Application Security Engineer
Required skills
3+ years of experience working in a professional, academic or research environment identifying and remediating security bugs/flaws, Strong knowledge of the principles and techniques for both manual and automated application security assessments of desktop and web applications, Good knowledge of common web security vulnerabilities (e.g., OWASP Top 10), attack techniques and remediation tactics/strategies, Good understanding of common low-level vulnerabilities (e.g. use-after-free and buffer overflows) and common mitigations, Good understanding of networking and web technologies (e.g. WebSockets, HTTPS, TCP/IP, UDP) and security controls relevant to them, Familiarity with Windows and Linux operating systems fundamentals, Familiarity with the software development lifecycle (SDLC) and working knowledge of components to secure the SLDC, Practical experience with client network traffic testing tools and techniques e.g., Burp Suite, Fiddler and Bruno, Proficiency in C#, Excellent communication skills
Preferred skills
BSc/MSc in a computer science or related field, Background in reverse engineering and exploit research & development and relevant tools such as Ghidra, IDA, x64dbg and WinDbg, Experience with scripting and process automation, An understanding of effective practices for securing the SDLC that considers developer experience, sustainability and compliments release velocity, Experience with authentication protocols and extensions such as OAuth2 and OIDC, Experience in results-oriented, retail driven environment with strict deadlines and ship dates, Familiarity with bug bounty programs/responsible disclosure programs, either running one or as a researcher, Proficiency in C++ and JavaScript/TypeScript
Technologies
C#, C++, JavaScript/TypeScript, Burp Suite, Fiddler, Bruno, Ghidra, IDA, x64dbg, WinDbg
Responsibilities
Track trends in the security community and stay abreast of emerging threats, Provide technical security guidance to developers, team leads and producers, Create and maintain threat models of applications and features to systematically understand how they can be attacked to prioritize control development, Conduct automated and manual security assessments of applications and services, Drive remediation efforts behind internally and publicly identified vulnerabilities, Support maintaining Rockstar Games’ public and private bug bounty programs
Seniority
Not specified
Domain
Application security, software development, game development