
Infrastructure Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Malta, +5 more countries.
• Take ownership of the complete lifecycle of Booming Games' technical security protocols.
• Establish and enforce hardening baselines for Linux hosts, Docker images and containers, MongoDB clusters, and network devices.
• Maintain runbooks for patch management, access provisioning and revocation, key and certificate rotation, backup verification, and incident management.
• Convert ISO 27001 controls and regulatory technical standards into actionable technical configurations.
• Evaluate and authorize security-relevant modifications to infrastructure and platform architecture.
• Strengthen Linux servers, container platforms, and MongoDB environments.
• Centrally manage secrets, keys, and certificates.
• Minimize the attack surface of game servers and platform services.
• Design and manage network segmentation for game delivery, platform services, databases, and administrative access.
• Operate firewalls, WAF/CDN policies, rate limiting, DDoS mitigation, and TLS configurations.
• Regulate partner and aggregator connectivity through IP allow-listing, mutual TLS, or VPN.
• Secure remote and administrative access utilizing VPNs, bastion hosts, MFA, and session logging.
• Keep network diagrams updated and maintain an inventory of internet-facing assets.
• Choose, deploy, and operate security tools, including logging/SIEM, intrusion detection, vulnerability scanning, endpoint protection, and secrets scanning.
• Create and refine alerts for unauthorized access, privilege escalation, anomalous database queries, configuration drift, and irregular traffic.
• Manage the vulnerability and patch management process from start to finish.
• Monitor security metrics and provide monthly reports to the CTO.
• Serve as the initial technical responder for suspected security incidents.
• Own the incident response plan and conduct at least one tabletop or live exercise annually.
• Generate post-incident reports and ensure corrective actions are completed.
• Assist Legal, Compliance, and Commercial teams with technical facts for notifications.
• Collaborate with external forensic or penetration testing services.
• Provide technical insights for ISO 27001 audits, certification lab reviews, and regulatory submissions.
• Complete security questionnaires and due diligence requests from operators and aggregators.
• Commission and oversee annual penetration tests and track remediation efforts.
• Evaluate third-party services and vendors with infrastructure or data access.
• Conduct practical security awareness training for engineering and operations teams.
• Integrate secure configuration checks into deployment pipelines.
• Report directly to the CTO and work collaboratively with Systems and Infrastructure, platform engineering, and Technical Compliance teams.
• Minimum of 4 years of hands-on experience in security engineering, DevSecOps, or infrastructure security.
• Proven track record of managing the security of production environments.
• Strong skills in Linux administration and hardening, including familiarity with Debian or RHEL, user and privilege management, SSH, firewalls, systemd, auditd, log management, and patching.
• Solid understanding of MongoDB security, including authentication and RBAC, TLS, encryption at rest, replica set security, auditing, and backup protection.
• Experience with Docker and container security in production settings, covering image build hygiene, scanning, registries, runtime hardening, and secrets management.
• Strong foundational knowledge of networking, including TCP/IP, DNS, TLS, routing, firewalls, VPNs, load balancers, segmentation, and WAF/CDN configuration.
• Experience in selecting and operating SIEM or log analytics, IDS/IPS, vulnerability scanners, endpoint protection, and secrets management tools.
• Proficiency in scripting and automation using Bash and Python or similar languages.
• Experience in writing and maintaining security protocols and runbooks.
• Incident response experience on live systems, including evidence handling and root cause analysis.
• Familiarity with ISO 27001 controls and their technical implementation.
• Excellent written and verbal communication skills.
• Applicants must reside within the European time zone (+/- 2 hours).
• Preferred: Experience in online gambling or iGaming.
• Preferred: Knowledge of MGA, UKGC, GLI-19, GLI-33, and test labs such as GLI, eCOGRA, or iTech Labs.
• Preferred: Experience with Kubernetes security and infrastructure-as-code tools like Terraform and Ansible.
• Preferred: Experience with public cloud and bare-metal or co-located hosting.
• Preferred: Background in penetration testing or offensive security.
• Preferred: Certifications such as OSCP, CISSP, CCSP, GIAC, or CompTIA Security+.
• Competitive base salary with performance-related bonuses.
• Flexible and/or hybrid work arrangements.
• Genuine budget and autonomy to select and implement the necessary tools.
• Clear career progression towards Head of Security or CISO as the function expands.
• Remote-first work culture.
• A diverse, equitable, supportive, and open work environment.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.