Live opening · Posted 1 day ago

Senior Application & Infrastructure Security Engineer

Baazi Games · European Union (Remote)
Linkedin Yes
You are 1 day behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 1 day ago
CompanyBaazi Games
LocationEuropean Union (Remote)
Work modeYes
SourceLinkedin
Listed1 day ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
5 min from Linkedin publishing this role to us finding it
9 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
73,016 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

About the Role
We are looking for a seasoned Security Engineer to own and elevate the security posture of our platform end to end — from the Cloudflare edge and AWS infrastructure down to the API layer, frontend, and backend application code. This is a high-impact, high-ownership role embedded within engineering. You will work closely with product, DevOps, and development teams to identify threats before they become incidents, respond decisively when they do, and build the systems, policies, and culture that keep our users and platform safe.
Key Responsibilities
Own and drive the end-to-end security posture of all web, API, and infrastructure surfaces
Identify, assess, and remediate vulnerabilities across frontend (web + Electron), backend services, and cloud infrastructure
Design and enforce security controls at the Cloudflare edge — WAF policies, bot mitigation rules, Turnstile integrations, and rate limiting strategies
Harden AWS environments: API Gateway, EC2, Lambda, S3, RDS, and supporting services in line with least-privilege and zero-trust principles
Lead threat modelling sessions for new product features and flag security gaps before they reach production
Monitor, investigate, and respond to security incidents — from Cloudflare firewall events and WAF alerts to SIEM-detected anomalies
Conduct regular penetration testing and vulnerability assessments; triage and prioritise findings by business impact
Define and enforce HTTP security header policies (CSP, HSTS, X-Frame-Options, Referrer-Policy) across all domains
Build and maintain a DDoS response playbook; lead active mitigation during volumetric and application-layer attacks
Partner with engineering teams to embed secure coding practices and participate in code reviews for security-sensitive changes
Manage the responsible disclosure and bug bounty programme; triage external researcher reports
Produce clear security reports, risk registers, and executive briefings; track remediation SLAs
Stay current on emerging attack vectors, CVEs, and threat landscape changes relevant to online gaming and fintech platforms
Must Have — Required Qualifications
10+ years of hands-on experience in application, infrastructure, and web security
Deep expertise in OWASP Top 10 vulnerabilities: SQLi, XSS, CSRF, IDOR, RCE, SSRF, and clickjacking
Proven experience with DDoS attack detection, mitigation, and post-incident analysis
Strong command of Cloudflare — WAF rules, Bot Management, Turnstile, Rate Limiting, Transform Rules, and Firewall Events analysis
Hands-on AWS security experience: IAM policies, Security Groups, VPC design, API Gateway throttling, WAFv2, Shield, GuardDuty, and CloudTrail
Deep understanding of API security: authentication flows (OAuth2, JWT, OTP abuse), rate limiting, and endpoint hardening
Experience securing frontend applications against XSS, CSP bypass, clickjacking, and third-party script risks
Backend security expertise: input validation, secure coding practices, secrets management, SQL injection prevention
Proficiency with penetration testing tools: Burp Suite, OWASP ZAP, Nmap, Metasploit, Nikto
Experience conducting and managing vulnerability assessments, threat modelling, and security audits
Solid understanding of TLS/SSL, HTTP security headers (HSTS, CSP, X-Frame-Options), certificate management
Experience with SIEM platforms, log aggregation, alert tuning, and incident response
Knowledge of bot mitigation strategies — JA3/JA4 fingerprinting, bot scoring, heuristic vs ML detection
Familiarity with compliance frameworks: ISO 27001, SOC 2, PCI-DSS, or GDPR
Strong written and verbal communication skills — able to produce security reports and brief non-technical stakeholders
Hands-on experience integrating security testing into CI/CD pipelines: SAST, DAST, SCA, and secrets scanning as automated gates
Good to Have — Preferred Qualifications
Experience with Cloudflare Zero Trust, Access, and Tunnel for secure internal tooling
Familiarity with threat intelligence platforms (VirusTotal, Shodan, AlienVault OTX)
Bug bounty experience or CVE disclosures
Scripting skills (Python, Bash, or Go) to automate security scanning and alerting pipelines
Experience securing Electron desktop applications and mobile API surfaces
Understanding of blockchain/crypto platform security: wallet integrations, smart contract interactions, and on-chain transaction verification
Knowledge of container security: Docker, Kubernetes RBAC, image scanning (Trivy, Snyk)
Certifications: OSCP, CEH, CISSP, AWS Security Specialty, or equivalent
Experience with chaos engineering or red team / blue team exercises
Exposure to gaming or fintech regulatory environments
Why Join Us
You will be the go-to security authority on a fast-growing platform operating at millions of requests per day across a global user base. You will have the autonomy to define how security works here — from tooling choices to how we respond under fire. If you want a role where your decisions actually matter and your work is visible, this is it.

Work arrangement
Yes

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App