
51 - 200 employees
Founded 2014
đŽ Gaming
đ¤ B2B
đď¸ eCommerce
Gaming ⢠B2B ⢠eCommerce
Booming Games is a dynamic gaming company focused on developing innovative slot games and casino content. With a commitment to high-quality graphics, engaging gameplay, and a user-friendly experience, Booming Games aims to enhance the entertainment value for players in the online gaming space.
đĽ 18 hours ago
đ Malta, Bulgaria, +4 more countries â Remote
â° Full Time
đĄ Mid-level
đ Senior
đŽââď¸ Cybersecurity / Security Engineer
đť Ghost score 10%
Improve your chances of getting an interview by checking your resume score before you apply.

51 - 200 employees
Founded 2014
đŽ Gaming
đ¤ B2B
đď¸ eCommerce
Gaming ⢠B2B ⢠eCommerce
Booming Games is a dynamic gaming company focused on developing innovative slot games and casino content. With a commitment to high-quality graphics, engaging gameplay, and a user-friendly experience, Booming Games aims to enhance the entertainment value for players in the online gaming space.
⢠Own the full lifecycle of Booming Games' technical security protocols ⢠Define and enforce hardening baselines for Linux hosts, Docker images and containers, MongoDB clusters and network devices ⢠Maintain runbooks for patching, access provisioning and revocation, key and certificate rotation, backup verification and incident handling ⢠Translate ISO 27001 controls and regulator technical standards into testable technical configurations ⢠Review and approve security-relevant infrastructure and platform architecture changes ⢠Harden Linux servers, container platforms and MongoDB environments ⢠Manage secrets, keys and certificates centrally ⢠Reduce the attack surface of game servers and platform services ⢠Design and maintain network segmentation across game delivery, platform services, databases and management access ⢠Operate firewalls, WAF/CDN policies, rate limiting, DDoS mitigation and TLS configuration ⢠Control partner and aggregator connectivity through IP allow-listing, mutual TLS or VPN ⢠Secure remote and administrative access through VPN, bastion hosts, MFA and session logging ⢠Maintain network diagrams and an inventory of internet-facing assets ⢠Select, deploy and operate security tooling, including logging/SIEM, intrusion detection, vulnerability scanning, endpoint protection and secrets scanning ⢠Build and tune alerting for unauthorized access, privilege escalation, anomalous database queries, configuration drift and abnormal traffic ⢠Run the vulnerability and patch management cycle end to end ⢠Track security metrics and report them to the CTO monthly ⢠Act as first technical responder for suspected security incidents ⢠Own the incident response plan and run at least one tabletop or live exercise per year ⢠Produce post-incident reports and drive corrective actions to closure ⢠Support Legal, Compliance and Commercial with technical facts for notifications ⢠Coordinate with external forensic or penetration testing providers ⢠Provide technical input for ISO 27001 audits, certification lab reviews and regulator submissions ⢠Complete operator and aggregator security questionnaires and due diligence requests ⢠Commission and manage annual penetration tests and track remediation ⢠Review third-party services and vendors with infrastructure or data access ⢠Run practical security awareness for engineering and operations staff ⢠Embed secure configuration checks into deployment pipelines ⢠Report directly to the CTO and collaborate with Systems and Infrastructure, platform engineering and Technical Compliance teams
⢠4+ years of hands-on experience in security engineering, DevSecOps or infrastructure security ⢠Demonstrable ownership of a production environment's security ⢠Strong Linux administration and hardening skills, including Debian or RHEL family, users and privileges, SSH, firewalls, systemd, auditd, log management and patching ⢠Solid MongoDB security knowledge, including authentication and RBAC, TLS, encryption at rest, replica set security, auditing and backup protection ⢠Production Docker and container security experience, including image build hygiene, scanning, registries, runtime hardening and secrets handling ⢠Strong networking fundamentals, including TCP/IP, DNS, TLS, routing, firewalls, VPNs, load balancers, segmentation and WAF/CDN configuration ⢠Experience selecting and operating SIEM or log analytics, IDS/IPS, vulnerability scanners, endpoint protection and secrets management tools ⢠Scripting and automation in Bash and Python or equivalent ⢠Experience writing and maintaining security protocols and runbooks ⢠Incident response experience on live systems, including evidence handling and root cause analysis ⢠Working knowledge of ISO 27001 controls and technical implementation ⢠Clear written and verbal communication ⢠Applicants must be located in the European time zone (+/- 2 hours) ⢠Nice to have: online gambling or iGaming experience ⢠Nice to have: familiarity with MGA, UKGC, GLI-19, GLI-33 and test labs such as GLI, eCOGRA or iTech Labs ⢠Nice to have: Kubernetes security and infrastructure-as-code tooling such as Terraform and Ansible ⢠Nice to have: public cloud and bare-metal or co-located hosting experience ⢠Nice to have: penetration testing or offensive security background ⢠Nice to have: OSCP, CISSP, CCSP, GIAC or CompTIA Security+ certification
⢠Competitive base salary with performance-linked bonus ⢠Flexible and/or hybrid working arrangements ⢠Real budget and autonomy to choose and implement the tooling you need ⢠Clear career pathway toward Head of Security or CISO as the function grows ⢠Remote-first approach ⢠Diverse, fair, supportive, and open work environment
Apply Nowđ September 10
Senior Security Engineer securing The Mill Adventureâs iGaming platform across AWS, Cloudflare, applications, and CI/CD. Building detection, response, IAM, offensive security, and AI security capabilities.
AWS
Cloud
Python
SDLC
TypeScript
Go
đ September 9
Senior Security Engineer securing The Mill Adventureâs iGaming platform across AWS, Cloudflare, applications and CI/CD. Building automated controls, detection, response and AI security capabilities.
AWS
Cloud
Python
SDLC
TypeScript
Go