O

Platform Security Engineer / DevSecOps

orsun tech Bratislava Metropolitan Area
Relocation
Apply
AI Summary

Hands-on platform engineering role combining AWS/Kubernetes operations with cloud security ownership for a new iGaming product. Responsibilities include building secure CI/CD pipelines, implementing detection engineering, and leading ATT&CK-based purple teaming. Requires strong DevOps/SRE experience, fluency in Ukrainian or Russian, and a pragmatic approach to security and reliability.

Key Highlights
Hybrid role combining hands-on AWS/Kubernetes platform engineering with end-to-end security ownership.
Focus on building security into the platform from the start, including threat modeling, detection engineering, and purple teaming.
Fluency in Ukrainian or Russian is required, with working English for a team of 250+ professionals.
Key Responsibilities
Design, build, and operate the AWS and Kubernetes platform together with the DevOps/SRE team.
Maintain infrastructure as code, CI/CD pipelines, environments, secrets, and deployment workflows.
Improve platform reliability, observability, scalability, backup, recovery, and production readiness.
Participate in platform on-call, incident response, root-cause analysis, and continuous operational improvement.
Own the cloud and Kubernetes security baseline, including IAM, network boundaries, secrets, audit logging, container security, and privileged access.
Build security controls into the software delivery lifecycle using SAST, SCA, secret scanning, IaC scanning, container scanning, and policy gates.
Lead threat modelling for critical areas such as authentication, wallet and ledger, payments, game-provider integrations, callbacks, and backoffice privileges.
Use OWASP ASVS to define practical application-security requirements and verification criteria with Tech Leads and developers.
Establish vulnerability-management processes, severity rules, remediation SLAs, evidence, and retesting.
Develop security monitoring, detection logic, incident playbooks, and security exercises using available cloud, infrastructure, and application telemetry.
Coordinate external penetration tests, define the scope and rules of engagement, triage findings, and drive remediation through formal retesting.
Design ATT&CK-mapped adversary-emulation and purple-team scenarios based on real risks to the platform.
Use or integrate tools such as MITRE CALDERA and Atomic Red Team for controlled security validation.
Work with developers acting as Security Champions to turn findings into controls, tests, detections, and regression coverage.
Help build a small AI-assisted internal platform for threat-model support, control mapping, scenario management, evidence collection, remediation tracking, and reporting.
Ensure offensive testing is authorised, scoped, auditable, and safe for the target environment.
Technical Skills Required
Amazon Web Services Kubernetes DevSecOps
Benefits & Perks
Full relocation assistance for you and your family
One month of accommodation covered on arrival
Real-estate agent fees covered
Annual learning and development budget
Top-tier hardware of your choice
28 calendar days of paid vacation per year
A paid day off on your birthday
Fully paid sick leave
Flexible hybrid schedule
Nice to Have
Experience in iGaming, fintech, payments, high-risk platforms, or other regulated environments.
Experience with wallet/ledger systems, payment providers, game providers, KYC/AML, or backoffice security.
Hands-on knowledge of OWASP ASVS, threat modelling, MITRE ATT&CK, CALDERA, or Atomic Red Team.
Experience leading purple-team exercises, detection engineering, security incident simulations, or external pentest remediation.
Knowledge of Kafka or RabbitMQ, PostgreSQL, Redis, microservices, and Node.js/NestJS environments.
Experience using modern AI-assisted engineering or security tools and the judgement to apply them safely.
Relevant AWS, Kubernetes, security, or offensive-security certifications.

Job Description


Location: Bratislava, Slovakia

Employment: Full-time | Office-first with a flexible hybrid schedule

Language: Fluency in Ukrainian or Russian is required


Role profile: This is a hands-on platform engineering role with security ownership - not a pure compliance position and not a standalone penetration-testing role.


About the Role

We are building our own iGaming product for Tier-1 markets and are looking for a Platform Security Engineer / DevSecOps to join our engineering team in Bratislava.

We are a Ukrainian marketing group with more than four years of experience in iGaming. During this time, we have grown to a team of over 250 professionals and built a strong in-house ecosystem. We are now entering a new stage of growth: developing our own iGaming platform with a core team and technical roadmap already in place.

You will work alongside our DevOps/SRE and engineering teams. Your role combines hands-on AWS and Kubernetes platform work with cloud security, secure delivery, detection engineering, incident readiness, and ATT&CK-based adversary emulation. You will help us build security into the platform from the start instead of attaching it as a PDF shortly before launch.



Key Responsibilities

Platform Engineering & Reliability

  • Design, build, and operate our AWS and Kubernetes platform together with the DevOps/SRE team.
  • Maintain infrastructure as code, CI/CD pipelines, environments, secrets, and deployment workflows.
  • Improve platform reliability, observability, scalability, backup, recovery, and production readiness.
  • Participate in platform on-call, incident response, root-cause analysis, and continuous operational improvement.
  • Create reusable platform standards that help engineering teams ship safely and consistently.

Security Engineering

  • Own the cloud and Kubernetes security baseline, including IAM, network boundaries, secrets, audit logging, container security, and privileged access.
  • Build security controls into the software delivery lifecycle using SAST, SCA, secret scanning, IaC scanning, container scanning, and policy gates.
  • Lead threat modelling for critical areas such as authentication, wallet and ledger, payments, game-provider integrations, callbacks, and backoffice privileges.
  • Use OWASP ASVS to define practical application-security requirements and verification criteria with Tech Leads and developers.
  • Establish vulnerability-management processes, severity rules, remediation SLAs, evidence, and retesting.
  • Develop security monitoring, detection logic, incident playbooks, and security exercises using available cloud, infrastructure, and application telemetry.
  • Coordinate external penetration tests, define the scope and rules of engagement, triage findings, and drive remediation through formal retesting.

Purple Teaming & Security Automation

  • Design ATT&CK-mapped adversary-emulation and purple-team scenarios based on real risks to our platform.
  • Use or integrate tools such as MITRE CALDERA and Atomic Red Team for controlled security validation.
  • Work with developers acting as Security Champions to turn findings into controls, tests, detections, and regression coverage.
  • Help build a small AI-assisted internal platform for threat-model support, control mapping, scenario management, evidence collection, remediation tracking, and reporting.
  • Ensure offensive testing is authorised, scoped, auditable, and safe for the target environment.

You Will Be a Great Fit If You Have

  • Strong commercial experience in DevOps, Platform Engineering, SRE, Cloud Security, or DevSecOps.
  • Hands-on experience with AWS, Kubernetes, Docker, Linux, networking, and infrastructure as code.
  • Practical experience with CI/CD, observability, secrets management, IAM, and production incident response.
  • A solid understanding of cloud, container, API, and application-security risks.
  • Experience implementing security scanning and vulnerability-management processes in engineering workflows.
  • The ability to read code, understand service architecture, and work directly with backend and frontend engineers.
  • A pragmatic engineering mindset: you can balance security, reliability, delivery speed, and business risk.
  • Good communication skills and the ability to explain risks and remediation clearly to both technical and non-technical stakeholders.
  • Fluency in Ukrainian or Russian, plus working English.

Nice to Have

  • Experience in iGaming, fintech, payments, high-risk platforms, or other regulated environments.
  • Experience with wallet/ledger systems, payment providers, game providers, KYC/AML, or backoffice security.
  • Hands-on knowledge of OWASP ASVS, threat modelling, MITRE ATT&CK, CALDERA, or Atomic Red Team.
  • Experience leading purple-team exercises, detection engineering, security incident simulations, or external pentest remediation.
  • Knowledge of Kafka or RabbitMQ, PostgreSQL, Redis, microservices, and Node.js/NestJS environments.
  • Experience using modern AI-assisted engineering or security tools and the judgement to apply them safely.
  • Relevant AWS, Kubernetes, security, or offensive-security certifications are welcome, but practical experience matters more.



What Success Looks Like in the First 90 Days

First 30 days

Understand the platform and threat model; complete the initial service/access inventory; identify crown jewels and critical launch risks; agree the security backlog and external pentest plan.

Days 31-60

Implement priority cloud/Kubernetes hardening and delivery-pipeline controls; establish ASVS-based requirements and threat models for critical services; validate security telemetry and incident paths.

Days 61-90

Run the first focused purple-team campaign; coordinate the pre-launch pentest; drive remediation and retesting; publish launch-readiness evidence and the next-quarter roadmap.



What We Offer

Relocation & Settling In

  • Full relocation assistance for you and your family.
  • One month of accommodation covered on arrival.
  • Real-estate agent fees covered to help you find a home.
  • Support with paperwork and getting set up in Bratislava.

Growth & Equipment

  • Annual learning and development budget for courses, certifications, conferences, and books.
  • Top-tier hardware of your choice and everything you need to do your best work.
  • A modern engineering stack and an AI-assisted workflow that lets you ship fast.
  • Real ownership of the security roadmap and the freedom to build practical internal tooling.

Time Off & Wellbeing

  • 28 calendar days of paid vacation per year.
  • A paid day off on your birthday.
  • Fully paid sick leave.
  • A flexible hybrid schedule based in Bratislava.

Team & Environment

  • A small, senior engineering team with real ownership and minimal bureaucracy.
  • A flat structure where your decisions ship and your input matters.
  • Direct collaboration with the CTO, Tech Leads, DevOps/SRE, and product stakeholders.
  • Substantial resources for platform development, security validation, and external testing.
  • Competitive compensation, by agreement.

  • Why join: You will help shape the platform before launch, own security as an engineering capability, and build systems that are used rather than admired once per audit.



    Similar Jobs

    Explore other opportunities that match your interests

    Head of Data Protection & Cybersecurity Risk

    Cyber Security
    4h ago

    Premium Job

    Sign up is free! Login or Sign up to view full details.

    •••••• •••••• ••••••
    Job Type ••••••
    Experience Level ••••••

    FIFA

    Switzerland

    Principal Systems Security Engineer (Anti-Tamper/Program Protection) - P4

    Cyber Security
    5h ago

    Premium Job

    Sign up is free! Login or Sign up to view full details.

    •••••• •••••• ••••••
    Job Type ••••••
    Experience Level ••••••

    Raytheon

    United State
    Visa Sponsorship Relocation Remote
    Job Type Full-time
    Experience Level Associate

    twentyfour industries

    Germany

    Subscribe our newsletter

    New Things Will Always Update Regularly