Senior DevSecOps Engineer
The organisation is seeking a Senior DevSecOps Engineer to play a key part in delivering secure applications and providing hands-on security support to developers. This is a multi-disciplinary engineering role with a focus on application and platform security controls, requiring close collaboration with development teams to improve security outcomes.
The role involves acting as a technical authority across development, platform, operations, and information security. The successful candidate will help the organisation move faster and improve smarter by ensuring that secure and compliant approaches are the default and easiest options for development teams to adopt.
- Integrate and operate application security controls within CI/CD pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secrets detection and dependency risk scanning.
- Support secure SDLC practices such as branch protection and quality gates, secure build and release controls, artifact integrity and validation checks.
- Assist with threat modelling and secure design reviews in collaboration with architecture teams.
- Support developers in vulnerability triage and remediation.
- Tune security tools to reduce false positives and developer friction.
- Support audit, compliance, and evidence generation activities.
- Participate in security incident investigation related to application flaws.
- Ensure secure, compliant approaches are the default and easiest options for development teams to adopt.
- Configure and maintain security tooling integrations within CI/CD systems (e.g. GitHub Actions, GitLab CI, Jenkins, Azure DevOps) under agreed architectural standards.
- Ensure security controls operate consistently across teams and repositories.
- Define and document DevSec security standards, patterns, and decisions.
- Provide evidence and control mappings to support audits, risk assessments, and regulatory reviews.
- Identify and track DevSec-related risks and technical debt, driving remediation through process improvements rather than manual controls.
- Influence security outcomes through collaboration and technical leadership rather than enforcement.
- Contribute to security enablement, awareness, and uplift initiatives focused on cloud-native and container security practices.
- Clear, confident communication (written and verbal), and the ability to breakdown complex ideas (required)
- Collaborative mindset, working smoothly with cross-functional teams to hit shared goals (required)
- Strong organisational skills and the ability to manage multiple projects without dropping the ball (required)
- Exceptional attention to detail and a commitment to high-quality work (required)
- Adaptability – you stay sharp, productive and positive in fast-moving environments (required)
- Strong grounding in application security concepts (required)
- Secure coding knowledge (OWASP Top 10, API security, dependency risk) (required)
- Strong knowledge of SAST, DAST, SCA, and software supply-chain security concepts (required)
- Strong advocate for enablement-first security (required)
- Ability to influence engineering teams through collaboration and technical credibility (required)
- Hands-on expertise with containers and orchestration platforms (e.g. Docker, Kubernetes) (required)
- Demonstrated experience implementing container security across build, registry, and runtime (required)
- Proven experience securing CI/CD pipelines and developer toolchains (required)
- Knowledge of Infrastructure as Code (Terraform, Bicep, CloudFormation, etc.) (required)
- Knowledge of secrets and key management (required)
- Knowledge of cloud identity and access management (required)
- Solid understanding of information security frameworks (e.g. ISO 27001) (required)
- Experience operating in regulated or audited environments (required)
- Able to design controls that are auditable without slowing delivery (required)
- In-depth knowledge of sports betting markets, including odds calculation, betting types and market trends (nice-to-have)
- Previous experience in the online gaming or casino industry, with a strong understanding of player behaviour and industry regulations (nice-to-have)
- Familiarity with gambling regulations and compliance requirements in various jurisdictions, ensuring adherence to legal standards (nice-to-have)
- Experience in developing and executing customer retention strategies (nice-to-have)
- Experience operating at scale in multi-team or multinational environments (nice-to-have)
- Prior involvement in audits, regulatory reviews, or formal assurance activities (nice-to-have)
- Supergrowth learning and development programmes
- Performance tool for meaningful feedback
- Employee Assistance Programme
- Private Health Care
- Life Assurance
- Income Protection
- Company Pension
Betway Group is an online gambling operator founded in 2006 and part of Super Group, which is listed on the New York Stock Exchange under the ticker SGHC. It provides entertainment across sports betting, casino and esports betting, built on proprietary and latest-generation technologies. The company offers interactive gaming experiences spanning pre-game and live sports betting, esports and casino in a regulated, responsible environment. Betway is headquartered in Gzira, Malta, and operates across multiple international markets.
