Application Security Engineer
Core
Application Security Engineer partnering with development teams to incorporate security practices throughout the software development lifecycle, assess code for vulnerabilities, and drive remediation efforts.
Role type
Application Security Engineer
Builds
Secure desktop and web applications for gaming
Domain
Gaming / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Manual and automated application security assessments, OWASP Top 10 vulnerabilities, low-level vulnerabilities (use-after-free, buffer overflows), networking and web technologies (WebSockets, HTTPS, TCP/IP, UDP), Windows and Linux fundamentals, software development lifecycle (SDLC), client network traffic testing tools (Burp Suite, Fiddler, Bruno), C#
Preferred skills
Reverse engineering and exploit research, scripting and process automation, authentication protocols (OAuth2, OIDC), bug bounty programs, C++, JavaScript/TypeScript
Technologies
Burp Suite, Fiddler, Bruno, Ghidra, IDA, x64dbg, WinDbg, C#, C++, JavaScript, TypeScript, OAuth2, OIDC
Responsibilities
Track trends in the security community and stay abreast of emerging threats, Provide technical security guidance to developers, team leads and producers, Create and maintain threat models of applications and features, Conduct automated and manual security assessments of applications and services, Drive remediation efforts behind internally and publicly identified vulnerabilities, Support maintaining Rockstar Games' public and private bug bounty programs
Seniority
Mid-level, hands-on IC