Senior DevSecOps Engineer

Whereby

United States

Hybrid

USD 150,000 - 210,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity
25 days holiday
Hybrid working
Nomad working
Family leave
Private medical insurance
Mental health support
Learning budget
Cycle to work
Refer a friend
Team socials
Dog-friendly office

Job summary

Yapily in the United States is seeking a Senior DevSecOps Engineer to embed security across the Software Development Lifecycle on a high-availability, multi-tenant GCP Kubernetes platform. You will own security tooling, automate compliance checks, harden IAM and network policies, and partner with engineering to deploy secure services via guardrails in CI/CD pipelines.

If you bring hands-on cloud security, Terraform or OpenTofu, CSPM tools, and automation in Python or Go, you’ll help us scale

Qualifications

  • Deep practical experience designing, managing, and securing high-availability infrastructure in GCP.
  • Proven ability to design, implement and enforce automated security guardrails across CI/CD and cloud environments.
  • Experience in securing Kubernetes (GKE) clusters, IAM, network policies, and secret management.

Responsibilities

  • Own Security Tooling: selecting, integrating, and maintaining tooling in environments and CI/CD pipelines.
  • Engineering Security Guardrails: design, implement, enforce automated guardrails and policies across cloud and CI/CD.
  • GCP Security Focus: hardening IAM, network security, and resource configurations in Google Cloud.
  • Compliance Automation: translate requirements into automated, verifiable infrastructure and deployment practices.
  • Vulnerability & Patch Management: automate end-to-end processes to identify, triage, and remediate vulnerabilities.
  • Developer Empowerment: build golden paths for secure service deployment and safe code rollout.

Skills

Cloud security (GCP)
Kubernetes security
API security
IaC (Terraform/OpenTofu)
Security tooling
Automation scripting (Python/Golang/S
CI/CD guardrails

Tools

Terraform
OpenTofu
Aqua Security
Falco
Prisma Cloud
GitLab CI
GitHub Actions

Job description

Who are Yapily

Why we exist, and where we’re headed: Our Mission: Redefining how the world interacts with value.

Our Vision: A world without financial friction

Our Purpose: To empower everyone to access and move value Our open banking platform powers leading companies, such as Adyen, Intuit QuickBooks, and Google. By delivering payment initiation, bank data access, and pre-built products, we enable businesses to innovate fast and push the boundaries of financial technology.

As an early pioneer of open banking, we’re actively shaping the future of this industry with unrivalled expertise and a relentless focus on innovation.

What We Are Looking For

As a Senior DevSecOps Engineer, you will be a key driver in integrating security into every phase of our Software Development Lifecycle (SDLC). You will join a high-impact team, responsible for securing our highly available, multi-tenant platform built primarily on GCP and Kubernetes.

This role requires a proactive and automated approach to security—you will be laying down the foundational security posture, automating compliance checks, and ensuring we not only meet but exceed the security requirements necessary for regulated financial services.

Requirements

Responsibilities: Secure Infrastructure & Compliance

As a Senior DevSecOps Engineer, you will be responsible for:

  • Owning Security Tooling: Selecting, integrating, and maintaining security tooling both within our environments and in our CI/CD pipelines
  • Engineering Security Guardrails: Designing, implementing, and enforcing automated security guardrails and policies across our entire cloud estate and CI/CD pipeline.
  • GCP Security Focus: Hardening and securing our Google Cloud Platform environment, including IAM policies, network security and resource configuration management.
  • Compliance Automation: Working closely with compliance and governance teams to translate requirements into automated, verifiable infrastructure and deployment practices.
  • Vulnerability & Patch Management: Automating and managing the end-to-end process for identifying, triaging, and working with the engineering teams to remediate security vulnerabilities in infrastructure, applications, and third-party dependencies.
  • Developer Empowerment: Building and maintaining "golden path" templates for secure service deployment, enabling feature teams to confidently and safely push code without compromising security.

Incident Response: Contributing expertise to the security incident response team, helping to swiftly and effectively manage and resolve security events.

What You Bring (Essential Skills)
  • Cloud Architecture & Security: Deep, practical experience designing, managing, and securing high-availability infrastructure within GCP.
  • API security: Proficient in reviewing, providing patterns and upskilling engineers to provide a secure API interface.
  • Kubernetes Security Proficiency: Expert knowledge of deploying, operating, and hardening Kubernetes (GKE) clusters, including network policies, container runtime security, and secrets management.
  • Infrastructure as Code (IaC): Solid skills in writing, securing, and testing configuration using Terraform or OpenTofu.
  • Security Tooling Expertise: Hands-on experience deploying and managing key security tools (e.g., Aqua Security, Falco, Prisma Cloud, or similar CSPM/CWPP/CNAPP solutions).
  • Automation & Scripting: Proficient in at least one relevant language (Python, Golang, or Shell) for developing security automation and workflow tooling.
  • CI/CD Guardrails: Proven ability to build secure, repeatable, and robust deployment pipelines (e.g., GitLab CI, GitHub Actions) that integrate mandatory security checks.
Impress Us More By Having (Desirable)
  • Proven experience working with and adhering to FinTech-related certifications, standards, or frameworks such as SOC2, ISO 27001, PCI DSS, DORA or similar regulated environments.
  • Relevant certifications such as Google Cloud Professional Security Engineer, CKS (Certified Kubernetes Security Specialist), or CISSP.

Benefits

Why You’ll Love Working With Us
  • Competitive Pay & Equity – We offer a great base salary plus equity, so you’ll own a part of what we’re building together.
  • Generous Time Off – Enjoy 25 days of holiday each year (plus bank holidays if you’re in the UK), and earn an extra day each year after your first, up to 5 more!
  • Hybrid Working – Life’s about balance. you can work from home up to 3 days a week, eligibility criteria applies.
  • Nomad Working – Feel like a change of scenery? Work from anywhere for up to 20 days each year.
  • Family First – We offer enhanced Maternity and Paternity leave because your family matters
  • Private Medical Insurance – You’ll get top-notch cover through BUPA, because your health is a priority.
  • Mental Health Support – Access personalised mental wellness support through our award-winning partner.
  • Future-Ready Perks – Including a solid company pension, life assurance, and income protection.
  • Learn & Grow – A £200 annual budget for learning and personal development. Invest in you!
  • Cycle to Work Scheme – Commute the healthy way with support from our cycle to work programme.
  • Refer a Friend – Bring someone great onboard and earn £1,000 with our referral scheme.
  • Team Vibes – Monthly socials, team lunches, and a budget to hang out and have fun (yes, pizza included ).
  • Office Snacks & Doggies – Daily snacks to keep you going, and yes – we’re proudly a dog-friendly office.
Our Values

We obsess about quality

  • Our customers have entrusted us with a critical function in a regulated industry…and we take that responsibility seriously. We always assume ownership and hold ourselves accountable.

We are curious

  • Our innovation is powered by our collective growth mindset. We’re lifelong learners who challenge assumptions, experiment, and iterate.

We act with integrity

  • We’re guided by our mission and earn and maintain trust by doing what’s right, even when it’s not easy.

We are do-ers

  • We reject indifference and agility is our strength.
  • We’re motivated by challenges, and biassed towards action.

We problem-solve together

  • We’re diverse people in diverse places, and know the best solutions are born out of collaboration. We win, lose, and learn…together.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer- Backend (Product & Cloud Security)
Senior Software Engineer- Backend (Product & Cloud Security)

Yoodli AI Roleplays • Seattle (WA)

On-site
USD 160,000 - 190,000
Equity opportunities
Security Operations Engineer
Security Operations Engineer

Yellow Card • Tulsa (OK)

On-site
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Candid Health • San Francisco (CA)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Thomson Reuters • Frisco (TX)

Hybrid
USD 140,000 - 210,000
Hybrid Work
Flexible policies
Career growth
+2
Senior Staff Software Security Engineer
Senior Staff Software Security Engineer

United States Digital Space LLC • Bellevue (CA)

On-site
USD 247,000 - 290,000
Health insurance
Equity
401(k) matching
+2
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Virtuous Management • Phoenix (AZ)

On-site
USD 120,000 - 180,000
Bonusly
401(k) with company match
Unlimited PTO
+2
Lead DevOps Engineer
Lead DevOps Engineer

Elliptic • United States

Hybrid
USD 120,000 - 160,000
Remote working budget
$1,000 Learning & Development budget
25 days of annual leave
+1
Senior Manager, Engineering - Platform Security
Senior Manager, Engineering - Platform Security

United States Digital Space LLC • Los Angeles (CA)

Hybrid
USD 228,000 - 274,000
Senior Engineer - Security Products (Backend APIs)
Senior Engineer - Security Products (Backend APIs)

United States Digital Space LLC • Denver (CO)

Hybrid
USD 181,000 - 217,000
Medical coverage
Dental coverage
Vision coverage
+2
Security Engineer – DevSecOps and Security Architect New York, New York
Security Engineer – DevSecOps and Security Architect New York, New York

PhysicsX Ltd. • New York (NY), Northern (KY)

Hybrid
USD 200,000 - 300,000
Equity options
Pension contributions
25 days holiday plus public holidays
+7