Description
Location: Bratislava, Slovakia
Employment: Full-time | Office-first with a flexible hybrid schedule
Language: Fluency in Ukrainian or Russian is required
Role profile: This is a hands-on platform engineering role with security ownership - not a pure compliance position and not a standalone penetration-testing role.
About the Role
We are building our own iGaming product for Tier-1 markets and are looking for a Platform Security Engineer / DevSecOps to join our engineering team in Bratislava.
We are a Ukrainian marketing group with more than four years of experience in iGaming.
During this time, we have grown to a team of over 250 professionals and built a strong in-house ecosystem.
We are now entering a new stage of growth: developing our own iGaming platform with a core team and technical roadmap already in place.
You will work alongside our DevOps/SRE and engineering teams.
Your role combines hands-on AWS and Kubernetes platform work with cloud security, secure delivery, detection engineering, incident readiness, and ATT&CK-based adversary emulation.
You will help us build security into the platform from the start instead of attaching it as a PDF shortly before launch.
Key Responsibilities
Platform Engineering & Reliability
Design, build, and operate our AWS and Kubernetes platform together with the DevOps/SRE team.Maintain infrastructure as code, CI/CD pipelines, environments, secrets, and deployment workflows.Improve platform reliability, observability, scalability, backup, recovery, and production readiness.Participate in platform on-call, incident response, root-cause analysis, and continuous operational improvement.Create reusable platform standards that help engineering teams ship safely and consistently.Security Engineering
Own the cloud and Kubernetes security baseline, including IAM, network boundaries, secrets, audit logging, container security, and privileged access.Build security controls into the software delivery lifecycle using SAST, SCA, secret scanning, IaC scanning, container scanning, and policy gates.Lead threat modelling for critical areas such as authentication, wallet and ledger, payments, game-provider integrations, callbacks, and backoffice privileges.Use OWASP ASVS to define practical application-security requirements and verification criteria with Tech Leads and developers.Establish vulnerability-management processes, severity rules, remediation SLAs, evidence, and retesting.Develop security monitoring, detection logic, incident playbooks, and security exercises using available cloud, infrastructure, and application telemetry.Coordinate external penetration tests, define the scope and rules of engagement, triage findings, and drive remediation through formal retesting.Purple Teaming & Security Automation
Design ATT&CK-mapped adversary-emulation and purple-team scenarios based on real risks to our platform.Use or integrate tools such as MITRE CALDERA and Atomic Red Team for controlled security validation.Work with developers acting as Security Champions to turn findings into controls, tests, detections, and regression coverage.Help build a small AI-assisted internal platform for threat-model support, control mapping, scenario management, evidence collection, remediation tracking, and reporting.Ensure offensive testing is authorised, scoped, auditable, and safe for the target environment.You Will Be a Great Fit If You Have
Strong commercial experience in DevOps, Platform Engineering, SRE, Cloud Security, or DevSecOps.Hands-on experience with AWS, Kubernetes, Docker, Linux, networking, and infrastructure as code.Practical experience with CI/CD, observability, secrets management, IAM, and production incident response.A solid understanding of cloud, container, API, and application-security risks.Experience implementing security scanning and vulnerability-management processes in engineering workflows.The ability to read code, understand service architecture, and work directly with backend and frontend engineers.A pragmatic engineering mindset: you can balance security, reliability, delivery speed, and business risk.Good communication skills and the ability to explain risks and remediation clearly to both technical and non-technical stakeholders.Fluency in Ukrainian or Russian, plus working English.Nice to Have
Experience in iGaming, fintech, payments, high-risk platforms, or other regulated environments.Experience with wallet/ledger systems, payment providers, game providers, KYC/AML, or backoffice security.Hands-on knowledge of OWASP ASVS, threat modelling, MITRE ATT&CK, CALDERA, or Atomic Red Team.Experience leading purple-team exercises, detection engineering, security incident simulations, or external pentest remediation.Knowledge of Kafka or RabbitMQ, PostgreSQL, Redis, microservices, and Node.js/NestJS environments.Experience using modern AI-assisted engineering or security tools and the judgement to apply them safely.Relevant AWS, Kubernetes, security, or offensive-security certifications are welcome, but practical experience matters more.
What Success Looks Like in the First 90 Days
First 30 days
Understand the platform and threat model; complete the initial service/access inventory; identify crown jewels and critical launch risks; agree the security backlog and external pentest plan.
Days 31-60
Implement priority cloud/Kubernetes hardening and delivery-pipeline controls; establish ASVS-based requirements and threat models for critical services; validate security telemetry and incident paths.
Days 61-90
Run the first focused purple-team campaign; coordinate the pre-launch pentest; drive remediation and retesting; publish launch-readiness evidence and the next-quarter roadmap.
What We Offer
Relocation & Settling In
Full relocation assistance for you and your family.One month of accommodation covered on arrival.Real-estate agent fees covered to help you find a home.Support with paperwork and getting set up in Bratislava.Growth & Equipment
Annual learning and development budget for courses, certifications, conferences, and books.Top-tier hardware of your choice and everything you need to do your best work.A modern engineering stack and an AI-assisted workflow that lets you ship fast.Real ownership of the security roadmap and the freedom to build practical internal tooling.Time Off & Wellbeing
28 calendar days of paid vacation per year.A paid day off on your birthday.Fully paid sick leave.A flexible hybrid schedule based in Bratislava.Team & Environment
A small, senior engineering team with real ownership and minimal bureaucracy.A flat structure where your decisions ship and your input matters.Direct collaboration with the CTO, Tech Leads, DevOps/SRE, and product stakeholders.Substantial resources for platform development, security validation, and external testing.Competitive compensation, by agreement.
Why join: You will help shape the platform before launch, own security as an engineering capability, and build systems that are used rather than admired once per audit.