Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Head of Security

mrq-1660314033
Companymrq-1660314033
CategorySecurity
Location
Remote
EmploymentNot stated
LevelDirector
SalaryNot stated by the employer
Posted5 Aug 2026
Last verified12 Aug 2026
SourceEmployer ATS (teamtailor)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Mr Who? MrQ - we're an awesome, award winning online casino launched in 2018. We're big on tech, big on performance and most of all - big on fun. Over the years, we have experienced explosive growth - which means we need more rock stars to join our quest for total world domination. This is a founding leadership role. We’re building a dedicated security function at MrQ, with its own strategy, roadmap, team and budget, and you’ll be the one building it. You won’t start from zero, and you won’t be handed someone else’s plan. Serious groundwork is already in place: an independent security maturity baseline, a live GRC platform, EDR and identity programmes in deployment, and security investment with real backing from the exec team. The strategy and roadmap from here are yours to define. Pressure-test what’s in flight, keep what works, change what doesn’t. You’ll report directly to the CTO and lead both Security and IT Operations. The Lead of IT Ops reports to you, and you’ll hire and lead the security engineering team, starting with a Principal Security Engineer. This is a player-coach role. We need someone strategic enough to own board-level risk conversations, and technical enough to earn the respect of a Principal-level engineer and challenge architecture decisions on an AWS-native platform. With a small team and serious AI leverage, you’ll build as well as lead. Threat modelling, architecture reviews and AI-powered security tooling are part of the job, not beneath it. Here, automation replaces headcount by design. What You Will Do 1. Own the security strategy Define and own the security strategy and maturity roadmap. Set priorities, allocate budget and effort, and be accountable for the targets you set. Report security posture, risk and investment cases to the CTO, exec team and board. Translate technical risk into business impact. Make sure security is part of every major technology and product decision, including how we build with AI, not just what we buy. 2. Build and lead the team Lead the IT Operations function through its Lead: identity and access, employee onboarding and offboarding, the device fleet, SaaS tools, and data requests (DSARs). Hire, develop and lead the security engineering team, starting with a Principal Security Engineer. Design the function for resilience: clear ownership, documented processes, no single points of failure. 3. Run security engineering and operations Own the security tooling end to end (EDR/XDR, SIEM, identity, vulnerability management, email security, DLP), including the deployments already in flight. Own security incident and breach response: deciding severity, directing containment, regulatory notification (ICO, UKGC) and post-incident review. Production incidents belong to Engineering’s on-call team. You own the security path and the call on when an incident is, or might become, a security event. Direct security across a cloud-native AWS estate: platform, payment flows, APIs, player data. 4. Own governance, risk and compliance Own the GRC programme: risk register, policies, control framework, audit readiness (ISO 27001 path, Cyber Essentials, GDPR) and the compliance-automation platform behind it. Partner with Compliance on the regulatory side of a UKGC-licensed operator: player data protection, technical standards, audit evidence. Build documentation to a standard that survives external scrutiny: auditors, regulators and commercial due diligence. 5. Secure how we build with AI MrQ is deeply AI-native: AI agents, internal AI platforms and AI-assisted engineering across the company. Own the security model for all of it: the AI gateway, agent permissions and sandboxing, data boundaries, and governance of third-party AI tools. Own the company’s AI usage policy: which tools are approved, what data they can touch, and what agents are allowed to do on their own. This is greenfield in most comp