Infrastructure Security Engineer

🔥 18 hours ago

🌐 Malta, Bulgaria, +4 more countries – Remote

infoinfo

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Booming Games

Booming Games

51 - 200 employees

Founded 2014

🎮 Gaming

🤝 B2B

🛍️ eCommerce

Gaming • B2B • eCommerce

Booming Games is a dynamic gaming company focused on developing innovative slot games and casino content. With a commitment to high-quality graphics, engaging gameplay, and a user-friendly experience, Booming Games aims to enhance the entertainment value for players in the online gaming space.

📋 Description

• Own the full lifecycle of Booming Games' technical security protocols • Define and enforce hardening baselines for Linux hosts, Docker images and containers, MongoDB clusters and network devices • Maintain runbooks for patching, access provisioning and revocation, key and certificate rotation, backup verification and incident handling • Translate ISO 27001 controls and regulator technical standards into testable technical configurations • Review and approve security-relevant infrastructure and platform architecture changes • Harden Linux servers, container platforms and MongoDB environments • Manage secrets, keys and certificates centrally • Reduce the attack surface of game servers and platform services • Design and maintain network segmentation across game delivery, platform services, databases and management access • Operate firewalls, WAF/CDN policies, rate limiting, DDoS mitigation and TLS configuration • Control partner and aggregator connectivity through IP allow-listing, mutual TLS or VPN • Secure remote and administrative access through VPN, bastion hosts, MFA and session logging • Maintain network diagrams and an inventory of internet-facing assets • Select, deploy and operate security tooling, including logging/SIEM, intrusion detection, vulnerability scanning, endpoint protection and secrets scanning • Build and tune alerting for unauthorized access, privilege escalation, anomalous database queries, configuration drift and abnormal traffic • Run the vulnerability and patch management cycle end to end • Track security metrics and report them to the CTO monthly • Act as first technical responder for suspected security incidents • Own the incident response plan and run at least one tabletop or live exercise per year • Produce post-incident reports and drive corrective actions to closure • Support Legal, Compliance and Commercial with technical facts for notifications • Coordinate with external forensic or penetration testing providers • Provide technical input for ISO 27001 audits, certification lab reviews and regulator submissions • Complete operator and aggregator security questionnaires and due diligence requests • Commission and manage annual penetration tests and track remediation • Review third-party services and vendors with infrastructure or data access • Run practical security awareness for engineering and operations staff • Embed secure configuration checks into deployment pipelines • Report directly to the CTO and collaborate with Systems and Infrastructure, platform engineering and Technical Compliance teams

🎯 Requirements

• 4+ years of hands-on experience in security engineering, DevSecOps or infrastructure security • Demonstrable ownership of a production environment's security • Strong Linux administration and hardening skills, including Debian or RHEL family, users and privileges, SSH, firewalls, systemd, auditd, log management and patching • Solid MongoDB security knowledge, including authentication and RBAC, TLS, encryption at rest, replica set security, auditing and backup protection • Production Docker and container security experience, including image build hygiene, scanning, registries, runtime hardening and secrets handling • Strong networking fundamentals, including TCP/IP, DNS, TLS, routing, firewalls, VPNs, load balancers, segmentation and WAF/CDN configuration • Experience selecting and operating SIEM or log analytics, IDS/IPS, vulnerability scanners, endpoint protection and secrets management tools • Scripting and automation in Bash and Python or equivalent • Experience writing and maintaining security protocols and runbooks • Incident response experience on live systems, including evidence handling and root cause analysis • Working knowledge of ISO 27001 controls and technical implementation • Clear written and verbal communication • Applicants must be located in the European time zone (+/- 2 hours) • Nice to have: online gambling or iGaming experience • Nice to have: familiarity with MGA, UKGC, GLI-19, GLI-33 and test labs such as GLI, eCOGRA or iTech Labs • Nice to have: Kubernetes security and infrastructure-as-code tooling such as Terraform and Ansible • Nice to have: public cloud and bare-metal or co-located hosting experience • Nice to have: penetration testing or offensive security background • Nice to have: OSCP, CISSP, CCSP, GIAC or CompTIA Security+ certification

🏖️ Benefits

• Competitive base salary with performance-linked bonus • Flexible and/or hybrid working arrangements • Real budget and autonomy to choose and implement the tooling you need • Clear career pathway toward Head of Security or CISO as the function grows • Remote-first approach • Diverse, fair, supportive, and open work environment

Apply Now

Similar Jobs

🕒 September 10

The Mill Adventure

11 - 50

🎮 Gaming

Senior Security Engineer securing The Mill Adventure’s iGaming platform across AWS, Cloudflare, applications, and CI/CD. Building detection, response, IAM, offensive security, and AI security capabilities.

AWS

Cloud

Python

SDLC

TypeScript

Go

🕒 September 9

The Mill Adventure

11 - 50

🎮 Gaming

Senior Security Engineer securing The Mill Adventure’s iGaming platform across AWS, Cloudflare, applications and CI/CD. Building automated controls, detection, response and AI security capabilities.

AWS

Cloud

Python

SDLC

TypeScript

Go