Principal Security Engineer
Indexed description
MrQ runs a real-money gaming platform for 300,000+ active players - payment flows, player data, an AWS-native platform, and a company that’s deeply AI-native across the board. That’s a lot of technical surface area. Someone needs to own securing it at the engineering level: the tooling, the detection, the identity architecture, the vulnerability management, the incident response. That’s this role. You’re the hands-on technical builder of MrQ’s security engineering function - architecting and running the stack that the security strategy depends on.
You report to the Head of Security, who owns the roadmap and the board relationship. You own making that roadmap real in production.
This is a Principal role in the truest sense: deep technical ownership, accountable for delivering complex, high-impact initiatives.
What You Will Do2. Security Operations & Incident Response3. Identity, Access & Endpoint Security4. Compliance Evidence & DocumentationWhat We're Looking ForHighly DesirableWhat We Offer
- Security Architecture, Tooling & Engineering
- Security Stack: Evaluate, select, deploy, configure and manage the full enterprise security tooling suite from scratch - EDR/XDR (CrowdStrike/SentinelOne), SASE/SWG (Netskope/Zscaler), SIEM, email security, DLP, endpoint privilege management, application allowlisting.
- Architecture: Design and implement enterprise security architecture built on zero trust and secure-by-default principles. Own the technical blueprint across cloud (AWS), SaaS, endpoints, network and identity.
- Detection Engineering: Build, tune and maintain detection rules, correlation logic and alerting across SIEM and EDR. Engineer high-fidelity detections mapped to MITRE ATT&CK. Continuously reduce false positives and expand coverage.
- Automation: Engineer automation for security operations at scale - scripting (Python, Bash, PowerShell) for response orchestration, access reviews, compliance checks, vulnerability reporting, threat intel enrichment.
- Integration & Evaluation: Ensure all security tooling integrates with existing infrastructure and identity platforms. Lead POCs, vendor evaluations and build-vs-buy recommendations for new security technologies.
- Security incident and breach response: Run the technical response of security incidents end to end - detection, triage, supporting containment, eradication, recovery and post-incident review. Author and maintain IR playbooks, runbooks and escalation procedures. Production incidents belong to Engineering’s on-call team, but where it impacts security you are the technical security expert of the response.
- Threat Intelligence: Investigate security events, perform root cause analysis, and apply threat intelligence to improve defensive posture. Understand attacker TTPs and operationalise frameworks like MITRE ATT&CK and NIST CSF.
- Vulnerability Management: Own the vulnerability management programme end to end - scanning, prioritisation, remediation tracking, SLA enforcement and reporting to the Head of Security, across infrastructure, endpoints and applications.
- Application & API Security: Assess the security of internal applications, third-party integrations, APIs, payment flows and authentication systems. Identify both technical vulnerabilities and product-level abuse scenarios.
- IAM & Zero Trust: Architect and implement identity and access controls - SSO, MFA, SAML, OAuth, SCIM, conditional access, passwordless authentication. Design and enforce least-privilege and zero trust access policies across all systems.
- Endpoint Security: Define and enforce endpoint security standards at scale - hardening, patching, disk encryption, MDM, device compliance. Own the security posture of the macOS and Windows fleet, with IT Operations running day-to-day device management.
- Access Governance: Design access review and certification programmes and run them with IT Operations. Proactively identify over-provisioned access, orphaned accounts, shadow IT and policy gaps. Maintain a clean, auditable access estate.
- Control Implementation: Implement and test the technical controls behind the security framework - ISO 27001, SOC 2, Cyber Essentials, GDPR. The framework, policies and GRC programme are owned by the Head of Security; the engineering behind them is yours.
- Audit Evidence: Own technical evidence collection, control testing and remediation tracking. Be the person who sits with auditors and delivers clear, documented, defensible answers about the estate.
- Technical Risk: Conduct threat modelling and technical risk assessments. Feed findings and treatment options into the risk register owned by the Head of Security.
- Documentation: Build and maintain the full security documentation estate architecture diagrams, tool configurations, runbooks, incident reports, risk registers, process maps, policy library. Set the standard for what good documentation looks like.
- Security Awareness: Support the security awareness programme with technical content - phishing simulation tooling, engineering inductions, technical policy rollouts. The programme itself is owned by the Head of Security.
- 6+ years in security engineering, enterprise security or security operations
- Deep hands-on experience deploying, configuring, managing and troubleshooting enterprise security tools - EDR/XDR, SASE/SWG, SIEM, DLP, email security, endpoint privilege management, MDM
- Expert-level knowledge of identity and access management SSO, SAML, OAuth, SCIM, conditional access, MFA, passwordless with proven zero trust implementation in production
- Led incident response investigations end to end - built playbooks, managed containment and drove remediation across real-world security incidents
- Strong scripting and automation capability (Python, Bash, PowerShell) applied to detection engineering, security operations and compliance automation
- Practical experience implementing technical controls and producing audit evidence against ISO 27001, SOC 2, Cyber Essentials or GDPR
- Fluent in security frameworks and threat methodologies (MITRE ATT&CK, NIST CSF, CIS Controls, OWASP) with practical application, not just theoretical knowledge
- Experience securing cloud-native and SaaS-heavy environments (AWS preferred)
- Experience in iGaming, fintech or another heavily regulated industry, with understanding of gaming regulatory frameworks and player data protection
- Background in application security, API security testing, secure SDLC or product security within a platform-based business
- Hands-on SIEM detection engineering - writing correlation rules, building dashboards, tuning alert logic at scale
- Experience with cloud security tooling (AWS GuardDuty, Security Hub, CloudTrail, Config), SSPM, CASB or DLP platforms
- Relevant senior certifications (CISSP, CISM, GIAC GSEC/GCIH/GCIA, CySA+, vendor-specific: CrowdStrike CCFA/CCFR, Netskope) or equivalent proven track record
- Experience mentoring engineers and building technical capability
We are committed to fostering a workplace that values and celebrates diversity. We welcome individuals of all backgrounds and experiences, and we believe that a diverse and inclusive environment leads to innovation and success. We actively promote equal opportunities for all employees and strive to create a space where everyone's voices are heard and respected. Join us in our journey to build a truly inclusive workplace where every person can thrive and contribute to our collective success.
To help our recruitment team work efficiently, please apply to the role that best matches your skills and experience. Our team will consider you for other similar roles as well!
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search