
Betsson Group · Malta
The Senior Information Security Engineer at Betsson plays a critical role in the protection of the organisation’s information systems. THE WOW The senior po...
The Senior Information Security Engineer at Betsson plays a critical role in the protection of the organisation’s information
systems.
The senior position assumes added responsibility due to experience across the areas of Security Governance, Security Operations,
Security Awareness Training, and Security Incident Response, with a concentration on Security Operations. In addition to hands-on
technical work, the Senior Engineer will act as a technical leader; mentor junior team members; and contribute to the overall
improvement of Betsson’s security posture.
Security Operations (SECOPS)
threat (APT) scenarios.
capabilities.
Incident Response (CSIRT)
external partners when required.
stakeholders.
Security Governance (GRC)
procedures.
engagements.
Security Awareness Training (SAT)
experience).
Much like riding a rollercoaster, sometimes life at Betsson can be lightning fast with twists and turns but always FUN! Then
again, what else would you expect from a business 75% millennial and 1700 strong, spread across 7 offices with 900 based out of
our Malta HQ alone! We recognise it may not be for the faint-hearted, but if you’re a go-getter, initiator and adrenaline junkie,
always striving to push the boundaries and challenge yourself, then you’ll fit right in.
By submitting your application, you understand that your personal data will be processed as set out in our Privacy Policy
Camunda is the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex, end-to-end business processes. With built-in governance, auditability, and human oversight, Camunda gives enterprises the control they need to move AI from pilots to production — safely and at scale. Trusted by over 700 organizations worldwide, including 9 of top 10 US banks, Camunda helps enterprises boost operational efficiency, accelerate time-to-value, and deliver better customer experiences. Fully remote and global, we are in the middle of something bigger: transforming into an AI-first organisation, built on our own platform. We use Agentic AI to automate, orchestrate intelligent processes, and elevate human contribution across every team. Named GP Bullhound’s Top 100 Next Unicorn list, 2025 Great Place to Work certified. Visionary in 2025 Gartner® Magic Quadrant™ for Business Orchestration and Automation Technologies. ranked 3rd in Flexa's 2026 Most Flexible Companies, We’re growing fast and looking for top talent to join our team. If you want meaningful work, visible impact and put something genuinely rare on your CV, keep reading. About the role: As a Senior Information Security Engineer (AppSec) at Camunda, you’ll join a small, senior, and highly collaborative InfoSec team that lives our FAITH values – Focus, Ambition, Integrity, Talent and Humor – every day. You’ll work hand-in-hand with our product and engineering teams across the entire SDLC to make sure our platform is designed, built, and shipped securely as we continue to grow. This is a technical, hands-on, developer-centric, developer-centric role where you’ll shape how we build secure Java services in a modern CI/CD, SaaS environment, strengthen our AppSec tooling and practices, and directly influence how customers trust and adopt Camunda. You can be based anywhere that allows you to collaborate effectively within CET to Eastern Time working hours. What you'll be doing: * Partner with engineering teams throughout the SDLC – from early design and architecture discussions, through implementation and testing, to deployment – to embed security by design in our products. * Lead and evolve our AppSec tooling and workflows by implementing, tuning, and integrating SAST, DAST, SCA, and container/image scanning into CI/CD pipelines, and making sure findings are actionable for developers. * Drive vulnerability management for our applications and supply chain, including triaging and prioritizing issues, coordinating with teams on fix/mitigate/accept decisions, and ensuring we continuously improve our security posture. * Perform secure design and architecture reviews and threat modeling for distributed, API- and microservices-based systems, helping teams understand security trade-offs and make sound, risk-based decisions. * Support and help coordinate application-layer security incidents and escalations, working closely with Engineering, Support, and other stakeholders to investigate, contain, and learn from issues. * Together with the rest of the InfoSec team, help with security audits, customer assurance, and other processes What you bring: * Ability and/or willingness to use our product. * Strong Software engineering and secure coding background, with substantial recent hands-on experience building and reviewing (Java) services, working in CI/CD environments, and shipping SaaS or other cloud-based applications securely. * Secure SDLC, architecture & risk assessment experience, including secure design reviews, threat modeling for distributed/API/microservices systems, and performing risk assessments on product changes or new features. * Vulnerability management & security tooling expertise, with a proven track record of implementing and tuning SAST/DAST/SCA and container/image scanning, evaluating and triaging findings (including false positives), and driving fix/mitigate/accept decisions with engineering teams. * Cross-team collaboration & communication skills, enabling you to work effectively with Engineering, Support, Sales, and other stakeholders while explaining complex security issues and trade-offs in a clear, pragmatic way to both technical and non-technical audiences. * Developer-centric, incident-savvy mindset, meaning you are comfortable managing and supporting security incidents and escalations, you see yourself as an enabler (not a gatekeeper), and you influence teams toward risk-based, practical security improvements. Nice-to-haves: * Experience developing in Python, JavaScript, or TypeScript in addition to Java. * Hands-on experience securing Kubernetes- or container-based workloads and modern cloud environments. * Prior work in a B2B software company, especially in high-availability or multi-tenant contexts. * Experience running security training, talks, or workshops for engineering teams This role is an existing vacancy #LI-SG1 #LI-Remote #C1 What We Have to Offer: Compensation We offer competitive, fair, and transparent compensation. Salary ranges are location-based, with Standard and Major markets (global tech hubs) reflecting local competition. The Annual Total Target Cash (base salary + 100% variable target, where applicable) shown below spans from the minimum in a Standard market to the maximum in a Major market. Final offers depend on skills, experience, and location, and we typically hire in the first half of the range to allow room for growth: * United States: $143,800.00 to $231,900.00 * United Kingdom: £90,300.00 to £148,500.00 * Singapore: S$178,600.00 to S$267,900.00 If you’re based elsewhere, you’ll be hired via Remote.com (our global employer partner), and your Talent Acquisition Partner will provide a personalized Total Rewards Calculator after your first interview. Equity: We also offer equity (where applicable) through our Virtual Stock Option Plan (VSOP). Benefits & Perks We invest in your wellbeing, growth, and ability to connect, along with perks that support you no matter where you’re based. Our benefits are globally designed and locally delivered where applicable. * Remote & Flexible: Work from anywhere with the setup that suits you, home office budget, co-working space support, and flexible time off to recharge when you need it. * In Person Connection: We invest in meaningful face time through our Annual Kickoff (Vienna in 2025, Madrid in 2026!), team offsites, and Camundi Connection Budgets, including contributing to meetups while travelling,, and local gatherings with fellow Camundi. * Health & Wellbeing: Access locally tailored healthcare, Modern Health for global mental wellbeing, and our Live Well Lifestyle Spending Account (LSA), a flexible, global benefit that puts you in control of your whole life, not just work, from: staying active, to caring for family, exploring personal passions, meaningful experiences, and investing in your financial wellbeing. The Live Well program launches in 2026 and scales to €1,000 annually from 2027. * Financial Security: Retirement and pension plans (often with company contributions), plus life and disability insurance where relevant. * Professional Growth: Up to $/€/£1,000 per year for self-driven learning: courses, certifications, books, you decide! ”Everyone is welcome at Camunda” — it’s a celebrated component of our culture. We strive to create an inclusive environment that empowers our people. At Camunda, we honour diverse cultures and backgrounds and are proud to be an equal opportunity employer. All qualified applicants will receive consideration without regard to gender, race, ethnicity, religion, belief, sexual orientation, age, disability or any other protected characteristics under applicable law. We are looking forward to your application! Come join us and be part of Camunda’s incredible journey: Make an impact at a pivotal moment in our story! AI in our hiring process: Camunda may use AI tools to aid the screening of applications and during the interview process. You can learn more here
💬 ACCURX IS SOLVING HEALTHCARE PRODUCTIVITY FOR THE NHS. For decades, the NHS has struggled with fragmented systems that make simple tasks feel impossible. At Accurx, we’re changing that by building a single, system-wide platform that helps every patient get gold-standard, efficient, and joined-up care. What started as a way for GPs to text a patient has now evolved into an all-in-one digital toolkit used by 98% of GP practices. Our platform now powers Total Triage to manage patient demand, and Self-Book, which lets patients schedule their own appointments in seconds. We’ve automated routine care with Patient Questionnaires for long-term conditions, while Accumail finally allows staff-to-staff communication to happen instantly across different care settings. We’re now pushing the boundaries of the consultation itself with Accurx Scribe, our AI-powered note-taker that drafts medical notes in real-time. We’re not just shipping features. We’re giving clinicians their time back and ensuring every patient journey is as smooth as it should be. HOW THIS ROLE SITS WITHIN THE FUNCTION * Reports to: Senior Information Security Officer * Function: Privacy & Information Security * Contract type: Six-month fixed-term contract This role works day-to-day alongside the Senior Information Security Officer, who owns the GRC framework, ISO 27001 programme, CE+ and DSPT compliance, and the security risk register. It provides dedicated capacity to push forward priority workstreams - particularly risk management, CE+ audit readiness, and data strategy delivery. CHALLENGES YOU’LL SOLVE... * Own the security risk register: Facilitate risk assessment sessions with technical and non-technical stakeholders across the business, keep the register current and accurate, and prepare clear risk reporting that translates technical risk into business language. * Drive Cyber Essentials Plus readiness: Coordinate evidence gathering across IT, Platform and Security Engineering ahead of the CE+ deep-dive audit, reviewing controls against requirements and flagging gaps with practical remediation guidance. * Deliver our data classification programme: Work with data owners to classify information assets in line with policy, and push the access control programme forward by reviewing current access patterns and identifying gaps. * Keep risk treatment moving: Track risk treatment actions and follow up with owners so items progress rather than stall, managing milestones and blockers across the risk, CE+, and data workstreams. * Support the wider security programme: Contribute to ISO 27001 and DSPT activities where your work intersects, including evidence collection and control documentation, and support policy and process documentation as needed. * Be a translator between security and the business: Communicate security requirements clearly to engineers, and help non-technical stakeholders understand risk well enough to act on it. YOU SHOULD APPLY IF... * You have 3–5 years of hands-on experience in information security and risk management, ideally in health-tech or a regulated SaaS environment. * You've run risk sessions, owned a risk register, and prepared risk reporting for senior stakeholders * You've worked through a Cyber Essentials Plus audit cycle yourself * You understand cloud infrastructure, endpoint management, identity and access controls, and network boundaries well enough to hold your own in a technical conversation - you don't need to be a developer. * You have working knowledge of ISO 27001 and Cyber Essentials Plus, and know what "proportionate" looks like in a fast-moving product company. * You write and communicate clearly, structuring your thinking logically so people know what's expected of them and why. * You're comfortable working at pace and without extensive hand-holding, managing your own workload and flagging blockers early. * You care about what Accurx does, and understand that the data we protect belongs to patients and clinicians who trust us with it. WHAT’S IN IT FOR ME? You'll be joining an established but fast-growing Tech for Good movement, led by our Principles and our mission to solve healthcare productivity. * £50k salary * Benefits to suit you: adjust your healthcare cover, your pension or life insurance, whatever stage you’re at in life * Flexible working: We are an office-first culture and ask that you’re in our (dog-friendly) Shoreditch office 3 days a week, with core hours of 10 am - 4 pm * Time off: You’ll get 28 days of holiday (plus bank holidays) and up to 4 weeks to work from anywhere per year * We have our very own Chef! Free healthy breakfasts, snacks and lunches will be provided, with the occasional sweet treat!
Join Truecaller – The place where innovation meets impact! Truecaller's mission is to build trust in communication by making it safer, smarter, and more efficient. Born in Sweden, trusted by the world, and here’s why we stand out: * We are trusted by over 450 million active users every month across 190+ countries * We identify over 15 billion calls daily, helping users avoid spam and scams * We are powered by a team of 450+ employees from 45+ nationalities We always look for people who take initiative, own their work, and keep raising the bar. An entrepreneurial mindset matters here, especially when it turns bold ideas into real actions. We stay collaborative and focused, always searching for smarter paths forward. If you want to make an impact and grow with a team that inspires millions, you’ll fit right in. The role: As a Senior Cloud Security Engineer, you will act as a technical leader in safeguarding our core cloud infrastructure. You will take ownership of maintaining the highest standards of security controls for our critical systems within Google Cloud Platform (GCP). We're looking for someone who thrives in complex environments, can solve infrastructure security problems where no established patterns exist, and isn't afraid to get their hands dirty. You won't just advise; you will actively build, configure, and fix security controls. You'll leverage your expert understanding of cloud services, infrastructure-as-code, and container security to architect robust security measures and drive systemic improvements across the organization. What you’ll do: * Architect and Lead GCP Security: Take end-to-end ownership of designing and implementing security architectures for our GCP infrastructure. You will look beyond immediate fixes to architect long-term, scalable solutions for networking, compute, storage, and GKE. * Hands-on Remediation & Engineering: You don't just identify risks; you fix them. You will actively write code, create Pull Requests, and apply configurations to resolve security issues, harden infrastructure, and deploy tooling (e.g., EDR, Identity proxies) in production environments. * Drive Systemic Risk Reduction: Identify repeating classes of vulnerabilities or systemic risks (e.g., data exfiltration paths) and drive organizational change to eliminate them, rather than just patching individual issues. * Manage GCP Security Posture: Utilize GCP-native tools (e.g., Security Command Center, Cloud Armor, VPC Service Controls, IAM) to continuously monitor, assess, and improve the security posture of our cloud environment. * Advanced Network & Container Security: Design complex network security controls and Kubernetes (GKE) hardening strategies, balancing strict security requirements with operational velocity. * Mentorship and Technical Sparring: Act as a technical mentor and sparring partner to other engineers. You will elevate engineering standards by guiding colleagues on advanced security concepts and architecture. * Automate Security Operations: Develop advanced automation (using Python, Go, No/Low Code) to eliminate toil, turning manual security reviews into automated policy-as-code checks and high-fidelity alerts. What you bring in: * Technical Experience: Several years of hands-on experience in a senior security engineering role. You have a track record of leading technical designs and influencing decisions across multiple squads. * Security Passion & Threat Awareness: You are passionate about security and stay constantly updated on the evolving threat landscape, emerging vulnerabilities, and attack vectors, translating this knowledge into proactive defense strategies. * Navigating Ambiguity: You excel at breaking down complex, multi-faceted technical problems into actionable components. You are comfortable defining security standards for experimental technologies where internal patterns may not yet exist. * Project Ownership & Grit: Demonstrated ability to drive mid-to-large scale projects from idea to implementation independently, including successful stakeholder alignment and management of external dependencies. * Operational "Doer" Mindset: You are a practitioner who enjoys the craft of engineering. You have recent, deep experience directly configuring infrastructure, writing production-grade code, and debugging complex systems. Once an issue has been identified you have the experience applying the fix either yourself or through collaboration with stakeholders. * Business-Aligned Risk Assessment: Experience weighing risk vs. speed, and making technical decisions that balance short-term delivery with long-term maintainability and business value. * Deep GCP Expertise: Expert-level knowledge of securing cloud infrastructure, with the ability to architect tool-agnostic solutions and evaluate trade-offs in GCP services (GCE, GKE, VPC, IAM, SCC). * Communication: Strong ability to communicate technical security concepts to non-technical stakeholders, clearly articulating business impact (e.g., financial loss, brand reputation) to secure buy-in. What we offer: We support growth through learning resources, leadership programs, mentoring, and real hands-on work. People can move between teams and projects to build new skills and keep things interesting. We offer clear internal mobility and a transparent path for progression, with leaders who stay involved and provide guidance throughout the year. In addition, you will benefit from: * A comprehensive compensation package: We offer a competitive salary, 30 days of paid vacation, private health insurance, parental leave top-up, pension, and wellness contributions. * Modern tools to do your best work: Choose your preferred computer and phone within our budget, so you can work comfortably and efficiently. * A people-focused office culture: We value in-person collaboration and follow an office-first model, with some flexibility. Our offices offer a vibrant environment with opportunities to learn, connect, and recharge, from breakfast, lunch, and well-stocked snack stations and quiet spaces to team activities such as movie nights, tech meetups, and cultural events. There's something for everyone. * Truecaller’s “Lab Days” offer a space for imagination: 5 times per year for 3 days, where everyone steps away from their normal tasks to explore new, bold ideas and build things they’ve always wanted to. It’s a space where curiosity leads the way, and prototypes take shape. Some concepts even make it into production, and a few have grown into real features used by millions today. Lab Days allow you to be creative, learn fast, and help shape Truecaller's future. Come as you are: Truecaller is committed to building a diverse and inclusive team. We believe that a wide range of backgrounds, perspectives, and experiences strengthens our products and our culture. No matter where you're from, what language you speak, or how you identify, we value what makes you unique and would love to get to know you. Check out Life at Truecaller - Behind the code: https://www.instagram.com/lifeattruecaller/ Sounds like a great opportunity? We will fill the position as soon as we find the right candidate, so please send your application as soon as possible. As part of the recruitment process, we will conduct a background check. We only accept applications in English.