Booming Games
Infrastructure Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About the Role
We are looking for an Infrastructure Security Engineer to own the security of the Booming Games platform: the Linux hosts and containers that serve our games, the MongoDB data layer and the network edge our operator partners connect to.
This is a hands-on role. You will write the security protocols, implement them on the infrastructure, keep them running and update them as threats and regulatory requirements evolve. You will choose and operate the tooling, run the vulnerability and patch cycle, and be the first responder when something looks wrong.
You report directly to the CTO and work with the Systems and Infrastructure team, platform engineers and Technical Compliance (owners of the ISMS and ISO 27001).
Responsibilities
Security Protocols & Standards
- Own the full lifecycle of Booming Games' technical security protocols: write them, implement them, maintain them and update them on a defined review cadence
- Define hardening baselines for Linux hosts, Docker images and containers, MongoDB clusters and network devices, and enforce them across production, staging and development
- Maintain operational runbooks for patching, access provisioning and revocation, key and certificate rotation, backup verification and incident handling
- Translate ISO 27001 controls and regulator technical standards into concrete, testable configuration, working with Technical Compliance on evidence and audit readiness
- Review and approve security-relevant changes to infrastructure and platform architecture before they reach production
Infrastructure & Platform Hardening
- Harden the Linux server estate: SSH policy, privilege management, kernel and package patching, host firewalls, file integrity and audit logging
- Secure the container platform: minimal base images, image scanning in the build pipeline, registry controls, runtime restrictions, secrets injection and least-privilege service accounts
- Own MongoDB security: authentication and role-based access, TLS between nodes and clients, encryption at rest, audit logging, backup encryption and restore testing
- Manage secrets, keys and certificates centrally, with documented ownership, rotation schedules and no credentials in code or images
- Reduce the attack surface of game servers and platform services through segmentation, exposure reviews and removal of unused services and ports
Network Security
- Design and maintain network segmentation between public-facing game delivery, internal platform services, databases and management access
- Operate the edge: firewall rules, WAF and CDN policies, rate limiting, DDoS mitigation and TLS configuration for all external endpoints
- Control partner and aggregator connectivity: IP allow-listing, mutual TLS or VPN where required, and reviewed exposure of every integration endpoint
- Secure remote and administrative access through VPN, bastion hosts, MFA and session logging
- Maintain accurate network diagrams and an inventory of every internet-facing asset
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Security Tooling, Monitoring & Detection
- Select, deploy and operate the security toolset: centralised logging and SIEM, intrusion detection, vulnerability scanning, endpoint protection and secrets scanning
- Build alerting that detects unauthorised access, privilege escalation, anomalous database queries, configuration drift and abnormal traffic to game endpoints
- Tune detection to reduce noise so that alerts are acted on, and define escalation paths and on-call expectations for security events
- Run the vulnerability and patch management cycle end to end: scan, prioritise by exploitability and exposure, remediate, verify and report
- Track security metrics (patch latency, open findings by severity, mean time to detect and respond) and report them to the CTO monthly
Incident Detection & Response
- Act as first technical responder for suspected security incidents: contain, preserve evidence, investigate root cause and coordinate remediation
- Own the incident response plan and run at least one tabletop or live exercise per year against a realistic platform compromise scenario
- Produce post-incident reports with timeline, impact, root cause and corrective actions, and drive those actions to closure
- Support Legal, Compliance and Commercial with the technical facts needed for regulator, partner and operator notifications
- Coordinate with external forensic or penetration testing providers when engaged
Assurance, Audit & Awareness
- Provide the technical input for ISO 27001 audits, certification lab reviews and regulator security submissions, and remediate findings
- Complete operator and aggregator security questionnaires and due diligence requests accurately and on time
- Commission and manage annual penetration tests, triage results and track remediation
- Review third-party services and vendors with access to infrastructure or data before onboarding
- Run practical security awareness for engineering and operations staff, and embed secure configuration checks into deployment pipelines
Requirements
- 4+ years of hands-on experience in security engineering, DevSecOps or infrastructure security, with demonstrable ownership of a production environment's security
- Strong Linux administration and hardening skills (Debian or RHEL family): users and privileges, SSH, firewalls, systemd, auditd, log management and patching
- Solid MongoDB security knowledge: authentication and RBAC, TLS, encryption at rest, replica set security, auditing and backup protection
- Docker and container security in production: image build hygiene, scanning, registries, runtime hardening and secrets handling
- Strong networking fundamentals: TCP/IP, DNS, TLS, routing, firewalls, VPNs, load balancers, segmentation and WAF/CDN configuration
- Experience selecting and operating security tooling: SIEM or log analytics, IDS/IPS, vulnerability scanners, endpoint protection and secrets management
- Scripting and automation in Bash and Python (or equivalent), with the ability to automate checks, remediation and reporting
- Experience writing security protocols and runbooks that engineers actually follow, and the discipline to keep them current
- Incident response experience on live systems, including evidence handling and root cause analysis
- Working knowledge of ISO 27001 controls and how they map to technical implementation
- Clear written and verbal communication, able to explain risk and required actions to engineers, management and external auditors


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Nice to have
- Experience in online gambling or iGaming, ideally on the supplier side: RGS platforms, game servers and operator integrations
- Familiarity with regulator and certification technical security standards such as ISO 27001, MGA and UKGC security requirements, GLI-19 and GLI-33, and experience working with test labs such as GLI, eCOGRA or iTech Labs
- Kubernetes security and infrastructure-as-code tooling (Terraform, Ansible) with policy-as-code or IaC scanning
- Experience with both public cloud and bare-metal or co-located hosting
- Penetration testing or offensive security background
- Professional certification such as OSCP, CISSP, CCSP, GIAC or CompTIA Security+
Good to know
We embrace diversity and equal employment opportunities. We are committed to creating a fair, supportive, and open environment for all.
Please understand that we can only consider applicants who are located in the European time zone. (+/- 2 hours). All other applications will be automatically deleted due to the high volume of applicants.
Why Work for Booming Games
Founder led. Impact driven. Employee centric.
At Booming Games, we're reshaping the iGaming world with our remote-first approach. Our rhythm? Thrilling slot games with captivating features and stunning designs released every two weeks - no exceptions! Here, it's all about co-ownership and real growth. Dive into a diverse team where your input powers every game we craft!
Our perks
- Competitive base salary with performance-linked bonus
- Flexible and/or hybrid working arrangements
- Ownership of the security function for a live, high-traffic gaming platform, reporting directly to the CTO
- Real budget and autonomy to choose and implement the tooling you need
- International regulatory exposure across multiple licensed jurisdictions
- Clear career pathway toward Head of Security or CISO as the function grows
Contact
HR Team
About us
BOOMING GAMES has evolved from a shared vision into a leading slot provider, delivering exhilarating mobile and web-based games. Our drive for innovation shapes an extraordinary gaming experience featuring top-notch gameplay, stunning graphics, and a steadfast commitment to fair and responsible gaming. Join us on this thrilling adventure, where each game we create is not just a product but a captivating journey blending cutting-edge technology with boundless excitement.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London