Product Security Architect
Product Security Architect

Product Security Architect

Leeds Full-Time 48000 - 72000 £ / year (est.) No home office possible
Go Premium
Flutter

At a Glance

  • Tasks: Lead the charge in defining and evolving our Product Security strategy across all brands.
  • Company: Join Flutter, a global leader in online sports betting and iGaming.
  • Benefits: Enjoy flexible working, uncapped holiday, private healthcare, and a £1,000 learning fund.
  • Why this job: Make a real impact on security practices while working with cutting-edge technologies.
  • Qualifications: Experience in software development and application security, with leadership skills.
  • Other info: Be part of an inclusive team that values diverse perspectives and experiences.

The predicted salary is between 48000 - 72000 £ per year.

Location: Leeds/Dublin. Hybrid: 2 days per week.

At Flutter, Product Security encompasses not just application code, but also infrastructure as code, APIs, CI/CD pipelines, containers and third-party dependencies. The Senior Product Security Architect is responsible for defining, evolving, and championing a group-wide Product Security strategy across all regions and brands. Operating in a federated environment, this role provides strategic guidance, technical direction, and hands-on expertise to help security and engineering teams across the enterprise embed security into the product development lifecycles. This role is the key advisor on AppSec standards, secure development practices, threat modelling, and security tooling (e.g. SAST, DAST, SCA, IaC scanning, container security, etc.), ensuring consistency and maturity in how applications are built and maintained. By aligning teams with modern DevSecOps principles, developer enablement, and security automation, the role plays a critical part in improving the overall security posture of Flutter's software estate.

About Division/Function: Flutter consists of two commercial divisions (Fanduel and International) and our central Flutter Functions; COO, Finance & Legal. Here in Flutter Functions we work with colleagues across all our divisions and regions to deliver something we call the Flutter Edge. It’s what differentiates us, our 'secret sauce' which plays a key part in our ongoing success and powers our brands and divisions, through Product, Tech, Expertise and Scale. In Flutter COO we work with experts across Flutter to build, deploy and communicate the Flutter Edge. Together we cover Product & Payments, Technology, Sportsbook Product & Trading, People, Property, Corporate Communications and Strategic Partnerships & Transformation.

What you’ll do:

  • Strategic Leadership & Roadmap: Define and lead the enterprise-wide Application Security and SSDLC strategy, including short, mid, and long-term goals aligned with the group’s security posture and digital transformation initiatives. Develop and maintain AppSec maturity models (e.g. based on OWASP SAMM, NIST SSDF, BSIMM) and work with business units to assess current state and define realistic improvement plans. Drive the development of a global secure development policy, including approved tools, practices, and coding standards.
  • Technology & Tooling Strategy: Evaluate, recommend, and support the rollout of AppSec tools such as SAST, DAST, SCA, container and IaC scanners, runtime protections, and CI/CD pipeline integrations. Collaborate with platform and DevOps teams to ensure tool integration and automation into developer workflows across brands. Provide architecture guidance on secure design patterns and security tool architecture in cloud-native and hybrid environments.
  • Global Collaboration: Work closely with the Associate Director of Group Enterprise Security and other domain leads to align strategies and ensure cross-cutting coverage. Define and monitor key AppSec KPIs and metrics (e.g. vulnerability MTTR, scan coverage, risk acceptance trends) and report findings to leadership and the Global Cyber Council. Coordinate secure architecture reviews for critical application initiatives and provide consultative threat modelling support to large cross-brand projects.
  • Continuous Improvement & Innovation: Keep up with emerging application security technologies, industry best practices, and threat trends. Evaluate new tools or features and incorporate them where beneficial into the strategy. Find opportunities to reduce friction for developers/brands while maintaining security. Continuously assess the program’s maturity across brands and implement improvements to process or technology to elevate weaker areas. Planning for product-related incident response and disaster recovery to ensure teams are prepared to handle a security incident.
  • Project and Vendor Management: Oversee Secure by Design project execution and coordinate with project managers to ensure results (system implementations, migrations, integrations) are completed on time. Manage relationships with product vendors and service providers (Remaining vendor neutral) - e.g. oversee any integration partners/consultants and ensure we leverage vendor support. Evaluate and select products or upgrades in line with the strategic roadmap. Ensure that vendor solutions are configured to meet our requirements and that any services used are governed under group policies.

How you’ll do it:

  • Several years of experience in software development and application security, with recent experience in an AppSec leadership or Security Architecture role.
  • A track record of designing and implementing enterprise-scale secure development programs and embedding security into engineering culture.
  • Broad experience integrating with various systems and tools such as: SonarCloud, Checkmarx, GitHub Advanced Security, Snyk, Aqua, Prisma Cloud, Semgrep, etc.
  • Strong understanding and use of CI/CD ecosystems (e.g. GitLab, Jenkins, Azure DevOps, GitHub Actions) and how to embed security in build and deploy processes.
  • Experience working in or with regulated industries or large enterprises is highly desirable.
  • Mergers and Acquisitions integration experience is a plus.
  • Familiarity with industry frameworks and standards: OWASP SAMM, OWASP ASVS, BSIMM, NIST SSDF, ISO 27034.
  • Lead teams and projects. This could be as a DevSecOps team lead, security architect, or manager for SSDLC initiatives.
  • Professional certifications in security are highly valued, such as CISSP/CSSLP, CISM, and/or other AppSec-specific certifications.

What’s in it for you:

We are a flexible employer; whether you have personal commitments or a hobby that brings you joy, we want you to bring your best self to work and feel empowered to do so. We also like to share our success; after all you make it happen. We have an excellent benefits package that can be personalised to you:

  • Bonus scheme
  • Uncapped holiday allowance
  • Enhanced pension scheme
  • Private healthcare
  • Life assurance
  • Income protection
  • £1,000 annual self-development learning fund
  • Invest via the Flutter Sharesave Scheme
  • Enhanced parental leave

About Flutter:

We are a world leader in online sports betting and iGaming, with a market leading position in the US and across the world. We have an unparalleled portfolio of the most innovative, diverse and distinctive brands including FanDuel, Sky Betting & Gaming, Sportsbet, PokerStars, Paddy Power, Sisal, tombola, Betfair, MaxBet, Junglee Games and Adjarabet. With our global scale and challenger mentality, through which we excite and entertain our customers, in a safe and sustainable way. Using our collective power, the Flutter Edge, we aim to disrupt the sector, learning from the past to create a better future for our customers, colleagues and communities.

We’re working to be an inclusive employer, and we encourage people from all backgrounds, ways of thinking and working to apply. Everyone brings different perspectives and experiences; you don’t have to meet all the requirements listed to apply for this role. If you need any adjustments to make this role work for you let us know, and we’ll see how we can accommodate them.

Product Security Architect employer: Flutter

At Flutter, we pride ourselves on being a flexible employer that values work-life balance and personal growth. Our vibrant work culture fosters collaboration and innovation, while our comprehensive benefits package, including an uncapped holiday allowance and a £1,000 annual self-development fund, empowers employees to thrive both personally and professionally. With opportunities for strategic leadership in a global environment, the role of Senior Product Security Architect offers a unique chance to shape the future of security practices across our diverse brands.
Flutter

Contact Detail:

Flutter Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Product Security Architect

✨Tip Number 1

Network like a pro! Reach out to folks in your industry on LinkedIn or at local meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects and contributions. This gives potential employers a taste of what you can do beyond your CV.

✨Tip Number 3

Prepare for interviews by practising common questions and scenarios related to product security. We recommend doing mock interviews with friends or using online platforms to boost your confidence.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive!

We think you need these skills to ace Product Security Architect

Application Security
Secure Development Practices
Threat Modelling
Security Tooling (SAST, DAST, SCA)
CI/CD Pipeline Integration
Cloud-Native Security
DevSecOps Principles
Architecture Guidance
AppSec Maturity Models (OWASP SAMM, NIST SSDF, BSIMM)
Project Management
Vendor Management
Software Development
Regulated Industry Experience
Professional Security Certifications (CISSP, CSSLP, CISM)

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in application security and software development. We want to see how your skills align with the role of Product Security Architect, so don’t hold back on showcasing relevant projects!

Showcase Your Leadership Skills: Since this role involves strategic leadership, it’s important to demonstrate your experience in leading teams and projects. Share specific examples where you’ve successfully embedded security into engineering culture or developed secure development programmes.

Highlight Your Technical Expertise: We’re looking for someone with a strong understanding of AppSec tools and CI/CD ecosystems. Be sure to mention any relevant technologies you’ve worked with, like SAST, DAST, or container security, and how you’ve integrated them into workflows.

Apply Through Our Website: We encourage you to apply directly through our website for the best chance of getting noticed. It’s the easiest way for us to keep track of your application and ensure it reaches the right people!

How to prepare for a job interview at Flutter

✨Know Your Stuff

Make sure you brush up on your knowledge of application security, especially the tools and frameworks mentioned in the job description like OWASP SAMM and NIST SSDF. Be ready to discuss how you've implemented secure development practices in your previous roles.

✨Show Your Leadership Skills

This role requires strategic leadership, so be prepared to share examples of how you've led teams or projects in the past. Highlight your experience in embedding security into engineering culture and how you've driven initiatives that align with business goals.

✨Be a Team Player

Collaboration is key in this position. Think of instances where you've worked closely with cross-functional teams, especially in a DevSecOps environment. Emphasise your ability to communicate effectively and align strategies across different departments.

✨Stay Current

The tech world moves fast, especially in security. Be ready to discuss recent trends or emerging technologies in application security. Showing that you're proactive about continuous learning will demonstrate your commitment to improving security practices.

Product Security Architect
Flutter
Location: Leeds
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>