BettingJobs is working with a rapidly growing B2B iGaming technology business on the appointment of an experienced Security Engineer to join its in-house technology function in Armenia.
This is a high-impact role securing a large-scale platform that powers sportsbook and casino products across multiple regulated markets, spanning customer-facing sites, management systems, wallet and payment integrations, third-party gaming integrations and high-volume transactional services.
Responsibilities:
- Identify, assess and mitigate security vulnerabilities across applications, infrastructure, networks and systems
- Perform security assessments of web applications, APIs, servers and third-party integrations
- Conduct vulnerability assessments and coordinate remediation with engineering teams
- Review application architecture and designs for security risks, and work with developers to remediate issues
- Review authentication, authorisation, session management and access-control implementations
- Assess REST APIs and external integrations for security vulnerabilities
- Implement and maintain security controls for production infrastructure, working closely with DevOps to secure servers, networks and deployments
- Establish secure configuration and hardening standards for Windows and Linux systems
- Monitor security events, logs and alerts, and support incident detection, investigation, response and root-cause analysis
- Manage vulnerability scanning and security testing processes, and support penetration testing and remediation
- Implement and maintain secrets, credentials, key and certificate-management practices
- Review third-party software, APIs and integrations from a security perspective
- Help establish secure software-development practices and security requirements, providing guidance to engineering and IT teams
- Maintain security documentation, policies, procedures and risk registers
- Support backup, disaster recovery and business continuity security requirements
- Stay current with emerging vulnerabilities, attack techniques and best practices
Requirements:
- 3+ years' professional experience in cybersecurity, application security, infrastructure security or a related field
- Strong understanding of web application security and the OWASP Top 10
- Experience performing vulnerability assessments and security testing
- Experience with API security and RESTful APIs
- Strong understanding of authentication, authorisation, session management and access control
- Experience with network security, including firewalls, VPNs, TCP/IP, DNS, HTTP/HTTPS and network segmentation
- Experience securing Windows Server environments and working knowledge of Linux security
- Experience with vulnerability scanning and security assessment tools
- Experience with security monitoring, logging and incident investigation
- Understanding of encryption, hashing, TLS/SSL, certificates and secure key management
- Understanding of secure software-development practices, with a track record of working alongside developers and DevOps teams on remediation
- Strong understanding of identity and access management principles
- Strong problem-solving and analytical skills
- Good written and spoken English