Senior Security Engineer Crypto
Teya
| Company | Teya |
| Category | Engineering |
| Location | London |
| Remote | Hybrid |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 4 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
Hello. We’re Teya.
Teya was founded on a simple belief: local businesses deserve better.
They are the cafés, restaurants, salons, shops and entrepreneurs that bring character to our high streets, create jobs and keep communities moving. Yet for too long, financial services has made life harder for them - with clunky tools, poor support and complexity that gets in the way of running a business.
Teya exists to change that.
We’re building a financial platform for local businesses across Europe - one built around simple tools, thoughtful design and real human support. Our Members rely on us to help them run their business with confidence, and that responsibility shapes the way we work.
We move fast. We care about quality. We stay close to the detail. And we believe great performance and genuine hospitality should go hand in hand.
If you want to build meaningful products, solve real problems and make a genuine difference for local businesses, we’d love to hear from you
YOUR MISSION
We're a regulated payments fintech operating across multiple European markets, scaling into banking-licence territory. Security Engineering is being rebuilt around a joint operating model with our platform and infrastructure teams. We're hiring a Senior Security Engineer who can pick up specific gaps in our current coverage: payment cryptography operations on cloud-hosted HSM services, application security at scale, and pipeline-embedded controls that let the rest of the company move fast without security sitting in the critical path.
This is not a review-queue role. We're not looking for another pair of hands doing manual pen tests, PR reviews, or spreadsheet audits. We want an engineer who builds, someone who writes production-quality Go, ships services, and turns manual security work into platforms other teams operate against.
RESPONSIBILITIES
- Design, implement, and continuously improve a Secure SDLC integrated from design through production
- Embed security into planning and delivery via threat modelling, security requirements, and automated controls
- Lead application security reviews for new systems, major features, and high-risk changes across web, API, mobile, and backend services
- Define and maintain secure architecture patterns for authentication, authorisation, APIs, data protection, and multi-tenant isolation
- Own the application security tooling stack (SAST, DAST, SCA), integrating it into CI/CD with high-signal, low-noise outputs
- Partner with engineers to triage and remediate vulnerabilities based on exploitability, impact, and regulatory risk
- Work with Security Operations to improve application-level logging, telemetry, and incident response readiness
- Act as a trusted advisor to engineering teams, raising the bar through practical guidance, documentation, and targeted training
REQUIREMENTS
- 5+ years in security engineering. With a demonstrable track record of shipping platforms, not just performing reviews or writing policy.
- Production Go experience. You should be comfortable designing, writing, testing, and shipping production Go services. Our platform is Go-native and we build our security tooling in the same stack. Applications without production Go will not progress.
- Software engineering fundamentals. Version control, code review, testing, CI/CD, observability, on-call for services you've built. You are an engineer who does security, not a security person who occasionally scripts.
- Payment cryptography operations. Hands-on experience with payment HSM services (cloud- hosted such as VirtuCrypt, AWS CloudHSM, Google Cloud HSM; or on-prem operated as a service). Payment key management including PIN keys, DUKPT, master/session key hierarchies, and TR-31 or TR-34 key exchange.
- Experience with key lifecycle management, PCI PIN and PCI-DSS scope experience is required.
- Application security at scale. SAST/DAST/SCA toolchain design and rollout. Threat modelling as a routin
1,014,484 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →