Overview
As Senior Application Security Engineer at Teya, you will own and evolve the Secure SDLC across our fintech products to enable fast, secure delivery. You’ll partner with product, platform and security teams to shift AppSec from reactive controls to proactive, developer-first security at scale. You’ll embed security into planning, design, and production, shaping secure architectures and tooling. This is a mission-driven role at a London-based company focused on empowering small businesses through trusted technology.
Responsibilities
- Design and continuously improve a Secure SDLC spanning design to production
- Embed security into planning and delivery via threat modelling, security requirements, and automated controls
- Lead application security reviews for new systems, features, and high-risk changes across web, API, mobile, and backend services
- Define and maintain secure architecture patterns for authentication, authorisation, APIs, data protection, and multi-tenant isolation
- Own the application security tooling stack (SAST, DAST, SCA), integrating it into CI/CD with high-signal outputs
- Triage and remediate vulnerabilities with engineers based on exploitability, impact, and regulatory risk
- Improve application-level logging, telemetry, and incident readiness with Security Operations
- Advise engineering teams through practical guidance, documentation, and targeted training
Key requirements
- 6+ years in application security, security engineering, or software engineering with strong AppSec focus
- Experience designing or operating Secure SDLC in fast-moving product teams
- Hands-on web and API security expertise (authentication, authorisation, data flows, vuls)
- Proven experience integrating SAST, DAST, and SCA into CI/CD pipelines
- Strong threat modelling and secure design for cloud-native systems
- Experience with modern backend/frontend or mobile stacks (e.g. JVM, Node.js, Go, TypeScript)
- Familiarity with AWS and cloud-native architectures (IAM, KMS, containers, microservices)
- Clear, pragmatic communication and collaborative influence
- clear, pragmatic communication
- ability to influence through partnership
- low-ego collaboration
- Secure SDLC design and operation
- Threat modelling
- SAST, DAST, SCA in CI/CD
…
