appsec engineer

Enfint

Barcelona

Presencial

EUR 90.000 - 140.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Scopely, a global leader in mobile and web gaming, seeks an experienced security leader to strengthen product security across our game development lifecycle. You will drive risk-based security strategies, perform threat modeling, and implement AI-enabled security workflows for both backend and client systems.

You will collaborate with game studios, security operations, and engineering teams to ensure secure coding practices, conduct penetration testing, and provide expert guidance on cloud

Formación

  • 8+ years of experience in product security, software development, or cybersecurity.
  • Proven experience securing large-scale software applications and systems.
  • Hands-on experience applying AI/LLMs to operational workflows, including designing, evaluating, and safely deploying AI-assisted systems.
  • Ability to communicate business risk and technical information clearly to technical and non-technical audiences.
  • Expert knowledge of modern programming languages such as Python and C#.
  • Strong understanding of API and backend security.
  • Experience with mobile application penetration testing, including traffic interception, runtime analysis, and API security.
  • Experience with modern development ecosystems, CI/CD pipelines, APIs, and developer platforms.
  • Hands-on experience with AWS shared responsibility, IAM, access control, and cloud network security.
  • Strong understanding of securing cloud workloads through configuration, deployment, and auditing.
  • Deep knowledge of Linux security practices.
  • Ability to think like both an attacker and defender.
  • Excellent analytical, problem-solving, and decision-making skills.
  • Exceptional communication and leadership skills; nice to have: GDPR, ISO 27001, and related frameworks.

Responsabilidades

  • Partner with game studios to develop comprehensive security strategies for game design and development.
  • Conduct threat modeling, vulnerability assessments, and security audits across all phases of game development.
  • Design and implement security controls and countermeasures to mitigate risks and ensure compliance with company policies and standards.
  • Collaborate with game teams to advocate for secure coding practices and integrate security throughout the SDLC.
  • Coordinate and participate in penetration tests and game feature security assessments.
  • Provide expert-level technical guidance to game teams securing games and backend infrastructure.
  • Translate business priorities and threat intelligence into actionable security roadmaps.
  • Identify and implement AI opportunities for vulnerability management and security operations.
  • Build AI-driven workflows, tools, and agents to reduce manual effort and improve speed and accuracy.
  • Integrate AI capabilities into security platforms (Wiz, SIEM, Jira, IAM).
  • Establish guardrails for safe AI use in security, including data handling and human review.
  • Define success metrics for AI-enabled workflows and security improvements.
  • Develop scalable security solutions across cloud and backend systems.
  • Stay updated on security technologies and AI capabilities.

Conocimientos

8+ years experience
Security tooling
AI/LLMs in operations
risk communication
Python
C#
API & backend security
Mobile app pentesting
CI/CD
AWS security
Linux security
attack/defender mindset
leadership

Herramientas

AWS
CI/CD pipelines
OWASP
NIST CSF

Descripción del empleo

Описание

Scopely is a global video game and interactive entertainment company that creates, develops, publishes, and live-operates games across mobile, web, PC, and console. Its portfolio includes MONOPOLY GO!, Pokémon GO, Stumble Guys, Star Trek™ Fleet Command, MARVEL Strike Force, and other games, supported by the proprietary Playgami technology platform.

Задачи
  • Partner with game studios to develop comprehensive security strategies for game design and development;
  • Conduct threat modeling, vulnerability assessments, and security audits across all phases of game development;
  • Design and implement security controls and countermeasures to mitigate risks and ensure compliance with company policies, standards, and industry norms;
  • Collaborate with game teams to advocate for secure coding practices and integrate security throughout the software development lifecycle;
  • Coordinate and participate in penetration tests and game feature security assessments;
  • Provide expert-level technical guidance to game teams securing games and backend infrastructure;
  • Translate business priorities, technical constraints, and threat intelligence into actionable security roadmaps;
  • Identify and implement AI opportunities for vulnerability management, security operations, and product security processes;
  • Build AI-driven workflows, tools, and agents to reduce manual effort and improve speed and accuracy;
  • Use AI to support vulnerability triage, risk classification, remediation guidance, and findings analysis;
  • Partner with Security Operations to improve detection, triage, investigation, and response through automation and AI-assisted analysis;
  • Integrate AI capabilities into security platforms such as Wiz, SIEM, Jira, and IAM systems;
  • Develop reusable AI-enabled components that scale across teams and studios;
  • Establish guardrails for safe and effective AI use in security, including data handling, quality control, and human review;
  • Define success metrics for AI-enabled workflows, including productivity gains, response times, remediation throughput, and signal quality;
  • Design and implement scalable security solutions across cloud and backend systems;
  • Work with information security domain owners to ensure games follow relevant security policies, standards, and regulatory requirements;
  • Develop and maintain documentation on security architectures, processes, and decisions for technical and non-technical stakeholders;
  • Improve security engineering efficiency through automation and tooling;
  • Stay updated on security technologies, trends, threats, and AI capabilities;
  • Interact with game studio leaders to understand roadmaps, risk posture, and how information security can support secure execution;
  • Develop security-related roadmaps with game teams;
  • Report to Information Security and Studio management on the threat landscape and security posture of games;
  • Act as a thought leader using qualitative and quantitative risk assessment frameworks;
  • Lead or assist with security incidents and investigations.
Требования
  • 8+ Years of experience in Product Security, software development, or cybersecurity;
  • Proven experience securing large-scale software applications and systems;
  • Strong experience building automation and security tooling;
  • Hands-on experience applying AI/LLMs to operational workflows, including designing, evaluating, and safely deploying AI-assisted systems;
  • Ability to communicate business risk and technical information clearly to technical and non-technical audiences;
  • Expert knowledge of modern programming languages such as Python and C#;
  • Strong understanding of application and product security, vulnerability management, and penetration testing methodologies;
  • Strong understanding of API and backend security;
  • Experience with mobile application penetration testing, including traffic interception, runtime analysis, and API security;
  • Experience with modern development ecosystems, CI/CD pipelines, APIs, and developer platforms;
  • Hands-on experience with AWS shared responsibility, IAM, access control, and cloud network security;
  • Strong understanding of securing cloud workloads through configuration, deployment, and auditing;
  • Deep knowledge of Linux security practices;
  • Ability to think like both an attacker and defender;
  • Excellent analytical, problem-solving, and decision-making skills;
  • Exceptional communication and leadership skills with the ability to influence across teams;
  • Nice to have: Experience architecting and managing high-scale, high-velocity workloads in AWS, familiarity with OWASP, NIST Cybersecurity Framework, GDPR, CCPA, and ISO 27001, experience at a game company, experience applying AI to security, automation, or developer workflows, familiarity with RAG architectures, vector databases such as pgvector, and AI-assisted code analysis or pentesting.
Условия

Hybrid role based in Barcelona, Catalonia, Spain, with the security team covering Spain and Portugal; No conditions specified.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Principal AI Product Security Engineer ES - Barcelona, Spain; ES - Spain; PT - Portugal
Principal AI Product Security Engineer ES - Barcelona, Spain; ES - Spain; PT - Portugal

Scopely • Barcelona

Presencial
EUR 70.000 - 100.000
Senior Engineer - Security Compliance New ES - Barcelona, Spain
Senior Engineer - Security Compliance New ES - Barcelona, Spain

Scopely • Barcelona

Presencial
EUR 60.000 - 80.000
Senior Security Compliance Engineer
Senior Security Compliance Engineer

Scopely • Barcelona

Híbrido
EUR 90.000 - 130.000
Sr. Security Compliance Engineer
Sr. Security Compliance Engineer

Scopely • Barcelona

Híbrido
EUR 65.000 - 95.000
Senior AppSec Engineer: AI-Driven Game Security
Senior AppSec Engineer: AI-Driven Game Security

Enfint • Barcelona

Híbrido
EUR 90.000 - 140.000
Senior Application Security Engineer
Senior Application Security Engineer

LeoVegas Group • Málaga

Híbrido
EUR 70.000 - 100.000
Hybrid work policy
Workation benefits
Wellness contribution
+7
Senior AI-Driven Product Security Engineer
Senior AI-Driven Product Security Engineer

Scopely • Barcelona

Híbrido
EUR 70.000 - 100.000
security engineer for web applications
security engineer for web applications

Enfint • Barcelona

Presencial
EUR 60.000 - 90.000
Commitment to professional development
Flexible and collaborative culture
Global opportunities
+2
Global Health & Safety Leader (Hybrid, 8 months)
Global Health & Safety Leader (Hybrid, 8 months)

Scopely • Barcelona

Híbrido
EUR 40.000 - 70.000
Lead IT Security AI-Redteamer
Lead IT Security AI-Redteamer

Dkbcodefactory • España

Presencial
EUR 90.000 - 150.000
Benefits package