Remote job
Infrastructure Security Engineer
Job details
About this role
Role overview
Hands-on infrastructure security engineer role owning the security of a Linux-based gaming platform, including hosts and containers that serve games, a MongoDB data layer, and the network edge that operator partners connect to. You will write security protocols, implement them on the infrastructure, keep them running, and update them as threats and regulatory requirements evolve. The role reports directly to the CTO and partners with platform engineering and technical compliance teams.
Responsibilities
- Own the full lifecycle of technical security protocols: write, implement, maintain, and update on a defined review cadence - Define hardening baselines for Linux hosts, Docker images and containers, MongoDB clusters, and network devices across production, staging, and development - Maintain operational runbooks for patching, access provisioning, key and certificate rotation, backup verification, and incident handling - Translate ISO 27001 controls and regulator technical standards into concrete testable configuration - Harden the Linux server estate, container platform, MongoDB clusters, secrets management, and network segmentation - Lead incident response, coordinate with external forensic or penetration testing providers, and drive issues to closure
Requirements
- 4+ years of hands-on experience in security engineering, DevSecOps, or infrastructure security, with demonstrable ownership of a production environment - Strong Linux administration and hardening skills (Debian or RHEL family), including SSH, firewalls, systemd, auditd, and patching - Solid MongoDB security knowledge covering authentication, RBAC, TLS, encryption at rest, auditing, and backup protection - Docker and container security in production, including image hygiene, scanning, registries, runtime hardening, and secrets handling - Strong networking fundamentals: TCP/IP, DNS, TLS, routing, firewalls, VPNs, load balancers, segmentation, and WAF/CDN configuration - Experience selecting and operating security tooling such as SIEM, IDS/IPS, vulnerability scanners, endpoint protection, and secrets management - Scripting and automation in Bash and Python or equivalent - Incident response experience on live systems, including evidence handling and root cause analysis - Working knowledge of ISO 27001 controls and how they map to technical implementation - Located within the European time zone (plus or minus 2 hours)
Nice to have
- Infrastructure-as-code tools (Terraform, Ansible) combined with policy-as-code or IaC scanning - Experience with both public cloud and bare-metal or co-located hosting - Penetration testing or offensive security background - Professional certifications such as OSCP, CISSP, CCSP, GIAC, or CompTIA Security+
Benefits and work setup
- Competitive base salary with a performance-linked bonus - Flexible and/or hybrid working arrangements - Ownership of the security function for a live high-traffic platform, with direct CTO exposure - Budget and autonomy to choose and implement the tooling you need - International regulatory exposure across multiple licensed jurisdictions - Clear career pathway toward Head of Security or CISO as the function grows