Une candidature complète en une minute — CV personnalisé et lettre de motivation, prêts à envoyer.
Enjoy Gaming is looking for an Application Security Engineer to join our team and act as the technical guardian for our games and platforms. If you have an attacker’s mindset but know how to build and defend alongside engineering teams, this role is for you.
You’ll dive into web and desktop applications, hunting vulnerabilities and collaborating with Architects, Studio, Slots, and Platform Developers to engineer more resilient systems.
Enjoy Gaming isasoftware provider focused oncreating high-quality digital entertainment experiences, including Slots and Live Games. Our team brings together experienced professionals ingame development, product, and design, driven byapassion for innovation and quality.
AtEnjoy Gaming, wevalue ownership, excellence, and drive. These principles shape the way wework, collaborate, and build products.
Joinus and bepart ofour innovative journey inthe gaming world!
We’re looking for a sharp Application Security Engineer to join our team and act as the technical guardian for our games and platforms. If you have an attacker's mindset but know how to build and defend alongside engineering teams, this role is for you. In this position, you won’t just be sending reports to the teams or management. You’ll be diving deep into web and desktop applications, hunting down game-level vulnerabilities, and collaborating closely with our Architects, Studio, Slots, and Platform Developers to engineer more resilient systems.
5+ years of Application Security Engineer experience
Background in red teaming, penetration testing, application security, and software development
Able to independently find vulnerabilities in web and desktop applications, triage them, and, where needed, fix them
Solid grounding in data structures, algorithms, and systems architecture designs
Previous security testing experience with Kafka/Redis/BullMQ/PubSub as message/streaming tools
Codes independently, can navigate unfamiliar web application frameworks
Experience using AI tools to aid with vulnerability hunting
Comfortable talking to developers and turning findings into practical, actionable advice
CRTO, OSCP, or OSWE certifications or similar
Knowledge of Cloud Platforms (GCP/AWS)
Understanding of CI/CD pipelines
Hands-on experience with Trivy, Nessus, Acunetix, or Wiz
Experience in iGaming or another regulated industry
Own and maintain our application security pipelines: SCA (Github/Trivy), DAST (Nessus, Acunetix, Wiz), and SAST
Triage findings from these tools and drive them to remediation
Perform penetration tests on new platform features, new internal applications, and new slots and live games
Run basic red team activities, including leaked credential reviews and external attack surface audits
Review complex auth flows with various third parties for cryptographic and security issues
Review/Triage application code for security issues ( 85% NestJS / 15% .NET )
Own security risk in existing code and applications
Act as the application-level security expert during incident response and be ready to deliver hotfixes yourself when needed
Prepare our quarterly SAST/DAST vulnerability scan reports for stakeholders/regulators and take part in audit meetings
Own the Secure Coding and Application Security areas of our ISMS
Meet regularly with development teams, learn about upcoming features early, and advise on secure design
Competitive Salary inEUR: with annual performance reviews torecognize your growth
Flexible Remote Work: balance productivity and comfort
Comprehensive Benefits: including medical insurance, psychologist support, and Polish, Slovak-speaking clubs
Generous Paid Time Off: 20working days ofpaid vacation, plus 10additional paid days off, 10paid sick days, and all national holidays inyour country
Professional Development Support: reimbursement for courses, trainings, and certifications
Well-being Perks: support for language classes, sports, massages, orlife coaching
Please note that feedback onyour application will beprovided within two weeks ifapositive decision ismade regarding your candidacy.