Senior DevSecOps Engineer
SmarketsAbout the role
Who are we? Smarkets: Predicting the Future of Betting Smarkets is a prediction market exchange for sports and political trading, having handled over $50 billion in volume since 2010. We're upending sports betting with the fairest prices, the best technology, and a superior customer experience, powered by attracting great people and building a high-performance environment where they thrive. We're looking for an atypical candidate with strong regulated-business experience to support our growing CFTC business. The Team Security sits within Infrastructure and Engineering, protecting the distributed, real-time systems behind our trading engine. The team's remit spans our core products and our DCM/DCO entities, with a real regulatory dimension to the work, particularly around our CFTC-regulated business units. Alongside that regulatory scope, the focus is squarely on hands-on engineering: designing, building, and shipping the security tooling and controls that let engineering teams move fast safely. About the Role: This is a founding build. You'll stand up security engineering from the ground up through go-live and mature it as we scale, working within Infrastructure and Engineering teams to build the controls, automation, and guardrails our trading systems and regulated entities need. What you will do: Build the Foundations: Be part of a founding build, standing up security engineering from the ground up through go-live and maturing it as we scale, working within Infrastructure and Engineering teams. Design Guardrails: Design, build, and deploy security controls and guardrails across cloud-native platforms, including AI security solutions protecting customer-facing and internal products. Automate as Code: Automate security processes as code, embedding compliance and infrastructure-as-code checks into CI/CD pipelines without slowing down frequent shipping. Assess & Remediate: Conduct risk audits and assessments, translating findings into practical recommendations for engineering teams, and be hands-on in implementing those recommendations. Monitor & Respond: Monitor and analyse system access logs, flag anomalies, and support incident response, containment, and post-incident root cause analysis. Plan for Resilience: Plan and test security backups and disaster recovery processes to keep the platform resilient. Maintain Compliance: Develop and maintain security policies, standards, and controls meeting DCM/DCO requirements, and maintain evidence and documentation to support regulatory examinations and audits. Partner Across Teams: Partner with business and engineering teams on solutions, translating technical work for product and engineering audiences. Champion Ownership: Build a culture of security ownership among engineers, acting as a security partner rather than a gatekeeper. Role Requirements: Security Engineering Background: Hands-on experience building security engineering/DevSecOps capabilities in a cloud-native, high-growth environment,
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s