- Location
- Porto, Portugal
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Source
- Workday
Description
Blip is a leading tech company focused on software engineering solutions for sports entertainment.
We operate at scale. As part of Flutter Entertainment, we play an essential role in the Group's goal of becoming the global leader in online sports betting and iGaming, developing innovative products and platforms for over 14 million monthly customers worldwide.
We are serious about Tech. We are problem-solvers with big ambitions, keeping a people-first mindset at the core of our work. We prioritize flexibility as we strive to deliver the best technological products and tackle the greatest industry challenges.
Recognizing that everyone brings their own strengths, backgrounds and new perspectives, we empower you to be yourself. That uniqueness shapes the culture of belonging we are so proud of.
The role
As a Senior Security Engineer on our Product Security team, you'll lead multi-phase, multi-team efforts that shape how we build securely by default. You'll bring mastery across multiple security domains and use it to design reference architectures, drive threat modeling and pen testing engagements at consequential scope, define how we assess and govern AI and LLM systems, and turn risk and vulnerability data into decisions the business can act on. The problems you take on will be ambiguous, open-ended, and tangled up with competing product and platform objectives — and you'll be the engineer who untangles them, defines the strategy, and drives the work to completion. You'll mentor Security Champions across engineering, partner closely with product and platform teams, and make sure the lessons from each engagement land somewhere durable: a pattern, a guardrail, an automation, or an architectural standard others can reuse.
What You’ll Be Doing
- Lead security architecture reviews and define reusable design patterns for the engineering teams you partner with.
- Define and evolve our AI / LLM security architecture standards. Think controls, patterns, and assessment approaches that let Blip ship AI-powered products safely.
- Run high-impact threat modeling engagements and pen testing campaigns, and turn findings into structural fixes rather than one-off remediations.
- Own the strategy for risk assessments in your area, helping the business make risk-informed decisions backed by real data.
- Shape our HackerOne bug bounty and vulnerability disclosure programs, including tuning scope, triage, and feedback loops so external findings translate into lasting improvements.
- Deliver authoritative security advisements to engineering teams on the hard architectural calls.
- Lead and grow the Security Champions program, raising the security bar across the business through mentorship, enablement, and community.
- Design automation that transforms how the team works by turning assessment, threat modeling, and review activities into scalable, repeatable, build-secure-by-default capabilities.
- Improve the data and systems behind vulnerability and risk management so leadership and partner teams can see, prioritize, and decide on risk with confidence.
- Track industry trends, emerging threats, and shifts in our technology stack, and incorporate them into the roadmap before they become problems.
- Mentor engineers across the team, raising the bar on technical judgment and craft.
- Other duties as required.
What You’ll Bring
- Substantial security engineering experience with demonstrated mastery across multiple security domains, including security architecture and security assessment.
- Track record of leading multi-team, multi-quarter initiatives in areas like reference architecture, threat modeling programs, pen testing campaigns, or bug bounty operations.
- Hands-on experience with threat modeling, penetration testing, secure design review, and translating findings into structural fixes.
- Working knowledge of AI / LLM security concerns and the architectural patterns used to mitigate them.
- Experience defining or running a vulnerability disclosure or bug bounty program (HackerOne or similar) is a strong plus.
- Experience designing automation that scales security work
- Strong grasp of how to turn vulnerability and risk data into systems and dashboards that drive business decisions.
- Deep familiarity with modern cloud, CI/CD, and software development environments.
- Experience working with and securing enterprise security tools, including collaboration and SaaS tooling
- Proficiency in at least one modern programming language (Python, Go, or similar) and comfort working in code-heavy environments.
- Working knowledge of industry frameworks (NIST, ISO 27001, OWASP, MITRE ATT&CK, SOC 2) and how to apply them pragmatically.
- Proven ability to influence and align partners across security teams, product and platform orgs, and engineering leadership, such as through Security Champions or similar enablement programs.
- Excellent written and verbal communication skills (English and Portuguese).
This is what you should have. What do we have, you ask? Well...you can check our amazing perks & benefits right here !
So ... are you in?
Equal opportunities
At Blip, we are committed to creating a diverse and inclusive workplace. We strongly encourage people from all backgrounds, ways of thinking, and working to apply.
We are committed to including everyone regardless of their race, disability, age, gender identity, sexual orientation, and religion.
Everyone brings different perspectives and experiences; you don’t have to meet all the requirements listed to apply for this role. If you need any adjustments to apply for the position and to ensure this role aligns with your needs, please send an email to [email protected]
We will only respond to inquiries related to disabilities.