远程工作雷达

高级安全工程师,加密货币

Senior Security Engineer Crypto

开发工程未标注地域
公司teya
薪资未公开
工作地点London / Porto / Riga
地域资格未标注地域
时区要求无特别要求
用工类型FullTime
发布时间2026-07-04
数据来源Ashby
前往企业招聘页投递 →

Hello. 我们是Teya。

Teya的创立基于一个简单的信念:本地企业值得更好的服务。

它们是咖啡馆、餐厅、美发店、商店和创业者,为我们的街道带来特色,创造就业机会并维持社区运转。然而,长期以来,金融服务让它们的生活变得更难——工具笨拙、支持差、复杂性阻碍了业务的正常运行。

Teya的存在就是要改变这一现状。

我们正在为欧洲各地的本地企业打造一个金融平台——以简单工具、周到设计和真正的客户服务为核心。我们的会员依赖我们帮助他们自信地经营业务,而这种责任塑造了我们的工作方式。

我们行动迅速。我们重视质量。我们关注细节。我们相信卓越的表现与真诚的服务应相辅相成。

如果你希望打造有意义的产品,解决真实的问题,并为本地企业带来真正的改变,我们期待你的加入。

你的使命

我们是一家在多个欧洲市场运营的持牌支付金融科技公司,正扩展至银行牌照领域。安全工程正在围绕与平台和基础设施团队的联合运营模式进行重建。我们正在招聘一名高级安全工程师,能够填补我们当前覆盖范围中的特定缺口:云托管HSM服务上的支付加密操作、大规模应用安全以及嵌入流水线的控制机制,使公司其他团队可以快速前进,而无需安全流程成为关键路径。

这不是一个审查队列的角色。我们不寻找另一个做手动渗透测试、PR审查或电子表格审计的“人手”。我们需要一位工程师,一位能构建产品的人,一位能编写高质量Go代码、发布服务,并将手动安全工作转化为其他团队可操作的平台的人。

职责

- 设计、实施并持续改进从设计到生产阶段的集成安全SDLC

- 通过威胁建模、安全需求和自动化控制,将安全嵌入规划和交付

- 领导新系统、主要功能和高风险变更的安全评审,涵盖网页、API、移动端和后端服务

- 定义并维护安全架构模式,包括认证、授权、API、数据保护和多租户隔离

- 负责应用安全工具栈(SAST、DAST、SCA),将其集成到CI/CD中,输出信号强、噪音低的结果

- 合作

查看英文原文

Hello. We’re Teya.

Teya was founded on a simple belief: local businesses deserve better.

They are the cafés, restaurants, salons, shops and entrepreneurs that bring character to our high streets, create jobs and keep communities moving. Yet for too long, financial services has made life harder for them - with clunky tools, poor support and complexity that gets in the way of running a business.

Teya exists to change that.

We’re building a financial platform for local businesses across Europe - one built around simple tools, thoughtful design and real human support. Our Members rely on us to help them run their business with confidence, and that responsibility shapes the way we work.

We move fast. We care about quality. We stay close to the detail. And we believe great performance and genuine hospitality should go hand in hand.

If you want to build meaningful products, solve real problems and make a genuine difference for local businesses, we’d love to hear from you

YOUR MISSION

We're a regulated payments fintech operating across multiple European markets, scaling into banking-licence territory. Security Engineering is being rebuilt around a joint operating model with our platform and infrastructure teams. We're hiring a Senior Security Engineer who can pick up specific gaps in our current coverage: payment cryptography operations on cloud-hosted HSM services, application security at scale, and pipeline-embedded controls that let the rest of the company move fast without security sitting in the critical path.

This is not a review-queue role. We're not looking for another pair of hands doing manual pen tests, PR reviews, or spreadsheet audits. We want an engineer who builds, someone who writes production-quality Go, ships services, and turns manual security work into platforms other teams operate against.

RESPONSIBILITIES

- Design, implement, and continuously improve a Secure SDLC integrated from design through production

- Embed security into planning and delivery via threat modelling, security requirements, and automated controls

- Lead application security reviews for new systems, major features, and high-risk changes across web, API, mobile, and backend services

- Define and maintain secure architecture patterns for authentication, authorisation, APIs, data protection, and multi-tenant isolation

- Own the application security tooling stack (SAST, DAST, SCA), integrating it into CI/CD with high-signal, low-noise outputs

- Partner with engineers to triage and remediate vulnerabilities based on exploitability, impact, and regulatory risk

- Work with Security Operations to improve application-level logging, telemetry, and incident response readiness

- Act as a trusted advisor to engineering teams, raising the bar through practical guidance, documentation, and targeted training

REQUIREMENTS

- 5+ years in security engineering. With a demonstrable track record of shipping platforms, not just performing reviews or writing policy.

- Production Go experience. You should be comfortable designing, writing, testing, and shipping production Go services. Our platform is Go-native and we build our security tooling in the same stack. Applications without production Go will not progress.

- Software engineering fundamentals. Version control, code review, testing, CI/CD, observability, on-call for services you've built. You are an engineer who does security, not a security person who occasionally scripts.

- Payment cryptography operations. Hands-on experience with payment HSM services (cloud- hosted such as VirtuCrypt, AWS CloudHSM, Google Cloud HSM; or on-prem operated as a service). Payment key management including PIN keys, DUKPT, master/session key hierarchies, and TR-31 or TR-34 key exchange.

- Experience with key lifecycle management, PCI PIN and PCI-DSS scope experience is required.

- Application security at scale. SAST/DAST/SCA toolchain design and rollout. Threat modelling as a routine practice, not an event. Familiarity with modern AppSec tooling (Snyk, Wiz, Veracode, Checkmarx, Semgrep, GitHub Advanced Security or equivalents).

- Cloud security depth on AWS. IAM design, workload identity, network isolation, and integration patterns between application workloads and HSM-backed key services.

- Written communication. You will publish runbooks, standards, ADRs, and reporting dashboards. If it isn't documented, it didn't happen.

- Comfort with a small team carrying real regulatory scope. PCI-DSS, PCI PIN, DORA and GDPR are constraints on the work, not optional context.

Nice to have:

- Open source contributions or side projects, we would like to see how you write code before the technical interview.

- Payments industry experience (card acquiring, issuing, PIN, EMV, terminal fleet operations).

- Regulated fintech environment (FCA, ECB, or equivalent supervisory scope).

WAYS OF WORKING

- Out-of-band, non-blocking. We embed in the pipeline, we do not sit in the critical path.

- Skin in the game is shared. Application owners own their app's security posture. We provide the patterns, tooling, and verification.

- Automation first. If you're doing something manually more than twice, you automate or you hand it back to the owning team.

- Public requests, not DMs. All work in the open. Backlog visible. Decisions logged.

- Ways of working matter. Defined split between roadmap, keep-the-lights-on, and unplanned work. We push back on unplanned demand with reasons

The Perks

- We trust you, so we offer flexible working hours, as long it suits both you and your team;

- Health Insurance;

- Physical and mental health support through our partnership with MyFitness;

- 25 days of Annual leave (+ Bank Holidays);

- Possibility to visit other Teya offices to meet colleagues in instances when travel is safe and appropriate;

- Friday lunch in the office;

- Friendly, comfortable and high-end work equipment and informal office environment;

- Hybrid work mode policy.

Teya is proud to be an equal opportunity employer.

We are committed to creating an inclusive environment where everyone regardless of race, ethnicity, gender identity or expression, sexual orientation, age, disability, religion, or background can thrive and do their best work. We believe that a diverse team leads to better ideas, stronger outcomes, and a more supportive workplace for all.

If you require any reasonable adjustments at any stage of the recruitment process whether for interviews, assessments, or other parts of the application—we encourage you to let us know. We are committed to ensuring that every candidate has a fair and accessible experience with us.

本页面信息整理自 Ashby,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位