
Motorway · London
ABOUT MOTORWAY Motorway is the UK’s fastest-growing used car marketplace - our online-only platform connects private car sellers with thousands of verified dea...
Motorway is the UK’s fastest-growing used car marketplace - our online-only platform connects private car sellers with thousands
of verified dealers nationwide, ensuring everyone gets the best deal. Founded in 2017, our award-winning, technology-led approach
has redefined the experience of selling a car. Motorway is backed by some of the world’s leading technology investors, having
raised £143 million in Series C funding.
This is a unique opportunity to join a fast-growing scale-up at a crucial phase of growth and help change an industry for the
better.
About the role
Motorway is rapidly growing its technology team and business, and we are looking for a Developer Experience Security Engineer to
help enable a secure, scalable, and frictionless developer experience across Motorway.
We have recently built and rolled out a new container platform on top of AWS Fargate, and are currently enhancing our
observability, reliability, and developer-focused tooling, and developer-focused tooling. We will continue to build and evolve
secure, standardised platform capabilities that reduce cognitive load and help teams ship faster with confidence.We will continue
to build and evolve secure, standardised platform capabilities that reduce cognitive load and help teams ship faster with
confidence.
This role will act as a bridge between the Developer Experience team and Security Operations team, ensuring security strategy is
embedded into platform abstractions, tooling, and defaults.This role will act as a bridge between the Developer Experience team
and Security Operations team, ensuring security strategy is embedded into platform abstractions, tooling, and defaults.
As a Security Developer Experience Security Developer Experience Security Engineer, you will ensure that security is built into
how engineers build, deploy, and operate software, making the secure path the easiest path you will ensure that security is built
into how engineers build, deploy, and operate software, making the secure path the easiest path
management, runtime protections, encryption) that are easy for product teams to adopt.Design, implement, and maintain
secure-by-default platform capabilities (e.g. IAM patterns, network primitives, secrets management, runtime protections,
encryption) that are easy for product teams to adopt.).
security audits.
s(Shift left and Secure by design principles).
tooling).
capability for all teams.
without bespoke configuration
appropriate.
Requirements
WE ENCOURAGE YOU TO APPLY, EVEN IF YOU MIGHT NOT MEET ALL THE REQUIREMENTS. YOU’LL BE DIRECTLY REPORTING TO AN ENGINEERING
pay) to eligible employees.
We are committed to equality of opportunity for all employees. We work to provide a supportive and inclusive environment where
people can maximise their full potential. We believe our workforce should reflect a variety of backgrounds, talents, perspectives
and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing
and advancing individuals based on their skills and talents.
We welcome applications from all individuals regardless of age, disability, sex, gender reassignment, sexual orientation,
pregnancy and maternity, race, religion or belief and marriage and civil partnerships.
Hello. We’re Teya. Teya was founded on a simple belief: local businesses deserve better. They are the cafés, restaurants, salons, shops and entrepreneurs that bring character to our high streets, create jobs and keep communities moving. Yet for too long, financial services has made life harder for them - with clunky tools, poor support and complexity that gets in the way of running a business. Teya exists to change that. We’re building a financial platform for local businesses across Europe - one built around simple tools, thoughtful design and real human support. Our Members rely on us to help them run their business with confidence, and that responsibility shapes the way we work. We move fast. We care about quality. We stay close to the detail. And we believe great performance and genuine hospitality should go hand in hand. If you want to build meaningful products, solve real problems and make a genuine difference for local businesses, we’d love to hear from you YOUR MISSION As a Senior DevSecOps Engineer (Security Tooling & Enablement), you will be responsible for embedding automated security controls and guardrails into our CI/CD pipelines, cloud platforms, and developer workflows. You’ll build and operate internal security tooling and integrations that enable secure delivery at scale—focusing on automation, low-friction developer experience, and high-quality security feedback loops. You will partner closely with platform, cloud, AppSec, and SecOps teams to deliver scalable, reliable, and friction-reducing security capabilities across the engineering organisation. RESPONSIBILITIES Security in CI/CD & Delivery Workflows * Integrate and maintain security checks (SAST, DAST, SCA, secrets scanning) into CI/CD pipelines. * Provide fast, actionable, low-noise feedback to developers. * Embed infrastructure and application scanning into automated deployments. Security Tooling & Platform Engineering * Design, build, and operate internal security services, APIs, CLIs, and automation workflows. * Apply strong software engineering practices to security tooling (testing, observability, version control). * Treat security tooling as a product with clear documentation and support. Policy-as-Code & Guardrails * Implement and maintain policy-as-code guardrails for IaC, Kubernetes manifests, cloud accounts and identity configurations. * Work with platform teams to define secure defaults and self-service patterns. Platform Security & Detection Pipelines * Support vulnerability scanning platforms and security telemetry pipelines. * Ensure high-quality structured security data flows to SIEM/log platforms. * Enable automated response actions via integrations and runbooks. DevSecOps Culture & Enablement * Champion secure engineering practices and a shared responsibility mindset. * Drive enablement activities (office hours, guides, training) to improve adoption of secure patterns. * Contribute to blameless post-incident reviews and continuous improvement. Automation, AI & Operational Metrics * Leverage automation and AI to reduce manual toil and enrich security findings. * Define and track metrics such as time-to-feedback, signal-to-noise, and tooling adoption. REQUIREMENTS * 5+ years in security engineering, DevSecOps, or platform engineering with significant security integration experience. * Hands-on experience embedding security into CI/CD (SAST/DAST/SCA, container scanning, secrets detection). * Proficiency with CI/CD platforms (e.g., GitHub Actions, GitLab CI, Jenkins) and IaC (e.g., Terraform). * Strong software engineering and automation skills (Python, Go, Bash, or similar). * Deep cloud-native experience (AWS preferred), including IAM, networking, and logging. * Experience designing and implementing policy-as-code and security guardrails. * Ability to collaborate cross-functionally, balancing security with delivery velocity. Nice-to-Haves * Experience in fintech or regulated environments. * Familiarity with WAF/DDoS tools, Zero Trust, and vulnerability management programmes. * Exposure to SOAR or security automation platforms. * Relevant certifications (AWS Security, Kubernetes Security, GIAC, CISSP, etc.). WAYS OF WORKING * Extreme ownership: You take end-to-end responsibility for outcomes, not just findings or tooling output * Pragmatic and delivery-aware: You balance risk reduction with product velocity, focusing on changes that materially reduce risk * Low-ego and collaborative: You build trust with engineers, product, and operations teams, influencing through credibility and partnership * Impact-driven: You measure success through outcomes—risk reduction, adoption, and time-to-remediate—not activity * Data-informed: You use metrics and trends to guide priorities and demonstrate impact * High bar for craft: You produce clear documentation, reusable patterns, and automation that scale across teams * AI-first mindset: You actively look for opportunities to use automation and AI to improve security outcomes The Perks * We trust you, so we offer flexible working hours, as long it suits both you and your team; * Health Insurance; * Physical and mental health support through our partnership with MyFitness; * 25 days of Annual leave (+ Bank Holidays); * Possibility to visit other Teya offices to meet colleagues in instances when travel is safe and appropriate; * Friday lunch in the office; * Friendly, comfortable and high-end work equipment and informal office environment; * Hybrid work mode policy. Teya is proud to be an equal opportunity employer. We are committed to creating an inclusive environment where everyone regardless of race, ethnicity, gender identity or expression, sexual orientation, age, disability, religion, or background can thrive and do their best work. We believe that a diverse team leads to better ideas, stronger outcomes, and a more supportive workplace for all. If you require any reasonable adjustments at any stage of the recruitment process whether for interviews, assessments, or other parts of the application—we encourage you to let us know. We are committed to ensuring that every candidate has a fair and accessible experience with us.
About us We are champions of rail, inspired to build a greener, more sustainable future of travel. Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels. Great journeys start with Trainline 🚄 Now Europe’s number 1 downloaded rail app, with over 135 million monthly visits and £6.3 billion in annual ticket sales, we collaborate with 270+ rail and coach companies in over 40 countries. We want to create a world where travel is as simple, seamless, eco-friendly and affordable as it should be. Today, we're a FTSE 250 company driven by our incredible team of over 1,000 Trainliners from 50+ nationalities, based across London, Paris, Barcelona, Milan, Edinburgh and Madrid. With our focus on growth in the UK and Europe, now is the perfect time to join us on this high-speed journey. INTRODUCING THE TRAINLINE CLOUD NATIVE DEVELOPER EXPERIENCE TEAM At Trainline, we're evolving the platform that powers millions of journeys across Europe. As part of our Cloud Native Acceleration Programme, we're modernising our backend services to create a more scalable, resilient and efficient engineering platform. This programme is about more than migrating workloads. It's an opportunity to redefine how .NET services are built, deployed and operated, helping teams deliver faster while improving reliability and reducing operational complexity. As a Senior C# Engineer, you'll play a key role in shaping our cloud-native engineering standards. Working closely with Platform Engineering, Infrastructure, Security and product development teams, you'll modernise existing services, build reusable patterns and develop automation that accelerates engineering across the organisation. Your work will have a lasting impact on both the developer experience and the resilience of our platform. Success in this role is measured not only by modernising services, but by raising engineering capability across Trainline through reusable tooling, technical leadership, collaboration and the adoption of cloud-native engineering practices and by the ability to collaborate across the organisation. IN THIS ROLE AS THE SENIOR C# ENGINEER, YOU WILL... * Modernise existing .NET services by containerising applications for Amazon ECS, removing legacy infrastructure dependencies and optimising services for cloud-native operation. * Design and build resilient distributed systems by improving health checks, fault tolerance, observability and runtime behaviour to enhance service reliability and reduce operational incidents. * Define and evolve the .NET migrations by creating reusable service templates, engineering standards and best practices covering dependency injection, configuration, logging, monitoring and deployment. * Develop automation and AI-assisted tooling that accelerates cloud migration by analysing existing services, identifying modernisation opportunities and generating infrastructure and deployment scaffolding. * Optimise containerised workloads to improve performance, resource utilisation and scalability, helping teams deliver efficient, cost-effective services at scale. * Partner with engineering teams across Trainline to drive adoption of cloud-native engineering practices, influence technical direction and build consensus around modernisation approaches that enable successful service migrations. * Contribute to the continuous improvement of CI/CD pipelines and deployment processes, enabling faster, safer and more consistent software delivery. * Champion cloud-native engineering through technical leadership, documentation, design reviews, demos, mentoring and engineering community engagement, helping teams adopt consistent engineering practices with confidence. WE'D LOVE TO HEAR FROM YOU IF YOU HAVE... CORE SKILLS * Strong professional experience developing applications with C# and .NET, alongside a solid understanding of software engineering principles and modern backend architecture. * A good understanding of distributed systems, including resilience patterns, observability, scalability and performance optimisation. * Experience designing reusable engineering patterns, frameworks or shared libraries that improve consistency and developer experience across multiple teams. * Strong collaboration and communication skills, with the ability to work effectively across engineering teams and influence technical decisions through partnership and expertise. * A continuous learning mindset and a passion for improving engineering practices, modernising legacy systems and delivering measurable business impact. INFRA AND CLOUD NATIVE EXPERIENCE * Experience developing and maintaining Infrastructure as Code using Terraform (or equivalent), alongside a strong understanding of CI/CD pipelines and modern software delivery practices. * Experience building and operating cloud-native applications using containers and orchestration technologies within AWS and Amazon ECS. AI EXPERIENCE * Experience using AI-assisted engineering tools to improve productivity, quality and software delivery, while applying sound judgement to validate outputs. * You're curious about the rapidly evolving AI landscape and can identify practical opportunities to apply AI to engineering workflows, automation and developer experience - ideally through first hand experience. COMMUNICATING AND INFLUENCE * A track record of influencing technical decisions across engineering teams through collaboration, clear communication and technical credibility. * Strong communication and collaboration skills, with the ability to explain technical concepts to diverse audiences, build trusted relationships and help drive organisational adoption of engineering standards and best practices. More information: Enjoy fantastic perks like private healthcare & dental insurance, a generous work from abroad policy, 2-for-1 share purchase plans, an EV Scheme to further reduce carbon emissions, extra festive time off, and excellent family-friendly benefits. We prioritise career growth with clear career paths, transparent pay bands, personal learning budgets, and regular learning days. Jump on board and supercharge your career from day one! We're operating a hybrid model and ask that Trainliners work from the office a minimum of 60% of their time over a 12-week period. We also have a 28-day Work from Abroad policy. Our values represent the things that matter most to us and what we live and breathe everyday, in everything we do: * 💭 Think Big - We're building the future of rail * ✔️ Own It - We focus on every customer, partner and journey * 🤝 Travel Together - We're one team * ♻️ Do Good - We make a positive impact We know that having a diverse team makes us better and helps us succeed. And we mean all forms of diversity - gender, ethnicity, sexuality, disability, nationality and diversity of thought. That's why we're committed to creating inclusive places to work, where everyone belongs and differences are valued and celebrated. Interested in finding out more about what it's like to work at Trainline? Why not check us out on LinkedIn, Instagram and Glassdoor!
About Abound We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full financial picture - how much you spend, and what you can afford to repay to build a deeper, more accurate understanding of each customer's unique financial situation. And we've shown it works at scale. We’ve issued over £1.3bn in loans directly to customers while delivering market-leading credit performance - for every 10 defaults the industry expects, we see only 3. We also reached profitability just 2.5 years after launch. Backed by £2bn+ of funding from top-tier investors including Citi, GSR Ventures, and Deutsche Bank, we’re recognised as one of Europe’s fastest-growing fintechs (Sifted, CNBC). Now, we’re expanding into new markets and product lines - and we’re looking for ambitious people who want to learn fast, take ownership, and grow with us. About the role: You won't be sitting in an ivory tower throwing policies over the fence. You will be embedded directly within our Platform team in a true DevSecOps capacity. Operating as a highly technical individual contributor, you will bridge the gap between product-led engineering and Corporate IT. You will play a hands-on role in challenging the security architecture of production and corporate IT infrastructure. In your first 6–12 months, you will design and implement our next-generation cloud security architecture across AWS and GCP, while helping to build and mature our internal SOC capabilities, including detection and response. You will take ownership of Microsoft Sentinel, enhancing our SIEM/SOAR capabilities, and strengthen identity and access management through improved and automated RBAC across AWS, Microsoft Entra, and internal systems. You will also drive a shift-left approach to security by embedding controls into GitLab CI/CD pipelines, including scanning, IaC reviews, and automated policy enforcement across the SDLC. Our technology stack: Cloud & Compute: AWS, ECS Fargate, Aurora, Lambda, GCP Data Lake: S3, DMS, Glue Cloud Security Tooling: GuardDuty, Security Hub, Inspector, Security Command Center Code & IaC: Python, Java, GitLab, AWS CDK, Terraform/CDK-TF Observability & Incident Management: AMP, Incident.io Who you are: * You are a security professional by trade, but a hacker by design. You have a strong track record in DevSecOps and cloud security engineering, with hands-on experience elevating the security posture of other organisations. * You are a strong Python developer. You know how to script automation, interact with APIs, and build security tooling from scratch. * You possess a rock-solid understanding of network security fundamentals and how they apply to modern, distributed cloud architectures. * You are comfortable owning both the build and run aspects of security—designing systems and responding to incidents. * You thrive in the dynamic, ambiguous, and fast-paced environment of a high-growth startup. You know how to balance rigorous security with engineering velocity. What you'll be doing: * Actively contribute infrastructure-as-Code (AWS CDK, Terraform) for security risks prior to deployment * Implement best practice network security across AWS and GCP (IAM, VPCs, encryption, logging, monitoring) * Embed zero-trust policies across the estate * Actively challenge the security standards of production applications and infrastructure * Embed security controls into CI/CD pipelines (SAST, dependency scanning, container security) * Partner with engineering teams on secure architecture and deployment patterns * Support secure SDLC practices and pre-deployment security reviews What we offer * Everyone owns a piece of the company - equity * Hybrid with 3 days a week in the office * 25 days’ holiday a year, plus 8 bank holidays * 2 paid volunteering days per year * One month paid sabbatical after 4 years * Employee loan * Free gym membership * Team wellness budget to be active together - set up a yoga class, a tennis lesson or go bouldering