Senior DevSecOps Engineer
Who are we?
Smarkets: Predicting the Future of Betting
Smarkets is a prediction market exchange for sports and political trading, having handled over $50 billion in volume since 2010. We're upending sports betting with the fairest prices, the best technology, and a superior customer experience, powered by attracting great people and building a high-performance environment where they thrive. We're looking for an atypical candidate with strong regulated-business experience to support our growing CFTC business.
The Team
Security sits within Infrastructure and Engineering, protecting the distributed, real-time systems behind our trading engine. The team's remit spans our core products and our DCM/DCO entities, with a real regulatory dimension to the work, particularly around our CFTC-regulated business units. Alongside that regulatory scope, the focus is squarely on hands-on engineering: designing, building, and shipping the security tooling and controls that let engineering teams move fast safely.
About the Role:
This is a founding build. You'll stand up security engineering from the ground up through go-live and mature it as we scale, working within Infrastructure and Engineering teams to build the controls, automation, and guardrails our trading systems and regulated entities need.
What you will do:
Build the Foundations: Be part of a founding build, standing up security engineering from the ground up through go-live and maturing it as we scale, working within Infrastructure and Engineering teams.
Design Guardrails: Design, build, and deploy security controls and guardrails across cloud-native platforms, including AI security solutions protecting customer-facing and internal products.
Automate as Code: Automate security processes as code, embedding compliance and infrastructure-as-code checks into CI/CD pipelines without slowing down frequent shipping.
Assess & Remediate: Conduct risk audits and assessments, translating findings into practical recommendations for engineering teams, and be hands-on in implementing those recommendations.
Monitor & Respond: Monitor and analyse system access logs, flag anomalies, and support incident response, containment, and post-incident root cause analysis.
Plan for Resilience: Plan and test security backups and disaster recovery processes to keep the platform resilient.
Maintain Compliance: Develop and maintain security policies, standards, and controls meeting DCM/DCO requirements, and maintain evidence and documentation to support regulatory examinations and audits.
Partner Across Teams: Partner with business and engineering teams on solutions, translating technical work for product and engineering audiences.
Champion Ownership: Build a culture of security ownership among engineers, acting as a security partner rather than a gatekeeper.
Role Requirements:
Security Engineering Background: Hands-on experience building security engineering/DevSecOps capabilities in a cloud-native, high-growth environment, ideally financial services or exchange infrastructure.
Confident Communicator: Comfortable communicating security risk, controls and technical decisions verbally and in writing to external stakeholders such as auditors or regulators.
Regulatory Familiarity: Familiarity with CFTC system safeguards expectations, including 17 C.F.R. § 38.1051 and § 39.18 or similar regulatory requirements.
AppSec Foundations: Strong grasp of application security principles (OWASP Top 10, NIST) and secure SDLC practices.
CI/CD & Tooling: Proficiency with CI/CD tooling (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, CircleCI) and security tools (Snyk, Aqua, Trivy, Checkov, Twistlock, Clair).
Cloud & Container Security: Hands-on expertise securing AWS/Azure/GCP, Kubernetes, containers, and IaC.
Compliance as Code: Working knowledge of infrastructure-as-code and compliance-as-code practices.
Automation Proficiency: Proficiency in at least one of Python, Bash, or Go, with a track record of automating security processes.
Nice-to-have: Demonstrated experience deploying AI security solutions, guardrails, and defences for AI systems used by customers; a personal interest in sports, exchanges, or trading; certifications such as DSOP, CKS, CISSP, CCSP, CSSLP, or an AWS/Azure/GCP Security Specialty; a track record of security automation at scale in Agile/Scrum environments; direct experience with regulators/examiners on technology and system safeguards; and familiarity with event contracts, prediction markets, or similar novel futures products under CFTC.
Our Values
Our values are at the heart of everything we do, guiding how we work, collaborate, and innovate. They reflect what we expect of ourselves and each other to deliver the best results, while fostering a positive, high-performing environment:
Push to Win: We set ambitious goals and relentlessly pursue them, always striving for excellence.
Make Others Better: We lift each other up, share knowledge, and celebrate team success over individual achievement.
Give a Shit: We care deeply about our work, our users, and the impact we make.
Be a Pro: We take ownership, act with integrity, and consistently deliver to a high standard.
Bring the Energy: We bring positivity, curiosity, and enthusiasm to everything we do, inspiring those around us.
Culture Fit: These values define how we succeed as a team. If this isn't you, this may not be the right place. We hire people who thrive in a fast-paced, collaborative, and ambitious environment.
Perks & Benefits
We offer a competitive salary and benefits package, alongside a dynamic, collaborative environment where your work truly makes an impact and your voice is heard. Our team is diverse, driven, and ambitious, united by a strong work ethic and a hunger to innovate and win.
Our benefits are designed around Health, Wealth, and Development, supporting you both professionally and personally. These include:
Stock Options: Vest over 4 years, your success is our success.
Pension Scheme: Competitive plan via Aviva, with up to 6% matched contributions if you opt in.
Health Insurance: Comprehensive coverage to keep you and your family healthy.
Enhanced Parental Leave: Enhanced maternity and paternity leave to support you through life's most important moments.
Stay Fuelled: Enjoy fresh, chef-made breakfast and lunch every day, plus a constant supply of fruit, snacks, tea, coffee and soft drinks, because great work starts with great food.
Cycle-to-Work Scheme: Support for sustainable commuting and staying active.
Learning & Development: £1,000 annual education budget for courses, conferences, books, or training.
Holiday: 25 days paid leave plus bank holidays, with the option to carry over 5 days.
Flexible Working: Hybrid model with 3 days in the office and 2 days from home to fit your lifestyle.
Global Working: Work from anywhere in the world for up to 20 days a year.
Team Energy: Regular socials, hackathons, and events, because collaboration and fun go hand-in-hand.
What happens next
CV application review: We will review it as quickly as possible.
Let's chat: A quick chat with our team about your experience and the role.
Competency Interview: Virtual with the Hiring Manager.
In-Office Interview: Meet the wider team.
Diversity & Inclusion
We're an equal opportunities employer and celebrate diversity in all its forms. If you need any adjustments during the recruitment process, please let us know; we're happy to accommodate your needs.
Smarkets is an Equal Opportunity Employer, committed to equality, inclusion, and a welcoming environment for all.
