MrQ
Principal Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Security Engineering Lead
MrQ - Founding Security Engineering Role
Mr Who’s not you—MrQ is. An award-winning, tech-first online casino launched in 2018, we combine performance, fun, and explosive growth (yes, real tech scaling for an iGaming heavyweight). We need a rockstar security engineer to build our security function from the ground up—no inherited tooling, no playbooks. If you love solving hard problems, owning strategy, and shaping a secure-by-design culture, this is your shot at leaving a legacy.
This isn’t a hands-on chaos role—this is strategic leadership with zero-trust architecture, cross-functional influence, and full ownership of MrQ’s security posture. You’ll partner with the IT Ops Specialist to merge security and operations into a tight, efficient, and risk-aware system. Whether you’re writing policies, tuning detections, or presenting risk cases to the C-suite, you answer to no one else—except the business’s bottom line and security.
About the Role
- This is a founding security engineering position with no existing playbook
- Build the entire security discipline—architecture, tooling, governance, and operations
- Serve as the definitive technical and strategic security leader for MrQ’s future
- Report to no one security-related—you influence the entire org, from tech stack to executive decisions
Responsibilities
1. Security Strategy & Technical Leadership
- Define an enterprise security strategy and multi-year roadmap, identifying gaps and prioritising efforts.
- Act as MrQ’s voice of security—assess threats, architect solutions, and enforce standards across all platforms and systems.
- Collaborate with the IT Ops Specialist to shape integrated security-ops processes, including:
- Unified tooling decisions (SIEM, EDR, DLP).
- Aligned incident response (SIEM + EDR correlation).
- Cross-team risk ownership (single source of truth).
- Influence and pragmatic risk trade-offs against the business, translating technical risk into executive presentable decisions.
2. Security Architecture & Engineering
- Evaluate and deploy enterprise security stack (vendor list attached):
- EDR/XDR: CrowdStrike, SentinelOne
- SASE/SWG: Netskope, Zscaler
- SIEM, Email Security, DLP, Privilege Management, Application Allowlisting (One the right tool to solve a problem—build vs. buy decisions optional.)
- Design zero-trust security architecture for:
- Cloud (AWS).
- SaaS.
- Endpoints (macOS/Windows).
- Networks.
- Identity.
- Detection Engineering:
- Build, tune, and maintain detections in SIEM + EDR via MITRE ATT&CK mappings.
- Reduce false positives; expand threat coverage.
- Automation:
- Script (Python, Bash, PowerShell) for security operations:
- Incident response orchestration.
- Access reviews.
- Compliance checks.
- Vulnerability reporting.
- Script (Python, Bash, PowerShell) for security operations:
- Ensure vendor tooling integrates with existing ecosystem and identity platforms.
- Lead POCs, vendor evaluations, and forward-thinking tech decisions.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
3. Security Operations & Incident Response
- Incident Response (IR): Own full lifecycle:
- Detection.
- Triage.
- Containment.
- Eradication.
- Recovery.
- Post-incident reviews. Author runbooks, playbooks, and escalation procedures.
- Threat Intelligence:
- Investigate via root cause analysis.
- Operate MITRE ATT&CK, NIST CSF frameworks.
- Chase attacker TTPs and turn threats into defensive improvements.
- Vulnerability Management:
- End-to-end programme—scanning, prioritisation, remediation tracking, SLA enforcement and executive reporting.
- Application/API Security:
- Assess internal apps, third-party integrations, payment flows, and authentication systems.
- Find both mag司️dᾛl security holes and product abuse scenarios.
4. Identity, Access & Endpoint Security
- Zero Trust & IAM:
- Build and enforce identity strategies: SSO, MFA, SAML, OAuth, SCIM, conditional access, passwordless.
- Deploy least-privilege access policies across systems.
- Endpoint Security:
- Harden/manage Windows/macOS endpoints: Patching, disk encryption, MDM, compliance postures.
- Access Governance:
- Design and run access review programmes.
- Remove risk of orphaned accounts, shadow IT, and over-provisioned access.
5. Governance, Risk & Compliance
- Build the entire framework: Policies, controls, and standards aligned with:
- ISO 27001.
- SOC 2.
- Cyber Essentials.
- GDPR. (This role literally creates the function—your work sets industry benchmarks.)
- Audit & Compliance:
- Maintain continuous readiness.
- Collect evidence for controls; test gap analysis.
- Deliver clear audit answers with supporting documentation.
- Risk Management:
- Threat model, amend risk registers, drive treatment plans to reduce residual risk.
- Documentation:
- Create and preserve the full security knowledge base:
- Architecture diagrams.
- Tool configurations (SIEM, EDR).
- Runbooks, incident reports, process maps, policy libraries.
- Create and preserve the full security knowledge base:
- Security Awareness:
- Drive culture and education: Phishing drills, training campaigns, security inductions, policy communication.
Requirements
Essential
✅ 6+ Years in security engineering, enterprise SOC operations, or security strategy with a track record of significantly boosting security maturity or building teams from scratch.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
✅ Hands-on experience with enterprise security tooling:
- EDR/XDR (CrowdStrike, SentinelOne).
- SASE/SWG (Netskope, Zscaler).
- SIEM, DLP, email security systems, endpoint privilege management, MDM.
✅ Zero Trust expertise:
- Identity: SSO, SAML, MFA, OAuth 2.4, SCIM, passwordless in production at scale.
- Least-privilege architecture and conditional access policy design.
✅ Incident Response:
- Led full IR lifecycle—detection, containment, post-incident reviews.
- Frequently needed to promote zero trust and defend against real-world breaches.
✅ Automation & scripting:
- Python, Bash, PowerShell for operations at scale:
- SIEM tuning.
- Detection rule automation.
- Compliance checks.
✅ Governance & Compliance:
- Experience writing policies and implementing controls.
- Prepared for ISO 27001, SOC 2, Cyber Essentials, GDPR audits (represented team).
- Shouldn’t just know frameworks like MITRE ATT&CK, NIST CSF, CIS Controls, OWASP.
✅ Cloud Security:
- Secured AWS-heavy environments, SaaS integrations.
- Preferred: cloud-native security experience (GaurdDuty, Security Hub).
✅ Strategic Thinker:
- Ability to balance security rigor with business enablement and sell policies at senior levels.
Highly Desirable
🔹 iGaming/Fintech background: Understanding of gaming regulations, player data protections, and tech stack nuances. 🔹 Application Security: API security testing, secure SDLC, product security in platform businesses. 🔹 Hands-on SIEM Detection Engineering with:
- MITRE ATT&CK correlation.
- Dashboard building.
- Alert tuning. 🔹 CISM, CISSP, or GIAC certifications (CCFA/CCFR, GSEC/GCIA—anything prestigious). 🔹 Cloud security tooling like *Orgs and DLP platforms. 🔹 Team-builder/mentee: Experience shaping security culture at scale.
What We Offer
- Competitive pay and tailored rewards for a visionary.
- Leave that works for you: extra PTO days + birthday leave.
- Generous family leave: 4 weeks paid for parents-to-be.
- Well-being support: International health/life insurance.
- Professional growth: Wellness incentives + growth stipend for your development.
- Flexibility: Modern workplace with localisation options.
- Community: Join an elite, multicultural team with playfulness and productivity.
- Inclusivity: MrQ is committed to diversity, equity, and accessibility—your voice at the table matters.
- The challenge: this isn’t maintenance—it’s building something new and game-changing.
Endnote: FYI, our HR team will pass your CV to all security business playbooks—if you’re curious, apply to any of our multi-discipline roles. We’ll find a way to make your job work.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills