Head of Security Engineering (DevSecOps & CISO)

United States Digital Space LLC

Greater London

Hybrid

GBP 140,000 - 230,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Private health insurance
Pension (up to 6%)
£1,000 annual education budget
Hybrid working
20 remote days/year globally
Stock options (4-year vesting)
In-house chef, daily snacks and drinks
Cycle to work scheme

Job summary

United States Digital Space LLC is seeking an inaugural Head of Security Engineering (DevSecOps & CISO) to lead our security program across core products and trading platforms. You will build from the ground up, partner with Infrastructure and Engineering, and report to senior leadership and the Board to define risk-based security strategy and ensure regulatory standards are exceeded.

The role requires hands-on security engineering in a cloud-native environment, experience with AWS/GCP/Azure,

Qualifications

  • Security expert with hands-on experience building security engineering/DevSecOps capabilities in a cloud-native, high-growth environment — ideally financial services or exchange infrastructure
  • Excellent communication skills for executive, board, and regulatory audiences
  • Familiarity with CFTC system safeguards expectations, including 17 C.F.R. § 38.1051 and § 39.18 or similar regulatory requirements
  • Strong grasp of application security principles (OWASP Top 10, NIST) and secure SDLC practices
  • Proficiency with CI/CD tooling (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, CircleCI) and security tools (Snyk, Aqua, Trivy, Checkov, Twistlock, Clair)
  • Hands-on expertise securing AWS/Azure/GCP, Kubernetes, containers, and IaC
  • Proficiency in Python, Bash, Go, or similar

Responsibilities

  • First dedicated security engineering hire, working from within Infrastructure and Engineering teams to establish and evolve the company' security capabilities
  • Own regulatory/industry engagement (including CFTC), reflecting external expectations in internal practice
  • Define a pragmatic, risk-based security strategy across cloud infrastructure, applications, trading systems, and corporate environment
  • Lead or support the investigation, containment and remediation of security incidents, including post-incident root cause analysis and corrective actions.
  • Work with Engineering teams to build security into the SDLC — SAST, DAST, SCA, container/IaC scanning in CI/CD — without becoming a delivery bottleneck
  • Implement controls across AWS, Kubernetes, containers, and IaC, hardening identity, secrets, and network access
  • Establish security monitoring and detection across applications, APIs, and infrastructure
  • Develop and maintain security policies, standards, and controls meeting DCM/DCO requirements
  • Maintain evidence and documentation to support regulatory examinations and audits
  • Act as a security partner to engineers, building a culture of ownership over security

Skills

Security engineering
DevSecOps
Cloud security
CI/CD tooling
Regulatory awareness
Kubernetes security
Python/Bash/Go
Executive comms
CFTC familiarity

Tools

Snyk
Aqua
Trivy
Checkov
Twistlock
Clair
GitHub Actions
GitLab CI
Jenkins
Azure DevOps
CircleCI
AWS
GCP

Job description

Head of Security Engineering (DevSecOps & CISO)

ABOUT the company

the company is a prediction market exchange for sports and political trading, having handled over $50 billion in volume since 2010. We're upending sports betting with the fairest prices, the best technology, and a superior customer experience — powered by attracting great people and building a high-performance environment where they thrive. We're looking for an atypical candidate with strong regulated-business experience to support our growing CFTC business.

THE ROLE

This is our inaugural security hire, working alongside Infrastructure to protect the distributed, real-time systems behind our trading engine. You'll lead our information security programme across our core products and our DCM/DCO entities — a founding build, standing up security engineering from the ground up through go-live and maturing it as we scale. Reporting directly to senior leadership and the Board, you'll own security posture updates and ensure our risk management and incident response frameworks exceed regulatory and operational standards.

ABOUT YOU
  • Security expert with hands-on experience building security engineering/DevSecOps capabilities in a cloud-native, high-growth environment — ideally financial services or exchange infrastructure
  • Excellent communication skills for executive, board, and regulatory audiences
  • Familiarity with CFTC system safeguards expectations, including 17 C.F.R. § 38.1051 and § 39.18 or similar regulatory requirements
  • Strong grasp of application security principles (OWASP Top 10, NIST) and secure SDLC practices
  • Proficiency with CI/CD tooling (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, CircleCI) and security tools (Snyk, Aqua, Trivy, Checkov, Twistlock, Clair)
  • Hands-on expertise securing AWS/Azure/GCP, Kubernetes, containers, and IaC
  • Proficiency in Python, Bash, Go, or similar
RESPONSIBILITIES
  • First dedicated security engineering hire, working from within Infrastructure and Engineering teams to establish and evolve the company' security capabilities
  • Own regulatory/industry engagement (including CFTC), reflecting external expectations in internal practice
  • Define a pragmatic, risk-based security strategy across cloud infrastructure, applications, trading systems, and corporate environment
  • Lead or support the investigation, containment and remediation of security incidents, including post-incident root cause analysis and corrective actions.
  • Work with Engineering teams to build security into the SDLC — SAST, DAST, SCA, container/IaC scanning in CI/CD — without becoming a delivery bottleneck
  • Implement controls across AWS, Kubernetes, containers, and IaC, hardening identity, secrets, and network access
  • Establish security monitoring and detection across applications, APIs, and infrastructure
  • Develop and maintain security policies, standards, and controls meeting DCM/DCO requirements
  • Maintain evidence and documentation to support regulatory examinations and audits
  • Act as a security partner to engineers, building a culture of ownership over security
DESIRABLE
  • Personal interest in sports, exchanges, or trading
  • Certifications: DSOP, CKS, CISSP, CCSP, CSSLP, or AWS/Azure/GCP Security Specialty
  • Track record of security automation at scale in Agile/Scrum
  • Direct experience with regulators/examiners on technology and system safeguards
  • Familiarity with event contracts, prediction markets, or similar novel futures products under CFTC
OUR VALUES
  • Push to win
  • Make others better
  • Give a shit
  • Be a pro
  • Bring the energy
COMPENSATION & BENEFITS
  • Competitive salary + stock options (4-year vesting)
  • Private health insurance
  • Pension (up to 6%)
  • £1,000 annual education budget
  • 25 days annual leave + bank holidays (5 days carryover)
  • Hybrid working, plus 20 remote days/year globally
  • In-house chef, daily snacks and drinks
  • Cycle to work scheme

the company is an Equal Opportunity Employer, committed to equality, inclusion, and a welcoming environment for all.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Security Engineering (DevSecOps & CISO)
Head of Security Engineering (DevSecOps & CISO)

Smarkets • Greater London

On-site
GBP 120,000 - 190,000
Private health insurance
Pension (up to 6%)
£1,000 annual education budget
+4
Engineering Manager, Security
Engineering Manager, Security

Insignis Cash • Greater London

Hybrid
GBP 120,000 - 180,000
25 days holiday
5% Pension contributions
Private medical insurance with Vitaliy
+5
Core IP Security Software Engineer
Core IP Security Software Engineer

G-Research • Greater London

On-site
GBP 70,000 - 110,000
Competitive compensation
Lunch via Just Eat for Business
35 days’ annual leave
+4
Engineering Manager, Security
Engineering Manager, Security

Insignis • Greater London

Hybrid
GBP 120,000 - 180,000
25 days holiday (exc. Bank holidays)
5% Pension contributions
Private medical insurance with Vitaliy
+4
Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

United States Digital Space LLC • Greater London

Hybrid
GBP 110,000 - 160,000
Hybrid London office
Private healthcare
25 days annual leave
+1
Security Engineer, Institutional Trading
Security Engineer, Institutional Trading

United States Digital Space LLC • Greater London

On-site
GBP 120,000 - 180,000
Equity participation
London in-office four days a week
Work from Anywhere 20 days/yr
+3
Senior DevSecOps Engineer
Senior DevSecOps Engineer

PCN Media • Greater London

On-site
GBP 90,000 - 130,000
Security Engineer, Institutional Trading London
Security Engineer, Institutional Trading London

Blockchain Ventures • Greater London

Hybrid
GBP 60,000 - 80,000
ClassPass
Unlimited vacation policy
Opportunity to advance in a global tech company
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Fundment • Greater London

Hybrid
GBP 90,000 - 130,000
Pension 6% employer contribution
Private Health Insurance
Life Assurance 4x base salary
+3
Senior Security Engineer
Senior Security Engineer

Capital Markets Gateway • Greater London

Hybrid
GBP 90,000 - 140,000
Equity
Unlimited PTO
Comprehensive benefits program
+6