Infrastructure Security Engineer

Posted 3 days ago

This is a fully remote position, open to applicants in Malta, +5 more countries.

📋 Description

• Take ownership of the complete lifecycle of Booming Games' technical security protocols.

• Establish and enforce hardening baselines for Linux hosts, Docker images and containers, MongoDB clusters, and network devices.

• Maintain runbooks for patch management, access provisioning and revocation, key and certificate rotation, backup verification, and incident management.

• Convert ISO 27001 controls and regulatory technical standards into actionable technical configurations.

• Evaluate and authorize security-relevant modifications to infrastructure and platform architecture.

• Strengthen Linux servers, container platforms, and MongoDB environments.

• Centrally manage secrets, keys, and certificates.

• Minimize the attack surface of game servers and platform services.

• Design and manage network segmentation for game delivery, platform services, databases, and administrative access.

• Operate firewalls, WAF/CDN policies, rate limiting, DDoS mitigation, and TLS configurations.

• Regulate partner and aggregator connectivity through IP allow-listing, mutual TLS, or VPN.

• Secure remote and administrative access utilizing VPNs, bastion hosts, MFA, and session logging.

• Keep network diagrams updated and maintain an inventory of internet-facing assets.

• Choose, deploy, and operate security tools, including logging/SIEM, intrusion detection, vulnerability scanning, endpoint protection, and secrets scanning.

• Create and refine alerts for unauthorized access, privilege escalation, anomalous database queries, configuration drift, and irregular traffic.

• Manage the vulnerability and patch management process from start to finish.

• Monitor security metrics and provide monthly reports to the CTO.

• Serve as the initial technical responder for suspected security incidents.

• Own the incident response plan and conduct at least one tabletop or live exercise annually.

• Generate post-incident reports and ensure corrective actions are completed.

• Assist Legal, Compliance, and Commercial teams with technical facts for notifications.

• Collaborate with external forensic or penetration testing services.

• Provide technical insights for ISO 27001 audits, certification lab reviews, and regulatory submissions.

• Complete security questionnaires and due diligence requests from operators and aggregators.

• Commission and oversee annual penetration tests and track remediation efforts.

• Evaluate third-party services and vendors with infrastructure or data access.

• Conduct practical security awareness training for engineering and operations teams.

• Integrate secure configuration checks into deployment pipelines.

• Report directly to the CTO and work collaboratively with Systems and Infrastructure, platform engineering, and Technical Compliance teams.


⛳️ Requirements

• Minimum of 4 years of hands-on experience in security engineering, DevSecOps, or infrastructure security.

• Proven track record of managing the security of production environments.

• Strong skills in Linux administration and hardening, including familiarity with Debian or RHEL, user and privilege management, SSH, firewalls, systemd, auditd, log management, and patching.

• Solid understanding of MongoDB security, including authentication and RBAC, TLS, encryption at rest, replica set security, auditing, and backup protection.

• Experience with Docker and container security in production settings, covering image build hygiene, scanning, registries, runtime hardening, and secrets management.

• Strong foundational knowledge of networking, including TCP/IP, DNS, TLS, routing, firewalls, VPNs, load balancers, segmentation, and WAF/CDN configuration.

• Experience in selecting and operating SIEM or log analytics, IDS/IPS, vulnerability scanners, endpoint protection, and secrets management tools.

• Proficiency in scripting and automation using Bash and Python or similar languages.

• Experience in writing and maintaining security protocols and runbooks.

• Incident response experience on live systems, including evidence handling and root cause analysis.

• Familiarity with ISO 27001 controls and their technical implementation.

• Excellent written and verbal communication skills.

• Applicants must reside within the European time zone (+/- 2 hours).

• Preferred: Experience in online gambling or iGaming.

• Preferred: Knowledge of MGA, UKGC, GLI-19, GLI-33, and test labs such as GLI, eCOGRA, or iTech Labs.

• Preferred: Experience with Kubernetes security and infrastructure-as-code tools like Terraform and Ansible.

• Preferred: Experience with public cloud and bare-metal or co-located hosting.

• Preferred: Background in penetration testing or offensive security.

• Preferred: Certifications such as OSCP, CISSP, CCSP, GIAC, or CompTIA Security+.


🏝️ Benefits

• Competitive base salary with performance-related bonuses.

• Flexible and/or hybrid work arrangements.

• Genuine budget and autonomy to select and implement the necessary tools.

• Clear career progression towards Head of Security or CISO as the function expands.

• Remote-first work culture.

• A diverse, equitable, supportive, and open work environment.

People also viewed

Sony Interactive Entertainment1 day ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads1 day ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j1 day ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)1 day ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting1 day ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International1 day ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers