2,818 Open roles
102 Companies
95 Posted today
Jobs / LeoVegas / Senior Application Security Engineer
Posted 2026-07-28

Senior Application Security Engineer

Description

LeoVegas is looking for a hands-on Senior Application Security Engineer to become a founding member of its security team. The role is based in a highly regulated iGaming environment where uptime, data integrity, and user trust are paramount. The successful candidate will shape the security of consumer-facing platforms and the underlying cloud infrastructure, balancing compliance requirements with the agility needed for business growth.

This position offers the opportunity to help build an application security practice and tooling from the ground up. The role involves working in a high-stakes environment where security directly impacts user trust, real-time operations, and the bottom line.

Responsibilities
  • Embed security into every stage of the software development lifecycle, from threat modelling at design time to security review before release.
  • Partner with engineering to make secure-by-default the path of least resistance.
  • Drive and run security testing and code review across web and mobile applications.
  • Review and harden the APIs powering platforms with a focus on authorisation and abuse prevention.
  • Manage and tune WAF and DDoS mitigation.
  • Harden the cloud environment where it matters most for application security.
  • Automate security checks, reduce manual toil, and ensure consistent controls across pipelines and environments.
  • Act as the technical bridge for regulatory and ISO certifications.
  • Work closely with engineering and product teams to champion a Security by Design culture.
  • Drive collaboration with Google to architect the future of AI workflows and security frameworks.
Requirements
  • Strong background in securing high-scale, consumer-facing applications across mobile and web (required).
  • Deep knowledge of the OWASP Top 10 (required).
  • Ability to read and audit code in modern high-level languages and use automated tools (required).
  • Deep, foundational understanding of networking protocols including TCP/IP, DNS, HTTP/S, and TLS (required).
  • Working knowledge of cloud security, Kubernetes, and the trade-offs of running microservices at scale (required).
  • Experience thriving in industries with strict compliance requirements such as iGaming, Fintech, or Healthcare (required).
  • Ability to automate security workflows with Python or similar languages (required).
  • Pragmatic communication skills to weigh business goals against security risk (required).
  • Experience evaluating, onboarding, and managing external security vendors or managed service providers (required).
Benefits
  • Hybrid work policy with 3 days a week in the office.
  • 4 weeks of Workation (terms and conditions apply).
  • 300 EUR wellness contribution annually.
  • Cobee benefits app with flexible compensation and discounts.
  • Health insurance via Alan.
  • Life insurance.
  • Employee Assistance Program providing free emotional, legal, and financial support.
  • Short Fridays with work ending at 16:00.
  • Complimentary snacks and drinks in offices, including Monday breakfast and Wednesday fika.
  • Team and office social events throughout the year.
About LeoVegas

LeoVegas Group is a Swedish mobile-first iGaming company founded in 2011, headquartered in Stockholm with its main operational hub in Sliema, Malta. A pioneer of mobile casino, it operates online casino and sportsbook products across regulated markets through brands including LeoVegas, BetUK, Expekt, Pink Casino and GoGo Casino. In 2022 the group was acquired by MGM Resorts International and now serves as MGM's international online-gaming arm, having previously been listed on Nasdaq Stockholm.

Read more about LeoVegas →

Apply on LeoVegas →