security engineer
генерация резюме под вакансию
сопроводительное письмо
описание
Founded in 1999, the company has a premium listing on the Main Market of the London Stock Exchange and is focused on regulated and regulating markets across its B2B business, delivering innovative products and services to ensure a safe, engaging, and entertaining gaming experience by leveraging its proprietary technology.
задачи
- Review the AI systems and infrastructure, including local and cloud LLM deployments, gateways, vector stores, and agentic / MCP components, and provide clear recommendations on required hardening measures and areas for improvement;
- Assess existing guardrails and controls, such as input/output filtering, prompt-injection defenses, rate limiting, and authentication, against industry best practice, provide recommendations to strengthen their effectiveness and drive the implementation of improvements and new controls to ensure the secure and responsible use of AI;
- Advise on secure-by-design AI architecture, reviewing team designs and deployments against recognized frameworks (OWASP, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001);
- Recommend and prioritize hardening across the infrastructure behind self-hosted and cloud-based LLMs, and guide teams through remediation;
- Evaluate the AI supply chain, such as model provenance, AIBOM/SBOM, dependency and artifact scanning, and provide recommendations to address gaps;
- Define standards, reference patterns, and best-practice guidance to ensure teams across Playtech build and operate AI securely;
- Review logging, observability, and detection coverage for AI workloads mapped to frameworks such as MITRE ATLAS, and recommend enhancements to ensure the SOC can effectively monitor and respond across the full AI attack surface;
- Assess identity, access, and secrets management for models, tools, and data, advising on least-privilege improvements;
- Support compliance in a regulated environment with audit-ready assessments, evidence, and documentation;
- Investigate and where possible implement Agentic AI usage within the unit, to optimize time consuming activities.
требования
- Hold valid and relevant Certifications or equivalent, verifiable experience in the field of Cyber Security and/or Information Technology;
- Bring solid infrastructure and security engineering experience, including Linux, networking, cloud, IAM, container security, and automation;
- Know your way around both self-hosted LLM deployment and cloud LLM platforms;
- Can review and assess AI systems against best practice and clearly advise teams on what to harden, improve, or remediate on an ongoing basis;
- Have prior knowledge of LLM-specific threats such as prompt injection, sensitive-data disclosure, data/model poisoning, excessive agency, insecure output handling, and supply-chain risk;
- Have knowledge of various AI security frameworks and guidelines and how to translate them into controls;
- Have prior experience in guardrail implementation and design evaluation;
- Had exposure to using infrastructure-as-code and CI/CD pipelines to make controls repeatable;
- Have experience navigating and working in regulated environments such as gaming, finance, or healthcare;
- Have clear communication, presentation, and collaboration skills;
- Nice to have: hands-on experience building CI/CD security gates and guardrails, working knowledge of Python and Bash scripting, hands-on experience securing MCP / agentic AI infrastructure and the governance of these tools, hands-on experience with AI Enablement and optimizing workflows using agentic AI and Vibe coding, familiarity with AIBOM / SBOM tooling and supply-chain security, exposure to MLSecOps practices and AI red-teaming, relevant certifications across cloud or emerging AI-security credentials.
условия
- No conditions specified
навыки
Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.