Infrastructure Security Engineer at Booming Games | BG | Rezi

Infrastructure Security Engineer at Booming Games

Infrastructure Security Engineer

Booming Games · BG

Today

Infrastructure Security Engineer

Booming Games · BG

6 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Infrastructure Security Engineer role.

Rezi rewrites your resume against Booming Games's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Infrastructure Security Engineer posting at Booming Games — free, in seconds.

About the Role

We are seeking an Infrastructure Security Engineer to take ownership of the security for Booming Games' platform, including Linux hosts, containers, the MongoDB data layer, and the network edge. This is a hands-on role involving the creation, implementation, and maintenance of security protocols, tooling selection and operation, vulnerability management, and incident response. You will report directly to the CTO and collaborate with the Systems and Infrastructure team, platform engineers, and Technical Compliance.

Responsibilities

  • Own the full lifecycle of Booming Games' technical security protocols: write, implement, maintain, and update them.
  • Define and enforce hardening baselines for Linux hosts, Docker images and containers, MongoDB clusters, and network devices across all environments.
  • Maintain operational runbooks for patching, access provisioning/revocation, key/certificate rotation, backup verification, and incident handling.
  • Translate ISO 27001 controls and regulatory technical standards into concrete, testable configurations, working with Technical Compliance on evidence and audit readiness.
  • Review and approve security-relevant changes to infrastructure and platform architecture.
  • Harden the Linux server estate, including SSH policy, privilege management, patching, host firewalls, file integrity, and audit logging.
  • Secure the container platform by implementing minimal base images, image scanning, registry controls, runtime restrictions, secrets injection, and least-privilege service accounts.
  • Own MongoDB security, including authentication, role-based access, TLS, encryption at rest, audit logging, and backup protection.
  • Manage secrets, keys, and certificates centrally with documented ownership and rotation schedules.
  • Reduce the attack surface of game servers and platform services through segmentation and exposure reviews.
  • Design and maintain network segmentation between public-facing game delivery, internal platform services, databases, and management access.
  • Operate the network edge, including firewall rules, WAF/CDN policies, rate limiting, DDoS mitigation, and TLS configuration.
  • Control partner and aggregator connectivity through IP allow-listing, mutual TLS, or VPNs.
  • Secure remote and administrative access using VPN, bastion hosts, MFA, and session logging.
  • Maintain accurate network diagrams and an inventory of internet-facing assets.
  • Select, deploy, and operate security tooling, including centralized logging, SIEM, intrusion detection, vulnerability scanning, endpoint protection, and secrets scanning.
  • Build alerting to detect unauthorized access, privilege escalation, anomalous database queries, configuration drift, and abnormal traffic.
  • Tune detection to reduce noise and define escalation paths for security events.
  • Manage the vulnerability and patch management cycle end-to-end: scan, prioritize, remediate, verify, and report.
  • Track and report security metrics to the CTO monthly.
  • Act as the first technical responder for security incidents: contain, preserve evidence, investigate, and coordinate remediation.
  • Own the incident response plan and conduct at least one tabletop or live exercise annually.
  • Produce post-incident reports and drive corrective actions to closure.
  • Support Legal, Compliance, and Commercial with technical facts for notifications.
  • Coordinate with external forensic or penetration testing providers.
  • Provide technical input for ISO 27001 audits, certification lab reviews, and regulator submissions, and remediate findings.
  • Complete operator and aggregator security questionnaires and due diligence requests.
  • Commission and manage annual penetration tests, triage results, and track remediation.
  • Review third-party services and vendors before onboarding.
  • Run practical security awareness training for engineering and operations staff.
  • Embed secure configuration checks into deployment pipelines.

Requirements

  • 4+ years of hands-on experience in security engineering, DevSecOps, or infrastructure security with demonstrable ownership of a production environment's security.
  • Strong Linux administration and hardening skills (Debian or RHEL family).
  • Solid MongoDB security knowledge.
  • Experience with Docker and container security in production.
  • Strong networking fundamentals.
  • Experience selecting and operating security tooling.
  • Scripting and automation in Bash and Python (or equivalent).
  • Experience writing security protocols and runbooks.
  • Incident response experience on live systems, including evidence handling and root cause analysis.
  • Working knowledge of ISO 27001 controls and their technical implementation.
  • Clear written and verbal communication skills.

Skills

  • Linux administration
  • Linux hardening
  • MongoDB security
  • Docker security
  • Container security
  • Network security
  • TCP/IP
  • DNS
  • TLS
  • Routing
  • Firewalls
  • VPNs
  • Load balancers
  • Segmentation
  • WAF
  • CDN
  • Security tooling
  • SIEM
  • Log analytics
  • Intrusion detection
  • Vulnerability scanning
  • Endpoint protection
  • Secrets management
  • Bash scripting
  • Python scripting
  • Automation
  • Incident response
  • Evidence handling
  • Root cause analysis
  • ISO 27001
  • Penetration testing
  • Kubernetes security
  • Infrastructure-as-code
  • Terraform
  • Ansible
  • Public cloud
  • Bare-metal hosting
  • Co-located hosting
  • Offensive security

Location

  • European time zone (+/- 2 hours)

Work Type

  • Remote-first
  • Flexible working arrangements
  • Hybrid working arrangements

Experience Level

  • 4+ years of experience

Education Level

  • Professional certification (OSCP, CISSP, CCSP, GIAC, CompTIA Security+)

Salary/Compensations

  • Competitive base salary with performance-linked bonus

Benefits

  • Competitive base salary
  • Performance-linked bonus
  • Flexible and/or hybrid working arrangements
  • Ownership of the security function
  • Reporting directly to the CTO
  • Real budget and autonomy to choose and implement tooling
  • International regulatory exposure
  • Clear career pathway toward Head of Security or CISO

About the Company

  • Booming Games is reshaping the iGaming world with a remote-first approach, releasing new slot games every two weeks. The company emphasizes co-ownership and growth within a diverse team.
  • Booming Games has evolved into a leading slot provider, delivering exhilarating mobile and web-based games with a focus on innovation, top-notch gameplay, stunning graphics, and fair and responsible gaming.

Equal Opportunity

  • We embrace diversity and equal employment opportunities. We are committed to creating a fair, supportive, and open environment for all.