> Markdown version of [/jobs/ext/2288768-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/2288768-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Oddschecker - **Location:** London, UK (Remote available) - **Experience:** Expert - **Salary:** £81,848.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Computer Networks, DDoS Mitigation, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Zero Trust Network Access, Security Software, Security Information and Event Management, Software Vulnerability Management, Web Application Frameworks, Data Logging, Google Cloud, Delivery Pipeline, Software Security, Amazon Virtual Private Cloud (VPC), Gitlab, Containerization, Gitlab-ci, Kubernetes, Real Time Data, U-Boot, Terraform, Devsecops, Docker, Static Application Security Testing, Vulnerability Analysis, Golang, Dynamic Application Security Testing - **Published:** August 29, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5859759219 ## About the Role We are looking for a hands-on, pragmatic, DevSecOps minded Senior Security Engineer to own and evolve the security posture of our Google Cloud Platform environment. Comfortable working across infrastructure, platforms, and pipelines, you will level up our InfoSec detection and response capabilities, harden our identity model toward Zero Trust, and build secure guardrails into our infrastructure-as-code and delivery pipelines., * GCP & Containers: Deep hands-on expertise in GCP (IAM, Workload Identity, VPC, Org Policy, Security Command Center) and containerisation (Docker, Kubernetes). * IaC & Pipeline Security: Strong proficiency with Terraform and deep experience managing CI/CD pipelines (GitLab CI) to embed automated security guardrails. * DevSecOps Automation: Proficiency in scripting and development (Python, Go, or Bash) to build internal security tools. * Security Architecture & Ops: Demonstrated ownership of incident response, detection engineering, vulnerability management, and WAF/DDoS mitigation. * Zero Trust & IAM: Practical experience designing least-privilege IAM and maturing architectures toward Zero Trust models. Highly Desirable * Relevant certifications (GCP Professional Cloud Security Engineer, GIAC, OSCP). * Experience using the Google Cloud Architecture Framework. * Experience with Chronicle, Wiz, or comparable CNAPP/SIEM tooling. * Familiarity with compliance frameworks (SOC 2, ISO 27001) as engineering requirements. Soft Skills * Ownership & Effective Problem-Solving: You are a pragmatic engineer who takes initiative, pursues problems to resolution, and balances speed with a meticulous attention to detail. * Resilience & Autonomy: You demonstrate high emotional intelligence, self-organisation, and self-direction. * Communication & Collaboration: You are an overcommunicator who clearly explains security risks and solution options to developers and engineering leadership. ## Description FairPlay Sports Media is building a tech-led, AI and data-powered sports media network that serves both owned brands (e.g., oddschecker, WhoScored.com, SuperScommesse, and others) and partners with BetTech products spanning data, display, and predictive capabilities. At FairPlay scale - real-time data, high-frequency updates, and partner integrations - you'll work with multiple engineering teams to deliver reliable, compliant, high-throughput product execution., * GCP Infrastructure Security: Audit, harden, and monitor our GCP footprint (including Security Command Center, IAM PoLP, Cloud Armor, encryption at rest with KMS, OS Login, GKE Network Policies for zero-trust, and remediating default service accounts). * SCA & Secrets: Integrate automated security scanning (SBOM, SAST, DAST) into GitLab pipelines, enforce policy-as-code across Terraform, route code-level vulnerabilities to owners, manage end-to-end secrets lifecycles (Google Secret Manager/KMS, rotation, access policies), and facilitate the remediation of hardcoded credentials by engineering teams. * Logging & Observability: Define logging policies (including VPC Flow Logs for forensic visibility) and build security telemetry and reporting frameworks for real-time incident response. * Workload & Host Hardening: Implement and automate Shielded VM configurations (Secure Boot, vTPM) across the compute fleet and ensure IaC deployments enforce security best practices. * Internal Tooling & Automation: Maintain and build developer-facing tools using Python, Go, and modern frameworks., * Vendor & Operational Oversight: Act as the primary technical interface with our MDR partner, ensuring seamless integration with internal NOC/SOC operations. * InfoSec Operations: Lead security operations, enforcing Zero Trust access management principles, and infrastructure incident response, driving rapid incident detection and leading internal incident command for high-severity threats. * Strategy & Principles: Collaborate with technical leadership to enhance our InfoSec, DevSecOps and AppSec policies and standards. * Vulnerability & Perimeter Management: Own and evolve the end-to-end vulnerability scanning lifecycle and perimeter detection pipelines. * Incident Response & On-Call: Working alongside our 24/7 MDR partner, this role takes part in a structured out-of-hours on-call rotation to lead incident response when required. All on-call duties and escalations are additionally compensated via callout pay. * Threat Modelling: Conduct regular threat modelling sessions and architectural security reviews to identify and mitigate risks early in the development lifecycle., * Experience: 5+ years in Security Engineering, Cloud Engineering, or SRE within a modern cloud environment. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk)