Application Security Engineer
Core
Application Security Engineer partnering with development teams to incorporate security practices throughout the software development lifecycle, assess code and builds, and remediate vulnerabilities.
Role type
Application Security Engineer
Builds
Desktop and web applications for the gaming industry
Domain
Gaming / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
manual and automated application security assessments, web security vulnerabilities (OWASP Top 10), low-level vulnerabilities (use-after-free, buffer overflows), networking and web technologies (WebSockets, HTTPS, TCP/IP, UDP), Windows and Linux fundamentals, software development lifecycle (SDLC), client network traffic testing tools (Burp Suite, Fiddler, Bruno), C#
Preferred skills
threat modeling, bug bounty program support, staying abreast of emerging security trends
Technologies
Burp Suite, Fiddler, Bruno, C#, WebSockets, HTTPS, TCP/IP, UDP
Responsibilities
Track trends in the security community and stay abreast of emerging threats, Provide technical security guidance to developers, team leads and producers, Create and maintain threat models of applications and features, Conduct automated and manual security assessments of applications and services, Drive remediation efforts behind internally and publicly identified vulnerabilities, Support maintaining Rockstar Games' public and private bug bounty programs
Seniority
Mid-level, hands-on IC