> Markdown version of [/jobs/ext/2793859-security-engineer](https://www.wearedevelopers.com/jobs/ext/2793859-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Efg (esl Faceit Group - **Location:** UK (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Cloud Computing, Cloud Engineering, Cyber Security, Computer Programming, Continuous Integration, Digital Forensics, Identity and Access Management, Zero Trust Network Access, Secure Coding, Security Support Provider Interface, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Scripting, Multi-Cloud, Cloudformation, Kubernetes, Deployment Automation, Terraform, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 8, 2026 - **Apply:** https://startup.jobs/senior-security-engineer-esl-faceit-group-limited-9946882 ## About the Role * Advanced Security Engineering Expertise: Extensive experience in Information Security Engineering, with a proven track record of architecting and deploying resilient security systems at scale. You have moved beyond implementation to designing the frameworks that define the company's security posture; * Strategic Policy & Standard Development: Ability to translate high-level security policies into enforceable technical standards. You have experience leading the rollout of security initiatives across multiple departments and influencing organisational change; * Expert Cloud & Infrastructure Security: Expert-level knowledge of major cloud platforms (AWS/GCP), with the ability to design secure multi-tenant architectures and perform deep-dive security configuration audits; * Cloud-Native & Container Security: Deep proficiency in securing containerised environments and orchestration platforms (Kubernetes). You are an expert in Infrastructure as Code (Terraform/CloudFormation) and can build automated guardrails to ensure compliant deployments; * Security Automation & Tooling Development: Advanced scripting and programming proficiency (with currently used languages) used to build custom security tooling, automate repetitive SecOps tasks, and develop sophisticated detection logic; * Detection & Response Architecture: Proven experience designing and optimising enterprise security stacks, including SIEM, SOAR, and EDR. You don't just use tools; you tune them to eliminate noise and build high-fidelity alerting pipelines; * DevSecOps Leadership: Experience leading the integration of security into complex CI/CD lifecycles. You have designed and scaled "Security-as-Code" initiatives that empower developers to ship secure code without sacrificing velocity; * Governance & Compliance Mastery: Comprehensive understanding of global security frameworks (ISO 27001, SOC2, NIST) and data protection regulations. You have experience demonstrating security controls during audits and aligning technical execution with regulatory requirements. * Incident Leadership & Forensics: Demonstrated ability to lead the technical response for critical security incidents. You possess strong digital forensics and incident response (DFIR) skills and can translate technical root-cause findings into long-term strategic roadmaps. ## Description The Senior Security Engineer leads the evolution of EFG's information security posture by architecting and overseeing the implementation of enterprise security tools, platforms, and frameworks across the organization. This role is a technical authority responsible for driving high-impact security outcomes through automation and strategic resource allocation, ensuring the secure, resilient, and scalable operation of the Digital Platform (FACEIT) and the wider EFG ecosystem. What you will do * Security Architecture & Threat Engineering: Architect and oversee the deployment of advanced security monitoring frameworks. Design automated detection logic to identify complex attack patterns across diverse log sources. Serve as the final escalation point for the Security Support Desk, resolving high-impact incidents and engineering systemic fixes for recurring issues; * Secure Software Development Life Cycle (SSDLC) Leadership: Lead the integration of security-as-code within the CI/CD pipeline. Architect the automated deployment of SAST, DAST, and SCA tooling, and partner with Engineering leads to define security gating criteria. Provide expert-level remediation guidance for complex architectural flaws and critical code vulnerabilities; * Enterprise Vulnerability & Risk Management: Own the end-to-end vulnerability management strategy for infrastructure and applications. Prioritise remediation efforts based on business risk and exploitability, and lead cross-departmental task forces to address systemic security gaps. Oversee the technical relationship with external penetration testers and bug bounty researchers; * Security Engineering & Orchestration: Design, implement, and optimize core security infrastructure (e.g. EDR,, Zero Trust, IAM, and DLP). Focus on automation and orchestration (SOAR) to reduce manual overhead and ensure security controls are consistently enforced across a global, multi-cloud environment; * Incident Response Leadership: Lead the technical response to high-priority security incidents. Drive the containment, eradication, and recovery phases, while coordinating communication between technical teams and senior stakeholders. Conduct deep-dive root cause analyses and develop long-term engineering roadmaps to prevent incident recurrence; * Compliance & Security Assurance: Lead internal security audits and maturity assessments. Ensure systems align with international standards (e.g., ISO 27001) and regulatory requirements. Define the technical standards that validate the effectiveness of the organisation's control environment; * Strategic Technical Advisory: Act as a primary security consultant for major business initiatives. Evaluate the security posture of new technologies and third-party vendors, ensuring that all projects are built on a foundation of "Security by Design."; * Standardisation & Mentorship: Define the standards for SOPs, runbooks, and technical documentation. Mentor junior and mid-level security engineers to elevate the team's collective technical proficiency and ensure the consistent execution of high-quality security operations. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)