ESL FACEIT Group - EFG
Senior Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About EFG (ESL FACEIT Group)
At EFG (ESL FACEIT Group) we create worlds beyond gameplay where players and fans become community. We pride ourselves in having a corporate social responsibility which is that “IT’S NOT GG, UNTIL IT’S GG FOR ALL”. We are passionate about the culture we foster that ultimately helps to create and shape the world of esports, gaming tournaments, leagues, events and holistic ecosystems staged for our millions of players, fans and heroes.
Everything we do, from global esports tournaments and community-driven leagues to next-generation platforms and live events, is rooted in our passion, craftsmanship, and culture. With millions of players and fans around the world, we aim to shape the future of esports and gaming by building ecosystems that are inclusive, innovative, and enduring.
About FACEIT
As one of the core pillars of EFG, FACEIT is the beating heart of competitive online gaming. With over 26 million registered users playing 30 million matches each month, we are the industry leader in competitive play. Our platform is where gamers of all levels come together to test their skills, climb the ranks, and forge communities. At FACEIT, we’re relentless in our pursuit of excellence. We push the limits of technology, deliver cutting-edge features, and provide an unparalleled competitive gaming experience. Our vision is simple: to empower every player to reach their full potential, while keeping competition fair, engaging, and thrilling.
The Role
The Senior Security Engineer leads the evolution of EFG’s information security posture by architecting and overseeing the implementation of enterprise security tools, platforms, and frameworks across the organization. This role is a technical authority responsible for driving high-impact security outcomes through automation and strategic resource allocation, ensuring the secure, resilient, and scalable operation of the Digital Platform (FACEIT) and the wider EFG ecosystem.
What we are looking for
- Security Architecture & Threat Engineering: Architect and oversee the deployment of advanced security monitoring frameworks. Design automated detection logic to identify complex attack patterns across diverse log sources. Serve as the final escalation point for the Security Support Desk, resolving high-impact incidents and engineering systemic fixes for recurring issues.
- Secure Software Development Life Cycle (SSDLC) Leadership: Lead the integration of security-as-code within the CI/CD pipeline. Architect the automated deployment of SAST, DAST, and SCA tooling, and partner with Engineering leads to define security gating criteria. Provide expert-level remediation guidance for complex architectural flaws and critical code vulnerabilities.
- Enterprise Vulnerability & Risk Management: Own the end-to-end vulnerability management strategy for infrastructure and applications. Prioritise remediation efforts based on business risk and exploitability, and lead cross-departmental task forces to address systemic security gaps. Oversee the technical relationship with external penetration testers and bug bounty researchers.
- Security Engineering & Orchestration: Design, implement, and optimize core security infrastructure (e.g. EDR, Zero Trust, IAM, and DLP). Focus on automation and orchestration (SOAR) to reduce manual overhead and ensure security controls are consistently enforced across a global, multi-cloud environment.
- Incident Response Leadership: Lead the technical response to high-priority security incidents. Drive the containment, eradication, and recovery phases, while coordinating communication between technical teams and senior stakeholders. Conduct deep-dive root cause analyses and develop long-term engineering roadmaps to prevent incident recurrence.
- Compliance & Security Assurance: Lead internal security audits and maturity assessments. Ensure systems align with international standards (e.g., ISO 27001) and regulatory requirements. Define the technical standards that validate the effectiveness of the organisation’s control environment.
- Strategic Technical Advisory: Act as a primary security consultant for major business initiatives. Evaluate the security posture of new technologies and third-party vendors, ensuring that all projects are built on a foundation of "Security by Design."
- Standardisation & Mentorship: Define the standards for SOPs, runbooks, and technical documentation. Mentor junior and mid-level security engineers to elevate the team’s collective technical proficiency and ensure the consistent execution of high-quality security operations.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What We Are Looking For
- Advanced Security Engineering Expertise: Extensive experience in Information Security Engineering, with a proven track record of architecting and deploying resilient security systems at scale. You have moved beyond implementation to designing the frameworks that define the company’s security posture.
- Strategic Policy & Standard Development: Ability to translate high-level security policies into enforceable technical standards. You have experience leading the rollout of security initiatives across multiple departments and influencing organisational change.
- Expert Cloud & Infrastructure Security: Expert-level knowledge of major cloud platforms (AWS/GCP), with the ability to design secure multi-tenant architectures and perform deep-dive security configuration audits.
- Cloud-Native & Container Security: Deep proficiency in securing containerised environments and orchestration platforms (Kubernetes). You are an expert in Infrastructure as Code (Terraform/CloudFormation) and can build automated guardrails to ensure compliant deployments.
- Security Automation & Tooling Development: Advanced scripting and programming proficiency (with currently used languages) used to build custom security tooling, automate repetitive SecOps tasks, and develop sophisticated detection logic.
- Detection & Response Architecture: Proven experience designing and optimising enterprise security stacks, including SIEM, SOAR, and EDR. You don't just use tools; you tune them to eliminate noise and build high-fidelity alerting pipelines.
- DevSecOps Leadership: Experience leading the integration of security into complex CI/CD lifecycles. You have designed and scaled "Security-as-Code" initiatives that empower developers to ship secure code without sacrificing velocity.
- Governance & Compliance Mastery: Comprehensive understanding of global security frameworks (ISO 27001, SOC2, NIST) and data protection regulations. You have experience demonstrating security controls during audits and aligning technical execution with regulatory requirements.
- Incident Leadership & Forensics: Demonstrated ability to lead the technical response for critical security incidents. You possess strong digital forensics and incident response (DFIR) skills and can translate technical root-cause findings into long-term strategic roadmaps.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Additional information
This role may require travel from time-to-time for team get togethers or specific partner engagements but should be minimal for the individual.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location