bet365 operates one of the world's largest online gambling platforms, a high-stakes target for cyber threats by nature. With over 100 million customers, 700,000 annual live-streamed events, and a real-time In-Play betting engine covering 96 sports, the attack surface is massive. The threat model spans credential stuffing at scale, real-time fraud detection across financial transactions, DDoS attacks on latency-critical streaming infrastructure, and the protection of personal data across 27 language markets. The company runs N-Tier distributed systems and processes high-velocity data streams, making availability and integrity non-negotiable operational requirements.
The security team operates across a global footprint with offices in Manchester, Gibraltar, Malta, the US, Bulgaria, Brazil, Armenia, and Australia. The underlying stack handles streaming event infrastructure and real-time data processing at scale - domains where a security incident doesn't just leak data, it directly impacts revenue and regulatory standing in multiple jurisdictions simultaneously. Founded in 2000 and still family-owned, bet365 has grown from a Stoke-on-Trent startup to an operation employing over 9,000 people.
Defending this environment means working on problems at the intersection of high-availability distributed systems and adversarial pressure. The platform supports sports betting, online casino, poker, and bingo - each with distinct risk profiles. Security engineering here is less about perimeter defense and more about securing systems where every millisecond of latency has a financial cost and every endpoint is a potential target for motivated, well-resourced adversaries.




