5+ years in Security Engineering / DevSecOps roles, with proven success delivering secure infrastructure and applications.
Strong skills in Python and Bash for building and automating security workflows.
Cloud Security (AWS focus) - Deep knowledge of IAM least-privilege design, encryption at rest/in transit, GuardDuty, Security Hub, and best practices for securing multi-account environments.
Implementation of security controls in pipelines (SAST, DAST, dependency scanning, container image scanning, policy-as-code).
Hardening of Linux systems, Docker, Kubernetes/EKS; strong experience with RBAC, PodSecurity/OPA/Gatekeeper/Kyverno policies.
Terraform/Terragrunt, including policy-as-code, drift detection, and compliance enforcement.
Expertise with HashiCorp Vault, AWS Secrets Manager, or equivalent.
Hands-on with centralized logging, SIEM/SOAR tools (Datadog Security, ELK, CloudWatch, etc.) and incident response workflows.
In-depth understanding of secure network design, segmentation, and monitoring.
Experience with tools enabling temporary, approval-based access (Teleport, AWS IAM Identity Center, Okta, etc.).
Ability to design and enforce zero trust principles (continuous verification, microsegmentation, contextual access).
Familiarity with SBOM generation (CycloneDX, Syft), artifact signing (Cosign, Sigstore), and applying SLSA/in-toto frameworks.
Understanding of ISO 27001, GDPR, PCI-DSS (iGaming relevance), plus experience automating compliance checks with IaC and policy engines.
Exposure to Kafka or ClickHouse in security-sensitive environments.
Familiarity with GitOps tooling (FluxCD/ArgoCD).
Broader knowledge of SOC 2, HIPAA, or other regulatory frameworks.
Responsibilities
Establish the DevSecOps function at Playson, defining best practices and security standards across the Platform Tribe.
Integrate security into CI/CD pipelines including SAST, DAST, dependency scanning, container image scanning, policy-as-code implementation.
Harden infrastructure and runtime environments such as Linux systems, Docker, Kubernetes/EKS with a focus on RBAC policies.
Design and enforce cloud security controls in AWS focusing on IAM least-privilege design, GuardDuty integration, Security Hub usage, encryption at rest/in transit practices.
Define and maintain Infrastructure as Code (IaC) security policies using Terraform or Terragrunt with policy-as-code implementation and drift detection mechanisms.
Implement and manage secrets management solutions like HashiCorp Vault, AWS Secrets Manager, ensuring secure handling of sensitive data.
Build centralized security monitoring & alerting systems utilizing tools such as Datadog Security, ELK stack (ELK), CloudWatch for SIEM/SOAR capabilities and incident response workflows.
Lead vulnerability management and threat modeling practices to identify and mitigate potential risks within the platform's infrastructure.
Automate security workflows through scripting in Python or Bash, enhancing efficiency of DevSecOps processes.
Partner with backend, infrastructure, and platform engineers for embedding security into design & delivery phases effectively.
Contribute to compliance readiness by aligning practices with standards like ISO 27001, GDPR, PCI-DSS ensuring regulatory adherence in operations.
Act as a subject matter expert and mentor within the organization for security best practices awareness among engineers.
Continuously evaluate and implement new tools and approaches to maintain cutting-edge DevSecOps capabilities at Playson.
Benefits
Compensation at top industry standards + quarterly bonuses based on transparent evaluation.
Remote-first flexibility and adaptable working hours.
Unlimited paid vacation & sick leave.
Comprehensive medical insurance (for you and your partner).
Financial support for major life events.
Professional growth budget for courses, training, and certifications.
Recruitment Process
1. Recruiter Interview – 45 min
2. Hiring Manager Interview – 60 min
3. Technical Interview – 90 min
4. Final Interview with Head of Platform & CTO – 60 min