Remote job

Infrastructure Security Engineer

Booming Games

Source: PersonioLocation: EU/EMEAPublished: Sep 23, 2026Confirmed active: Sep 23, 2026
Full-time

Key points from the posting

Tech stack
LinuxDockerMongoDBSSHTLSWAFCDNVPNMFASIEM
Seniority:
Senior

Read out of the job posting automatically

Our assessment

  • The posting states no salary. Comparable roles in our index (80 postings): median 5,834 euros per month, middle range 4,400 to 6,917 euros.
  • 5 more open roles from this employer in our index. 5 of them fully remote.

This section only: calculated automatically by nomado24, from our own job index and our own reading of the posting text. Not stated by the employer.

Job description

About the role

We are looking for an Infrastructure Security Engineer to own the security of the Booming Games platform: the Linux hosts and containers that serve our games, the MongoDB data layer and the network edge our operator partners connect to.

This is a hands-on role. You will write the security protocols, implement them on the infrastructure, keep them running and update them as threats and regulatory requirements evolve. You will choose and operate the tooling, run the vulnerability and patch cycle, and be the first responder when something looks wrong.

You report directly to the CTO and work with the Systems and Infrastructure team, platform engineers and Technical Compliance (owners of the ISMS and ISO 27001).

Responsibilities

  • Security Protocols & Standards
  • Own the full lifecycle of Booming Games' technical security protocols: write them, implement them, maintain them and update them on a defined review cadence
  • Define hardening baselines for Linux hosts, Docker images and containers, MongoDB clusters and network devices, and enforce them across production, staging and development
  • Maintain operational runbooks for patching, access provisioning and revocation, key and certificate rotation, backup verification and incident handling
  • Translate ISO 27001 controls and regulator technical standards into concrete, testable configuration, working with Technical Compliance on evidence and audit readiness
  • Review and approve security-relevant changes to infrastructure and platform architecture before they reach production
  • Infrastructure & Platform Hardening
  • Harden the Linux server estate: SSH policy, privilege management, kernel and package patching, host firewalls, file integrity and audit logging
  • Secure the container platform: minimal base images, image scanning in the build pipeline, registry controls, runtime restrictions, secrets injection and least-privilege service accounts
  • Own MongoDB security: authentication and role-based access, TLS between nodes and clients, encryption at rest, audit logging, backup encryption and restore testing
  • Manage secrets, keys and certificates centrally, with documented ownership, rotation schedules and no credentials in code or images
  • Reduce the attack surface of game servers and platform services through segmentation, exposure reviews and removal of unused services and ports
  • Network Security
  • Design and maintain network segmentation between public-facing game delivery, internal platform services, databases and management access
  • Operate the edge: firewall rules, WAF and CDN policies, rate limiting, DDoS mitigation and TLS configuration for all external endpoints
  • Control partner and aggregator connectivity: IP allow-listing, mutual TLS or VPN where required, and reviewed exposure of every integration endpoint
  • Secure remote and administrative access through VPN, bastion hosts, MFA and session logging
  • Maintain accurate network diagrams and an inventory of every internet-facing asset
  • Security Tooling, Monitoring & Detection
  • Select, deploy and operate the security toolset: centralised logging and SIEM, intrusion detection, vulnerability scanning, endpoint protection and secrets scanning
  • Build alerting that detects unauthorised access, privilege escalation, anomalous database queries, configuration drift and abnormal traffic to game endpoints
  • Tune detection to reduce noise so that alerts are acted on, and define escalation paths and on-call expectations for security events
  • Run the vulnerability and patch management cycle end to end: scan, prioritise by exploitability and exposure, remediate, verify and report
  • Track security metrics (patch latency, open findings by severity, mean time to detect and respond) and report them to the CTO monthly
  • Incident Detection & Response
  • Act as first technical responder for suspected security incidents: contain, preserve evidence, investigate root cause and coordinate remediation
  • Own the incident response plan and run at least one tabletop or live exercise per year against a realistic platform compromise scenario
  • Produce post-incident reports with timeline, impact, root cause and corrective actions, and drive those actions to closure
  • Support Legal, Compliance and Commercial with the technical facts needed for regulator, partner and operator notifications
  • Coordinate with external forensic or penetration testing providers when engaged
  • Assurance, Audit & Awareness
  • Provide the technical input for ISO 27001 audits, certification lab reviews and regulator security submissions, and remediate findings
  • Complete operator and aggregator security questionnaires and due diligence requests accurately and on time
  • Commission and manage annual penetration tests, triage results and track remediation
  • Review third-party services and vendors with access to infrastructure or data before onboarding
  • Run practical security awareness for engineering and …
Engineeringpermanent

This role is provided by an external source. Applications are handled on the source website.

New remote jobs like “Security Engineer” by email

Only when something fitting appears. Free, unsubscribe any time.

You confirm your subscription by email (double opt-in) and can unsubscribe at any time via the link in every email. Our Privacy Policy.

All Remote DevOps Jobs
Or let us search for you

Matching job categories

Not the right job?