
Senior Security Engineer
ESL FACEIT GROUP
Job description
At EFG (ESL FACEIT Group) we create worlds beyond gameplay where players and fans become community. We pride ourselves in having a corporate social responsibility which is that “IT’S NOT GG, UNTIL IT’S GG FOR ALL” . We are passionate about the culture we foster that ultimately helps to create and shape the world of esports, gaming tournaments, leagues, events and holistic ecosystems staged for our millions of players, fans and heroes.
Everything we do, from global esports tournaments and community-driven leagues to next-generation platforms and live events, is rooted in our passion, craftsmanship, and culture. With millions of players and fans around the world, we aim to shape the future of esports and gaming by building ecosystems that are inclusive, innovative, and enduring.
About FACEIT
As one of the core pillars of EFG, FACEIT is the beating heart of competitive online gaming. With over 26 million registered users playing 30 million matches each month, we are the industry leader in competitive play. Our platform is where gamers of all levels come together to test their skills, climb the ranks, and forge communities. At FACEIT , we’re relentless in our pursuit of excellence. We push the limits of technology, deliver cutting-edge features, and provide an unparalleled competitive gaming experience. Our vision is simple: to empower every player to reach their full potential, while keeping competition fair, engaging, and thrilling.
The Role
The Senior Security Engineer leads the evolution of EFG’s information security posture by architecting and overseeing the implementation of enterprise security tools, platforms, and frameworks across the organization. This role is a technical authority responsible for driving high-impact security outcomes through automation and strategic resource allocation, ensuring the secure, resilient, and scalable operation of the Digital Platform (FACEIT) and the wider EFG ecosystem.
What you will do
-
Security Architecture & Threat Engineering: Architect and oversee the deployment of advanced security monitoring frameworks. Design automated detection logic to identify complex attack patterns across diverse log sources. Serve as the final escalation point for the Security Support Desk, resolving high-impact incidents and engineering systemic fixes for recurring issues;
-
Secure Software Development Life Cycle (SSDLC) Leadership: Lead the integration of security-as-code within the CI/CD pipeline. Architect the automated deployment of SAST, DAST, and SCA tooling, and partner with Engineering leads to define security gating criteria. Provide expert-level remediation guidance for complex architectural flaws and critical code vulnerabilities;
-
Enterprise Vulnerability & Risk Management: Own the end-to-end vulnerability management strategy for infrastructure and applications. Prioritise remediation efforts based on business risk and exploitability, and lead cross-departmental task forces to address systemic security gaps. Oversee the technical relationship with external penetration testers and bug bounty researchers;
-
Security Engineering & Orchestration: Design, implement, and optimize core security infrastructure (e.g. EDR,, Zero Trust, IAM, and DLP). Focus on automation and orchestration (SOAR) to reduce manual overhead and ensure security controls are consistently enforced across a global, multi-cloud environment;
-
Incident Response Leadership: Lead the technical response to high-priority security incidents. Drive the containment, eradication, and recovery phases, while coordinating communication between technical teams and senior stakeholders. Conduct deep-dive root cause analyses and develop long-term engineering roadmaps to prevent incident recurrence;
-
Compliance & Security Assurance: Lead internal security audits and maturity assessments. Ensure systems align with international standards (e.g., ISO 27001) and regulatory requirements. Define the technical standards that validate the effectiveness of the organisation’s control environment;
-
Strategic Technical Advisory: Act as a primary security consultant for major business initiatives. Evaluate the security posture of new technologies and third-party vendors, ensuring that all projects are built on a foundation of "Security by Design.";
-
Standardisation & Mentorship: Define the standards for SOPs, runbooks, and technical documentation. Mentor junior and mid-level security engineers to elevate the team’s collective technical proficiency and ensure the consistent execution of high-quality security operations.
** What We Are Looking For **
-
Advanced Security Engineering Expertise: Extensive experience in Information Security Engineering, with a proven track record of architecting and deploying resilient security systems at scale. You have moved beyond implementation to designing the frameworks that define the company’s security posture;
-
Strategic Policy & Standard Development: Ability to translate high-level security policies into enforceable technical standards. You have experience leading the rollout of security initiatives across multiple departments and influencing organisational change;
-
Expert Cloud & Infrastructure Security: Expert-level knowledge of major cloud platforms (AWS/GCP), with the ability to design secure multi-tenant architectures and perform deep-dive security configuration audits;
-
Cloud-Native & Container Security: Deep proficiency in securing containerised environments and orchestration platforms (Kubernetes). You are an expert in Infrastructure as Code (Terraform/CloudFormation) and can build automated guardrails to ensure compliant deployments;
-
Security Automation & Tooling Development: Advanced scripting and programming proficiency (with currently used languages) used to build custom security tooling, automate repetitive SecOps tasks, and develop sophisticated detection logic;
-
Detection & Response Architecture: Proven experience designing and optimising enterprise security stacks, including SIEM, SOAR, and EDR. You don't just use tools; you tune them to eliminate noise and build high-fidelity alerting pipelines;
-
DevSecOps Leadership: Experience leading the integration of security into complex CI/CD lifecycles. You have designed and scaled "Security-as-Code" initiatives that empower developers to ship secure code without sacrificing velocity;
-
Governance & Compliance Mastery: Comprehensive understanding of global security frameworks (ISO 27001, SOC2, NIST) and data protection regulations. You have experience demonstrating security controls during audits and aligning technical execution with regulatory requirements.
-
Incident Leadership & Forensics: Demonstrated ability to lead the technical response for critical security incidents. You possess strong digital forensics and incident response (DFIR) skills and can translate technical root-cause findings into long-term strategic roadmaps.
Additional information
This role may require travel from time-to-time for team get togethers or specific partner engagements but should be minimal for the individual.
Firmly rooted in our values, EFG is an affirmative action employer that celebrates being an equal opportunity workplace. Our unwavering commitment to fair employment extends to all individuals, regardless of their race, color, ancestry, religion, sex, national origin, age, sexual orientation, disability, citizenship, marital status, gender identity, or Veteran status.