At a Glance
- Tasks: Join us to enhance security in our cutting-edge Google Cloud Platform environment.
- Company: FairPlay Sports Media, a leader in AI-driven sports media and BetTech.
- Benefits: Enjoy flexible remote work, unlimited holiday, and a £1,000 training fund.
- Other info: Be part of a diverse team that values inclusion and personal growth.
- Why this job: Make a real impact in a fast-paced, innovative tech environment.
- Qualifications: 5+ years in Security Engineering with expertise in GCP and DevSecOps.
The predicted salary is between 66150 - 80850 £ per year.
FairPlay Sports Media is an AI-driven, technology-led media network and BetTech infrastructure provider. Built on the 25-year legacy of oddschecker (founded in 1999), the group operates globally at the intersection of high-intent sports audiences, premium publishers and betting operators. By combining deep market expertise with technical proficiency, FairPlay Sports Media bridges the gap between sports content and sustainable monetisation. Its global infrastructure runs on a proprietary data platform built to process over one billion odds on peak days and cover more than 30,000 sporting events annually. The company nurtures a portfolio of highly engaged, trusted brands, including oddschecker, WhoScored, SuperScommesse and Confido Network. FairPlay Sports Media is a Bruin Capital company headquartered in London, UK, and has operations in North America and throughout Europe, supported by a global workforce of over 200 employees.
iGaming is one of the fastest-growing and most technologically innovative sectors, and we're on top of our game, powered by market-leading technology and driven by brilliant people. We champion diversity and operate an open and inclusive culture while remaining focused, fast-paced, and always making sure to have fun along the way. So why not join FairPlay Sports Media and be part of something bigger...
We’re flexible on remote working, but ideally, we’d like you to attend our London office once a month to meet the team. The role also includes an on-call rota of approximately 1 week every 5 weeks, with additional callout compensation.
Role Summary:
FairPlay Sports Media is building a tech-led, AI and data-powered sports media network that serves both owned brands (e.g., oddschecker, WhoScored.com, SuperScommesse, and others) and partners with BetTech products spanning data, display, and predictive capabilities. At FairPlay scale - real-time data, high-frequency updates, and partner integrations - you’ll work with multiple engineering teams to deliver reliable, compliant, high-throughput product execution.
What you’ll do:
We are looking for a hands-on, pragmatic, DevSecOps minded Senior Security Engineer to own and evolve the security posture of our Google Cloud Platform environment. Comfortable working across infrastructure, platforms, and pipelines, you will level up our InfoSec detection and response capabilities, harden our identity model toward Zero Trust, and build secure guardrails into our infrastructure-as-code and delivery pipelines.
Key Responsibilities:
- Pillar 1: Engineering & Infrastructure Security
- Automating security guardrails, so developers can ship safe code fast:
- GCP Infrastructure Security: Audit, harden, and monitor our GCP footprint (including Security Command Center, IAM PoLP, Cloud Armor, encryption at rest with KMS, OS Login, GKE Network Policies for zero-trust, and remediating default service accounts).
- SCA & Secrets: Integrate automated security scanning (SBOM, SAST, DAST) into GitLab pipelines, enforce policy-as-code across Terraform, route code-level vulnerabilities to owners, manage end-to-end secrets lifecycles (Google Secret Manager/KMS, rotation, access policies), and facilitate the remediation of hardcoded credentials by engineering teams.
- Logging & Observability: Define logging policies (including VPC Flow Logs for forensic visibility) and build security telemetry and reporting frameworks for real-time incident response.
- Workload & Host Hardening: Implement and automate Shielded VM configurations (Secure Boot, vTPM) across the compute fleet and ensure IaC deployments enforce security best practices.
- Internal Tooling & Automation: Maintain and build developer-facing tools using Python, Go, and modern frameworks.
- Pillar 2: Security Operations
- Protecting company assets and responding to threats:
- Vendor & Operational Oversight: Act as the primary technical interface with our MDR partner, ensuring seamless integration with internal NOC/SOC operations.
- InfoSec Operations: Lead security operations, enforcing Zero Trust access management principles, and infrastructure incident response, driving rapid incident detection and leading internal incident command for high-severity threats.
- Strategy & Principles: Collaborate with technical leadership to enhance our InfoSec, DevSecOps and AppSec policies and standards.
- Vulnerability & Perimeter Management: Own and evolve the end-to-end vulnerability scanning lifecycle and perimeter detection pipelines.
- Incident Response & On-Call: Working alongside our 24/7 MDR partner, this role takes part in a structured out-of-hours on-call rotation to lead incident response when required. All on-call duties and escalations are additionally compensated via callout pay.
- Threat Modelling: Conduct regular threat modelling sessions and architectural security reviews to identify and mitigate risks early in the development lifecycle.
What we’re looking for:
Technical Skills & Experience
Must have:
- Experience: 5+ years in Security Engineering, Cloud Engineering, or SRE within a modern cloud environment.
- GCP & Containers: Deep hands-on expertise in GCP (IAM, Workload Identity, VPC, Org Policy, Security Command Center) and containerisation (Docker, Kubernetes).
- IaC & Pipeline Security: Strong proficiency with Terraform and deep experience managing CI/CD pipelines (GitLab CI) to embed automated security guardrails.
- DevSecOps Automation: Proficiency in scripting and development (Python, Go, or Bash) to build internal security tools.
- Security Architecture & Ops: Demonstrated ownership of incident response, detection engineering, vulnerability management, and WAF/DDoS mitigation.
- Zero Trust & IAM: Practical experience designing least-privilege IAM and maturing architectures toward Zero Trust models.
Highly Desirable:
- Relevant certifications (GCP Professional Cloud Security Engineer, GIAC, OSCP).
- Experience using the Google Cloud Architecture Framework.
- Experience with Chronicle, Wiz, or comparable CNAPP/SIEM tooling.
- Familiarity with compliance frameworks (SOC 2, ISO 27001) as engineering requirements.
Soft Skills:
- Ownership & Effective Problem-Solving: You are a pragmatic engineer who takes initiative, pursues problems to resolution, and balances speed with a meticulous attention to detail.
- Resilience & Autonomy: You demonstrate high emotional intelligence, self-organisation, and self-direction.
- Communication & Collaboration: You are an overcommunicator who clearly explains security risks and solution options to developers and engineering leadership.
What you’ll get back from us:
Alongside being challenged daily and a real interest in your development, you will also receive:
- Subsidized Sky HD package, broadband and discounted sky talk
- Free Puregym membership
- Free healthcare with Bupa, life assurance and income protection
- Pension scheme with up to 9% contribution from the company
- £1,000 training fund each financial year, to spend on your professional development
- Unlimited holiday plan
Research shows that women and ethnic minorities are less likely to apply if they don’t meet every qualification. If you’re passionate about our purpose, determined to take on challenges, and eager to learn, we’re committed to building a diverse and inclusive team, and to ensuring an accessible recruitment process.
Equal opportunity employment, non‑discrimination in recruitment, compensation, development, and promotion, inclusive leadership and respectful workplace behaviours.
If you need any accommodations during the recruitment process, please let us know.
Senior Security Engineer in London employer: FairPlay Sports Media
At FairPlay Sports Media, we pride ourselves on fostering a dynamic and innovative work culture that empowers our employees to thrive. As a Senior Cloud Security Engineer, you will benefit from our commitment to professional growth through continuous learning opportunities and hands-on experience with cutting-edge technologies in a collaborative environment. Located in a vibrant tech hub, we offer competitive compensation, including on-call pay, and the chance to be part of a forward-thinking team dedicated to revolutionising the sports media landscape.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Security Engineer in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including FairPlay Sports Media, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through FairPlay Sports Media
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at FairPlay Sports Media. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Security Engineer in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at FairPlay Sports Media insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to FairPlay Sports Media that you’re committed to staying ahead in the game.
How to prepare for a job interview at FairPlay Sports Media
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at FairPlay Sports Media to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at FairPlay Sports Media.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.