Overview
As the inaugural Head of Security Engineering, you will establish and mature Smarkets’ security program for real-time, cloud-native trading platforms. You’ll build security from the ground up across core products and regulatory entities, reporting to senior leadership and the Board to ensure robust risk management and incident response. You’ll work closely with Infrastructure and Engineering to implement pragmatic, scalable security controls that meet regulatory expectations. This role offers strategic impact at a high-growth, regulated exchange and a chance to shape secure, reliable trading technology.
Pay / Benefits
- Competitive salary + stock options (4-year vesting)
- Private health insurance
- Pension (up to 6%)
- 1,000 annual education budget
- 25 days annual leave + bank holidays (5 days carryover)
- Hybrid working, plus 20 remote days/year globally
Responsibilities
- Establish and evolve the security program within Infrastructure and Engineering
- Own regulatory engagement, including CFTC interactions and external expectations
- Define a risk-based security strategy across cloud infra, applications, and trading systems
- Lead or support security incident response, including post-incident analysis and remediation
- Integrate security into the SDLC (SAST, DAST, SCA, container/IaC scanning) without bottlenecks
- Implement controls across AWS, Kubernetes, containers, and IaC; harden identity, secrets, and network access
- Establish security monitoring and detection for applications, APIs, and infrastructure
- Develop and maintain security policies and controls meeting DCM/DCO requirements
- Maintain evidence and documentation for regulatory examinations and audits
- Act as a security partner to engineers to foster ownership of security within teams
Key requirements
- Hands-on security leadership in cloud-native, high-growth environments (finance or exchange infrastructure preferred)
- Strong communication skills for executive, board, and regulator audiences
- Familiarity with CFTC safeguards and relevant regulations (e.g., 17 C.F.R. § 38.1051, § 39.18)
- Solid understanding of application security (OWASP Top 10, NIST) and secure SDLC practices
- Proficiency with CI/CD tooling (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, CircleCI) and security tools (Snyk, Aqua, Trivy, Checkov, Twistlock, Clair)
- Hands-on experience securing AWS/Azure/GCP, Kubernetes, containers, and IaC
- Proficiency in programming/scripting (Python, Bash, Go)
- Track record of security automation at scale in Agile/Scrum
- Direct experience with regulators/examiners on technology and system safeguards
- Excellent communicator at executive, board, and regulatory levels
- Collaborative partner to engineers; advocates for security ownership
- Strategic thinker with a pragmatic, risk-based approach
- Cloud security (AWS/Azure/GCP)
- Kubernetes and container security
- IaC security (scanning and hardening)
…
