InfrastructureAWSPlatformCI/CDKubernetesAzureGCPJenkinsIaCGitlab CI
📋 Job Overview
Smarkets: Predicting the Future of Betting Smarkets is a prediction market exchange for sports and political trading, having handled over $50 billion in volume since 2010. We're upending sports betting with the fairest prices, the best technology, and a superior customer experience, powered by attracting great people and building a high-performance environment where they thrive. We're looking for an atypical candidate with strong regulated-business experience to support our growing CFTC business.
🏢 About Smarkets
Security sits within Infrastructure and Engineering, protecting the distributed, real-time systems behind our trading engine. The team's remit spans our core products and our DCM/DCO entities, with a real regulatory dimension to the work, particularly around our CFTC-regulated business units. Alongside that regulatory scope, the focus is squarely on hands-on engineering: designing, building, and shipping the security tooling and controls that let engineering teams move fast safely.
🎯 The Role
This is a founding build. You'll stand up security engineering from the ground up through go-live and mature it as we scale, working within Infrastructure and Engineering teams to build the controls, automation, and guardrails our trading systems and regulated entities need.
✅ Key Responsibilities
Build the Foundations: Be part of a founding build, standing up security engineering from the ground up through go-live and maturing it as we scale, working within Infrastructure and Engineering teams.
Design Guardrails: Design, build, and deploy security controls and guardrails across cloud-native platforms, including AI security solutions protecting customer-facing and internal products.
Automate as Code: Automate security processes as code, embedding compliance and infrastructure-as-code checks into CI/CD pipelines without slowing down frequent shipping.
Assess & Remediate: Conduct risk audits and assessments, translating findings into practical recommendations for engineering teams, and be hands-on in implementing those recommendations.
Monitor & Respond: Monitor and analyse system access logs, flag anomalies, and support incident response, containment, and post-incident root cause analysis.
Plan for Resilience: Plan and test security backups and disaster recovery processes to keep the platform resilient.
Maintain Compliance: Develop and maintain security policies, standards, and controls meeting DCM/DCO requirements, and maintain evidence and documentation to support regulatory examinations and audits.
Partner Across Teams: Partner with business and engineering teams on solutions, translating technical work for product and engineering audiences.
Champion Ownership: Build a culture of security ownership among engineers, acting as a security partner rather than a gatekeeper.
📌 Required Qualifications
Security Engineering Background: Hands-on experience building security engineering/DevSecOps capabilities in a cloud-native, high-growth environment, ideally financial services or exchange infrastructure.
Confident Communicator: Comfortable communicating security risk, controls and technical decisions verbally and in writing to external stakeholders such as auditors or regulators.
Regulatory Familiarity: Familiarity with CFTC system safeguards expectations, including 17 C.F.R. § 38.1051 and § 39.18 or similar regulatory requirements.
AppSec Foundations: Strong grasp of application security principles (OWASP Top 10, NIST) and secure SDLC practices.
Compliance as Code: Working knowledge of infrastructure-as-code and compliance-as-code practices.
Automation Proficiency: Proficiency in at least one of Python, Bash, or Go, with a track record of automating security processes.
⭐ Desirable Experience
Demonstrated experience deploying AI security solutions, guardrails, and defences for AI systems used by customers.
A personal interest in sports, exchanges, or trading.
Certifications such as DSOP, CKS, CISSP, CCSP, CSSLP, or an AWS/Azure/GCP Security Specialty.
A track record of security automation at scale in Agile/Scrum environments.
Direct experience with regulators/examiners on technology and system safeguards.
Familiarity with event contracts, prediction markets, or similar novel futures products under CFTC.
🎁 Benefits
We offer a competitive salary and benefits package, alongside a dynamic, collaborative environment where your work truly makes an impact and your voice is heard. Our team is diverse, driven, and ambitious, united by a strong work ethic and a hunger to innovate and win.
Our benefits are designed around Health, Wealth, and Development, supporting you both professionally and personally.
🛂 Visa & Eligibility
We're looking for an atypical candidate with strong regulated-business experience to support our growing CFTC business.
Please let Smarkets know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.