident response team for swift and effective management of security events The role offers hybrid working (up to 3 days per week from home), 25 days holiday annually plus bank holidays, nomad working (up to 20 days per year), enhanced maternity/paternity leave, private medical insurance through BUPA, mental health support, company pension, life assurance, income protection, £200 annual learning budget, and a dog-friendly office environment. Requirements: - Deep, practical experience designing, managing, and securing high-availability infrastructure within GCP - Proficiency in API security review, pattern design, and engineer upskilling - Expert knowledge of deploying, operating, and hardening Kubernetes (GKE) clusters, including network policies, container runtime security, and secrets management - Solid skills in Infrastructure as Code (IaC) using Terraform or OpenTofu - Hands-on experience deploying and managing security tools (e.g., Aqua Security, Falco, Prisma Cloud, or similar CSPM/CWPP/CNAPP solutions) - Proficiency in at least one scripting language (Python, Golang, or Shell) for security automation and workflow tooling - Proven ability to build secure, repeatable, and robust deployment pipelines (e.g., GitLab CI, GitHub Actions) with mandatory security checks Desirable: - Proven experience with FinTech-related certifications, standards, or frameworks such as SOC2, ISO 27001, PCI DSS, DORA, or similar regulated environments - Relevant certifications such as Google Cloud Professional Security Engineer, CKS (Certified Kubernetes Security Specialist), or CISSP

Similar roles