Job Closed
This listing is no longer active.
Where Poker Meets Blockchain - CoinPoker, the Future of Online Gaming!
Senior Application & Infrastructure Security Engineer
Location
Worldwide
Posted
47 days ago
Salary
0
Seniority
Senior
Job Description
Senior Application & Infrastructure Security Engineer
CoinPoker
• Own and drive the end-to-end security posture of all web, API, and infrastructure surfaces • Identify, assess, and remediate vulnerabilities across frontend (web + Electron), backend services, and cloud infrastructure • Design and enforce security controls at the Cloudflare edge — WAF policies, bot mitigation rules, Turnstile integrations, and rate limiting strategies • Harden AWS environments: API Gateway, EC2, Lambda, S3, RDS, and supporting services in line with least-privilege and zero-trust principles • Lead threat modelling sessions for new product features and flag security gaps before they reach production • Monitor, investigate, and respond to security incidents — from Cloudflare firewall events and WAF alerts to SIEM-detected anomalies • Conduct regular penetration testing and vulnerability assessments; triage and prioritise findings by business impact • Define and enforce HTTP security header policies (CSP, HSTS, X-Frame-Options, Referrer-Policy) across all domains • Build and maintain a DDoS response playbook; lead active mitigation during volumetric and application-layer attacks • Partner with engineering teams to embed secure coding practices and participate in code reviews for security-sensitive changes • Manage the responsible disclosure and bug bounty programme; triage external researcher reports • Produce clear security reports, risk registers, and executive briefings; track remediation SLAs • Stay current on emerging attack vectors, CVEs, and threat landscape changes relevant to online gaming and fintech platforms
Job Requirements
- 8+ years of hands-on experience in application, infrastructure, and web security
- Deep expertise in OWASP Top 10 vulnerabilities: SQLi, XSS, CSRF, IDOR, RCE, SSRF, and clickjacking
- Proven experience with DDoS attack detection, mitigation, and post-incident analysis
- Strong command of Cloudflare — WAF rules, Bot Management, Turnstile, Rate Limiting, Transform Rules, and Firewall Events analysis
- Hands-on AWS security experience: IAM policies, Security Groups, VPC design, API Gateway throttling, WAFv2, Shield, GuardDuty, and CloudTrail
- Deep understanding of API security: authentication flows (OAuth2, JWT, OTP abuse), rate limiting and endpoint hardening
- Experience securing frontend applications against XSS, CSP bypass, clickjacking, and third-party script risks
- Backend security expertise: input validation, secure coding practices, secrets management, SQL injection prevention
- Proficiency with penetration testing tools: Burp Suite, OWASP ZAP, Nmap, Metasploit, Nikto
- Experience conducting and managing vulnerability assessments, threat modelling, and security audits
- Solid understanding of TLS/SSL, HTTP security headers (HSTS, CSP, X-Frame-Options), certificate management
- Experience with SIEM platforms, log aggregation, alert tuning, and incident response
- Knowledge of bot mitigation strategies — JA3/JA4 fingerprinting, bot scoring, heuristic vs ML detection
- Familiarity with compliance frameworks: ISO 27001, SOC 2, PCI-DSS, or GDPR
- Strong written and verbal communication skills — able to produce security reports and brief non-technical stakeholders
- Hands-on experience integrating security testing into CI/CD pipelines: SAST, DAST, SCA, and secrets scanning as automated gates
Benefits
- Flexible work arrangements
- Professional development
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Principal Specialist, IT & Cloud Security
HARMAN InternationalHarman International is a global leader in automotive technology, lifestyle innovations, design and analytics.
A Career at HARMAN As a technology leader that is rapidly on the move, HARMAN is filled with people who are focused on making life better. Innovation, inclusivity and teamwork are a part of our DNA. When you add that to the challenges we take on and solve together, you’ll discover that at HARMAN you can grow, make a difference and be proud of the work you do every day. Introduction: A Career at HARMAN Automotive We’re a global, multi-disciplinary team that’s putting the innovative power of technology to work and transforming tomorrow. At HARMAN Automotive, we give you the keys to fast-track your career. · Engineer audio systems and integrated technology platforms that augment the driving experience · Combine ingenuity, in-depth research, and a spirit of collaboration with design and engineering excellence · Advance in-vehicle infotainment, safety, efficiency, and enjoyment. About the Role As an IT & Cloud Security Engineer, you will bring specialized depth and breadth of expertise in Cloud Security and Risk Governance, leading strategic security initiatives and ensuring the implementation of best practices across the organization. This role requires a strong analytical mindset, the ability to lead complex projects, and a deep understanding of enterprise security frameworks. You will independently drive security improvements, providing strategic recommendations to address both internal and external business challenges. As a thought leader in security, you will collaborate with cross-functional teams to strengthen the company’s security posture, influencing technology, processes, and risk management. Additionally, you will be facilitating technical discussions with external vendors, ensuring accountability for performance, and optimizing security tools across the organization. Your insights will directly impact security strategy, operational excellence, and risk mitigation at a global scale. This position reports to the Director, Digital Security Engineering and is technically guiding a Cloud Security Analyst position. You also lead cross-functional teams on security initiatives and projects with moderate resource requirements, risk, and complexity What You Will Do - Drive the company's Cloud Security strategy, ensuring continuous improvement and optimization in alignment with industry best practices. - Own and enhance the risk governance framework for Cloud Security, defining KPIs and reporting metrics for executive leadership. - Independently assess, analyze, and mitigate complex security risks, influencing corporate-wide security decisions. - Lead security-related projects with cross-functional teams, ensuring effective collaboration and risk mitigation. - Manage and evaluate external security vendors, ensuring appropriate licensing, service quality and accountability. - Provide strategic guidance to business and IT teams, interpreting business challenges and identifying innovative solutions. - Communicate complex security concepts to stakeholders, negotiating adoption of best practices across departments. - Ensure effective operation and maintenance of security tools, continuously identifying opportunities for improvement. What You Need to Be Successful - Bachelor’s degree or equivalent qualification. - 8+ years of experience in Cyber Security, preferably in a global organization. - Deep expertise in Risk Governance and Cloud Security, including AWS, Azure, or GCP. - Strong knowledge of Endpoint Security, Application Security, and Network Security. - CISSP certification required. - Experience managing external security vendors and ensuring performance accountability. - Ability to interpret complex security risks, provide strategic recommendations, and influence leadership decisions. - Strong project leadership experience, with the ability to lead cross-functional teams on security initiatives. - Excellent communication and negotiation skills, with the ability to explain complex security challenges to both technical and non-technical stakeholders. - Structured and analytical approach to problem-solving, with strong prioritization skills. Bonus Points if You Have - Additional security certifications (e.g., CISM, CCSP, ISO 27001 LI, OSCP). - Hands-on expertise with Cisco and CrowdStrike security solutions. - Experience in enterprise security architecture and cloud-native security solutions. What Makes You Eligible - Be willing to travel up to 5%, domestic only OR domestic and international travel What We Offer - Flexible work environment, allowing for full-time remote work globally for positions that can be performed outside a HARMAN or customer location - Access to employee discounts on world-class Harman and Samsung products (JBL, HARMAN Kardon, AKG, etc.) - Extensive training opportunities through our own HARMAN University - Competitive wellness benefits - Tuition reimbursement - “Be Brilliant” employee recognition and rewards program - An inclusive and diverse work environment that fosters and encourages professional and personal development #LI-NK3 HARMAN is proud to be an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
Security Hacking Expert - CL11
AccentureAccenture Federal Services, a division of Accenture, provides technology and consulting services to U.S. federal agencies, delivering solutions that enhance performance and efficie
. . About Accenture Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.Visit us at www.accenture.com Declaración de igualdad de oportunidades en el empleo Creemos que nadie debe ser discriminado por sus diferencias. Todas las decisiones de empleo se tomarán sin importar la edad, raza, credo, color, religión, sexo, origen nacional, ascendencia, discapacidad, condición de veterano militar, orientación sexual, identidad o expresión de género, información genética, estado civil, ciudadanía ni ningún otro criterio protegido por la legislación aplicable. Nuestra rica diversidad nos hace más innovadores, competitivos y creativos, lo que nos ayuda a servir mejor a nuestros clientes y comunidades.
We are looking for a Senior Security Specialist to lead and support cybersecurity and compliance initiatives across our cloud environments. This role will be responsible for managing security compliance processes, assessing regulatory and customer-specific requirements in new countries and markets, and ensuring the organization maintains strong security posture aligned with standards such as SOC 2, ISO 27001, and GDPR. Innovecs is a global digital transformation tech company with a presence in the US, the UK, the EU, Israel, Australia, and Ukraine. Specializing in software solutions, the Innovecs team has experience in Supply Chain, Healthtech, Software & Hightech, and Gaming. For the fifth year in a row, Innovecs is included in the Inc. 5000 and recognized in IAOP’s ranking of the best global outsourcing service providers. Innovecs is featured in the Global Top 100 Inspiring Workplaces Ranking and won gold at the Employer Brand Management Awards. Our value to you: - Flexible hours and remote-first mode - Competitive compensation - Complete Hardware/Software setup – anything you need for work - Open-door culture, transparent communication, and top management at a handshake distance - Health insurance, vacation, sick leaves, holidays, paid maternity/paternity leave - Access to our learning & development center: workshops, webinars, training platform, and edutainment events - Virtual team buildings and social activities If you feel like you’re the perfect match for this role, drop us your CV! There are no limitations, no barriers when the right people are on your way — apply for the vacancy and succeed with us! Innovecs is an equal opportunity employer. All hiring decisions are based on professional qualifications, skills, and experience. We are committed to a transparent, merit-based recruitment process that prevents discrimination and ensures equal opportunities for all candidates. Reasonable accommodations are available upon request throughout the recruitment process to support accessibility and inclusion.
• Develop and implement threat modeling to identify security risks across applications and infrastructure. • Conduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses. • Define and enforce secure coding practices in collaboration with development teams. • Work with DevOps to integrate security into CI/CD pipelines and automate security testing. • Monitor and respond to security incidents, conducting root cause analysis and implementing preventative measures. • Ensure compliance with security standards and regulations (e.g., ISO 27001, GDPR, SOC 2). • Design and implement identity and access management (IAM) policies, encryption standards, and authentication mechanisms. • Collaborate with product teams to conduct security reviews of features, APIs, and third-party integrations. • Develop incident response plans, security documentation, and best practices. • Stay ahead of emerging threats, vulnerabilities, and security technologies.



