Software Developer (Compliance)
- Remote
- All software engineering jobs
- European Union
- FullTime
- General
About the role
About Playson
Playson builds premium casino games and platform solutions for operators worldwide. Our products reach millions of players across regulated markets, and we ship frequently - which means our certification and compliance evidence has to be as well-engineered as the games themselves.
We are hiring a Software Developer, Compliance, to own that engineering: a pipeline that lets us ship faster and safer, and a defence of the platform and the games that holds up in front of a lab, an ISO assessor, and a future SOC 2 auditor.
About the role
You are a software developer sitting inside compliance. You will build and continuously evolve a secure compliance pipeline so we can ship games and platform changes faster and safer - and you will be the technical person who defends what we shipped when an auditor, a certification lab, or a regulator asks.
The scope is not games alone. You will stand in front of game certification labs, and you will also defend the platform: ISO certification of our systems and the evidence work that leads into a future SOC 2 audit. In every case, the job is the same. You produce the proof. You walk the auditor through it. You answer the question that was asked, with the evidence that was requested, and you stop there.
You will own the technical side of game certification. You take a game math package from the review channel to the lab, you produce the evidence the lab needs - build hashes, PAR sheets, configuration snapshots, version manifests - and you answer the lab's technical questions yourself, without a developer sitting next to you. When a certificate comes back, you are the person who confirms every deficiency is closed before the game is allowed past the pre-release gate.
Between lab submissions, you treat the pipeline as a product. Manual evidence collection, one-off screenshots, and tribal knowledge are the things you replace. You automate controls, tighten the audit trail, and shorten the path from "ready to ship" to "ready to show an auditor" without weakening the bar. Faster and safer at the same time is the point of this role - not one at the expense of the other.
Your first 90 days
First 30 days
Learn the certification path end-to-end: how a game goes from math review channel to lab submission to certificate
Map how we currently produce evidence for labs, for ISO, and for any control an auditor would ask to see - what is automated, what is manual, and what exists only in someone's head
Read the last year of certification submissions, deficiency cycles, and compliance incidents. Understand what we got wrong and why
Shadow one live lab submission and one auditor or ISO evidence walkthrough
First 60 days
Prepare and submit one certification evidence pack under supervision
Take a real auditor or lab question and answer it from evidence you assembled yourself
Identify the highest-friction steps in the current compliance pipeline and start replacing at least one of them with an engineered control
Document the evidence map for ISO: which platform controls we claim, where the proof lives, and what is still missing
First 90 days
Run a certification submission yourself: evidence pack, lab correspondence, deficiency tracking, certificate in hand
Sign off compliance evidence at the certification and pre-release gates independently
Ship a measurable pipeline improvement: less manual evidence, a shorter path to lab-ready, or a control that used to be a conversation and is now a repeatable artefact
Present a plan for ISO evidence hygiene and the first SOC 2 control gaps - what we can already show, what we must build, and in what order
What we're looking for
You are a developer first. 3+ years writing production code, comfortable reading someone else's codebase and forming your own opinion about what it does. You are not a documentation coordinator who learned some technical words
Strong Node.js and TypeScript. Our game math packages, engine integration, rules and bets migrations, test suites, and compliance automation are all JavaScript-side. You will read game math code and verify that what it does matches what we told the lab it does - and you will write the tooling that makes that check repeatable
You know what it takes to build certified products. You have worked for an iGaming game provider, a lottery, or another business where products require certification. You understand how that shapes development, testing, and releases, and why the code and supporting evidence need to stay aligned.
You build pipelines, not checklists. You have taken a manual, high-stakes process and turned it into something engineered: automated evidence, versioned artefacts, gates that fail closed
You can read data and write queries. SQL against a production analytics store, log investigation, understanding a metrics pipeline well enough to tell a real control failure from a broken dashboard
Composure in front of an auditor. In a lab session, an ISO assessment, or a future SOC 2 walkthrough, you answer the question that was asked with the evidence that was requested. You do not speculate, you do not narrate our internal process, and you do not volunteer material outside the scope of the question. This is never about withholding or misrepresenting facts: misleading an auditor is unacceptable and a licensing risk. It is about answering precisely, and knowing that "I will confirm that and come back to you in writing" is a complete and professional response
You know where your authority ends. When a question moves from technical fact to regulatory interpretation or commercial consequence, you route it to the Head of Compliance instead of improvising
You write clearly and permanently. Compliance evidence is read years later by people who were not in the room. Your documentation has to survive that
You are comfortable saying no. You will be the person telling a squad, under release pressure, that their change does not pass the gate. That conversation needs to be calm, specific, and final
Precise by temperament. You check the version number rather than remembering it. You are not bored by an audit trail
Nice to have
Direct dealings with a certification lab (GLI, BMM, eCOGRA, iTech Labs, or similar) or a gaming regulator
Hands-on evidence work for ISO 27001, SOC 2, or an equivalent information-security audit
Understanding of RNG, RTP mathematics, and how statistical certification evidence is produced
Familiarity with multi-jurisdiction licensing (UKGC, MGA, and regulated EU and LatAm markets)
Observability and alerting tooling - Datadog or equivalent, including building automation on top of it rather than just reading dashboards
Experience with change-management controls, audit trails, and segregation-of-duties models
Incident response experience, particularly where the incident had a regulatory or audit dimension
What you can expect on this role
A role with real authority: you hold gate sign-off, and a release does not go past you without it
Genuine engineering work - you own the compliance pipeline as a product, not a pile of checklists with a technical title
Direct exposure to certification labs, ISO assessors, and the path to SOC 2 - rare and portable experience
Close collaboration with math, QA, platform, and SRE across games and the platform
A compliance function that is being built up deliberately, with room to shape how it works
What we offer
Competitive Salary
Quarterly Bonuses
Unlimited Paid Time Off
Unlimited Paid Sick Leave
Remote & Flexible Working
Private Medical Insurance
Financial Support for Life Events
Professional Development Budget
International Exposure
Regular Company Events
*Benefits may vary depending on location and contractual agreement
Join us today!
By submitting your application, you acknowledge that your personal data will be processed in accordance with our Privacy Policy.
Description as published by Playson.