Head of Security

MrQ

St Albans

On-site

GBP 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Birthday leave
Parental leave
Health insurance
Wellness incentives
Growth allowance
Flexible working
Diversity & inclusion

Job summary

MrQ is building a dedicated security function with a clear strategy and budget. You will lead Security and IT Operations, shaping how AI is used securely across the platform and guiding governance, risk and compliance at board level.

You will hire and develop the security engineering team, starting with a Principal Security Engineer, and own the security roadmap on an AWS-native estate.

Qualifications

  • Over 10 years in security with leadership exposure at a function or team level.
  • Experience owning GRC: policies, control frameworks, risk registers, audits (ISO 27001, SOC 2, Cyber Essentials or equivalent).
  • Able to report to the CTO and executive team with business-focused risk discussions.
  • Experience securing AI/LLM systems and cloud-native architectures (AWS).
  • Proven track record building or maturing a security function and leading a team.
  • Strong budget management and vendor relationship skills.

Responsibilities

  • Build and lead the security engineering and IT operations teams.
  • Own governance, risk and compliance across the organisation.
  • Define and secure the use of AI across platforms and tools.
  • Manage security tooling (EDR/XDR, SIEM, identity, DLP) and ongoing deployments.
  • Lead incident response planning, regulatory notifications and post-incident reviews.
  • Partner with Compliance on UKGC regulatory matters and write security documentation.

Skills

Security leadership
Security strategy
Risk management
GRC
Cloud security AWS
EDR/XDR
SIEM
IAM
Incident response
Vendor management
Board-level communication
AI security
Team building
Budget ownership

Tools

EDR/XDR
SIEM
AWS
GRC platform
IAM

Job description

Mr Who?

MrQ - we're an awesome, award winning online casino launched in 2018. We're big on tech, big on performance and most of all - big on fun. Over the years, we have experienced explosive growth - which means we need more rock stars to join our quest for total world domination.

Mr Who?

MrQ - we're an awesome, award winning online casino launched in 2018. We're big on tech, big on performance and most of all - big on fun. Over the years, we have experienced explosive growth - which means we need more rock stars to join our quest for total world domination. This is a founding leadership role. We’re building a dedicated security function at MrQ, with its own strategy, roadmap, team and budget, and you’ll be the one building it. You won’t start from zero, and you won’t be handed someone else’s plan. Serious groundwork is already in place: an independent security maturity baseline, a live GRC platform, EDR and identity programmes in deployment, and security investment with real backing from the exec team. The strategy and roadmap from here are yours to define. Pressure-test what’s in flight, keep what works, change what doesn’t. You’ll report directly to the CTO and lead both Security and IT Operations. The Lead of IT Ops reports to you, and you’ll hire and lead the security engineering team, starting with a Principal Security Engineer. This is a player-coach role. We need someone strategic enough to own board-level risk conversations, and technical enough to earn the respect of a Principal-level engineer and challenge architecture decisions on an AWS-native platform. With a small team and serious AI leverage, you’ll build as well as lead. Threat modelling, architecture reviews and AI-powered security tooling are part of the job, not beneath it. Here, automation replaces headcount by design.

What You Will Do
  1. Build and lead the team
  2. Run security engineering and operations
  3. Own governance, risk and compliance
  4. Secure how we build with AI
  5. Build the security culture
  6. Own the security vendor portfolio
What We're Looking For
Highly Desirable
  • Own the security strategy
  • Define and own the security strategy and maturity roadmap. Set priorities, allocate budget and effort, and be accountable for the targets you set.
  • Report security posture, risk and investment cases to the CTO, exec team and board. Translate technical risk into business impact.
  • Make sure security is part of every major technology and product decision, including how we build with AI, not just what we buy.
  • Lead the IT Operations function through its Lead: identity and access, employee onboarding and offboarding, the device fleet, SaaS tools, and data requests (DSARs).
  • Hire, develop and lead the security engineering team, starting with a Principal Security Engineer.
  • Design the function for resilience: clear ownership, documented processes, no single points of failure.
  • Own the security tooling end to end (EDR/XDR, SIEM, identity, vulnerability management, email security, DLP), including the deployments already in flight.
  • Own security incident and breach response: deciding severity, directing containment, regulatory notification (ICO, UKGC) and post-incident review. Production incidents belong to Engineering’s on-call team. You own the security path and the call on when an incident is, or might become, a security event.
  • Direct security across a cloud-native AWS estate: platform, payment flows, APIs, player data.
  • Own the GRC programme: risk register, policies, control framework, audit readiness (ISO 27001 path, Cyber Essentials, GDPR) and the compliance-automation platform behind it.
  • Partner with Compliance on the regulatory side of a UKGC-licensed operator: player data protection, technical standards, audit evidence.
  • Build documentation to a standard that survives external scrutiny: auditors, regulators and commercial due diligence.
  • MrQ is deeply AI-native: AI agents, internal AI platforms and AI-assisted engineering across the company. Own the security model for all of it: the AI gateway, agent permissions and sandboxing, data boundaries, and governance of third-party AI tools.
  • Own the company’s AI usage policy: which tools are approved, what data they can touch, and what agents are allowed to do on their own.
  • This is greenfield in most companies. Here it’s live production surface. Treat it as a first‑class part of the threat model.
  • Own security awareness across the company: training, phishing simulations, onboarding inductions, and security champions inside the squads. Make security something people do, not something done to them.
  • Own vendor selection, commercial relationships and spend across the security stack. Run build‑vs‑buy honestly. Kill tools that don’t earn their keep.
  • 10+ years in security, including 3+ years leading a security function or team with real budget and hiring ownership
  • Built or significantly matured a security function before: you’ve taken a company up a maturity curve, not just operated inside a mature one
  • Deep technical credibility: you can hold your own with senior security and platform engineers on EDR, SIEM, identity and cloud security (AWS), and you know when to defer
  • Direct experience owning GRC: policies, control frameworks, risk registers, and leading audits (ISO 27001, SOC 2, Cyber Essentials or equivalent)
  • Led security incident response at company level: you’ve owned real incidents, not just contributed to them
  • Managed managers or senior individual contributors, ideally including an IT operations remit
  • Exec‑level communicator: you can hold a board conversation about risk appetite and a whiteboard session about detection logic in the same day
  • Pragmatist: balances risk with business enablement in a company that ships fast
  • Builder’s mindset in the age of AI: you’d rather automate a control than staff it, and you use AI tooling to make a small team punch far above its weight
  • iGaming, fintech or another heavily regulated industry; UKGC or similar gaming regulation and player data protection are a strong plus
  • Experience securing AI/LLM systems: agent architectures, model access controls, AI tooling governance
  • Experience preparing a security function for commercial due diligence or external investment scrutiny
  • Application or product security background in a platform business
  • Relevant senior certifications (CISSP, CISM, CCISO) or an equivalent proven track record

At MrQ, we take pride in providing an array of fantastic benefits to our valued team members. Enjoy a competitive salary package that recognizes your hard work and dedication. Need some extra time off? We've got you covered with additional leave days, and we believe in celebrating life's special moments, including your birthday, with dedicated birthday leave. Family matters to us, too, which is why we offer a generous four‑week parental leave. Your well-being is our priority, supported by international health and life insurance. Stay motivated with wellness incentives and seize opportunities for personal and professional growth with our growth allowance. Embrace a flexible working environment that caters to your needs, and join our friendly and multinational team, where collaboration and camaraderie flourish. At MrQ, we’re committed to ensuring that your experience with us goes beyond just a job – it’s a fulfilling journey with a supportive community.

We are committed to fostering a workplace that values and celebrates diversity. We welcome individuals of all backgrounds and experiences, and we believe that a diverse and inclusive environment leads to innovation and success. We actively promote equal opportunities for all employees and strive to create a space where everyone's voices are heard and respected. Join us in our journey to build a truly inclusive workplace where every person can thrive and contribute to our collective success.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Engineer
Principal Security Engineer

MrQ • St Albans

On-site
GBP 120,000 - 170,000
Birthday leave
Parental leave
Health insurance
Product Marketing Manager
Product Marketing Manager

MrQ Masters • United Kingdom

Hybrid
GBP 45,000 - 65,000
Competitive salary package
Additional leave days
Birthday leave
+5
Staff Creative Design Lead
Staff Creative Design Lead

MrQ • Greater London

Hybrid
GBP 75,000 - 120,000
Birthday leave
Parental leave
Health insurance
+4
Senior Offensive Security Engineer (Autonomous testing)
Senior Offensive Security Engineer (Autonomous testing)

Hollybank Trustees Ltd • City of Edinburgh

Hybrid
GBP 90,000 - 130,000
World-class benefits
Social Media Content Creator
Social Media Content Creator

MrQ • St Albans

Hybrid
GBP 32,000 - 45,000
Birthday leave
Parental leave
Health insurance
+4
Senior Offensive Security Engineer (Autonomous testing)
Senior Offensive Security Engineer (Autonomous testing)

Quorum Cyber • City of Edinburgh

On-site
GBP 90,000 - 140,000
Staff Creative Design Lead
Staff Creative Design Lead

MrQ • St Albans

On-site
GBP 90,000 - 120,000
AML Officer
AML Officer

MrQ • St Albans

On-site
GBP 30,000 - 50,000
Competitive salary
Additional leave days
Birthday leave
+5
Player Protection Executive (Day Shifts)
Player Protection Executive (Day Shifts)

Rank Group • Sheffield

On-site
GBP 30,000 - 50,000
Hybrid and flexible working hours
Wellbeing program and support networks
Private medical insurance
Senior Security Engineer
Senior Security Engineer

FairPlay Sports Media • Greater London

Hybrid
GBP 95,000 - 135,000
Unlimited holiday
Pension scheme
Discount Sky package
+3