Job Search and Career Advice Platform

Enable job alerts via email!

Senior Application Security Engineer

Rockstar

City of Edinburgh

On-site

GBP 60,000 - 80,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading gaming company seeks a Senior Application Security Engineer in Edinburgh. The role involves identifying security flaws, providing technical guidance, and assessing application security. The ideal candidate has over 5 years of experience, proficiency in C++/C#/JavaScript, and a thorough understanding of software vulnerabilities. Join a collaborative team to enhance security in game development.

Qualifications

  • 5+ years of experience identifying and remediating security bugs/flaws.
  • Proficiency in C++/C#/JavaScript.
  • Knowledge of common software security vulnerabilities.
  • Experience with CI/CD pipelines and shifting security left.
  • Knowledge of web technologies like JSON and RESTful APIs.

Responsibilities

  • Track trends in the security community.
  • Provide technical security guidance.
  • Engage with development teams for security requirements.
  • Develop threat models for applications.
  • Conduct automated and manual security assessments.

Skills

C++
C#
.NET
JavaScript
OWASP Top 10
Penetration testing
Communication

Education

BSc/MSc in Computer Science or related field

Tools

Burp Suite
Metasploit
Wireshark
Job description

At Rockstar Games, we create world-class entertainment experiences.

Become part of a team working on some of the most rewarding, large-scale creative projects to be found in any entertainment medium - all within an inclusive, highly-motivated environment where you can learn and collaborate with some of the most talented people in the industry.

Rockstar is on the lookout for talented Senior Application Security Engineer who possess a passion for diving into complex software designs to identify security flaws and vulnerabilities.

This is a full-time, permanent and in-office position based in Rockstar’s state-of-the-art game development studio in Edinburgh, Scotland.

WHAT WE DO
  • The Rockstar Games Application Security team partners with numerous development teams across the company to incorporate security practices throughout the software development lifecycle.
  • We strive to understand the threat landscape affecting our development studios, the gaming industry, and the world at large to define secure development standards and guidelines to safeguard our business and protect our players.
  • We independently assess our application code and builds through various techniques (static analysis, dynamic analysis, software composition analysis, etc.) to identify potential vulnerabilities and design flaws and work with development teams to remediate.
RESPONSIBILITIES
  • Track trends in the security community and keep abreast of emerging threats.
  • Provide technical security guidance to developers, team leads and producers.
  • Engage development teams to identify security requirements for new products and features while ensuring other requirements don’t introduce an unintended security impact.
  • Develop threat models of new applications and features to systematically understand how they can be attacked in order to prioritize control development.
  • Conduct automated and manual security assessments.
  • Drive remediation efforts behind internally and publicly identified vulnerabilities.
  • Support maintaining Rockstar Games’ public and private bug bounty programs.
REQUIREMENTS
  • 5+ years of experience working in a professional, academic or freelance environment (e.g. bug bounty) identifying and remediating security bugs/flaws.
  • Proficiency in C++/C#/.NET and JavaScript.
  • Extensive knowledge of common software security vulnerabilities (e.g., OWASP Top 10), attack techniques and remediation tactics/strategies.
  • Experience working in or establishing secure CI/CD pipelines and the concept of shifting security left in the SDLC.
  • Working knowledge of the principles and techniques for both manual and automated application security assessments.
  • Understanding of a variety of web technologies including: JSON, WebSockets, HTTP/2, DNS, RESTful APIs.
  • Experience in results-oriented, retail driven environment with strict deadlines and ship dates.
  • Strong written and verbal communication skills.
PLUSES

Please note that these are desirable skills and are not required to apply for the position.

  • Experience with scripting and process automation.
  • An understanding of effective practices for securing the SDLC that considers developer experience, sustainability and compliments release velocity.
  • Experience with penetration testing and offensive security tools and techniques, e.g., Burp Suite, Metasploit, Wireshark.
  • Industry certifications preferred (CISSP, GSEC, OSCP, CEH, etc.).
  • BSc/MSc in a computer science or related field.
HOW TO APPLY

Please apply with a CV and cover letter demonstrating how you meet the skills above. If we would like to move forward with your application, a Rockstar recruiter will reach out to you to explain next steps and guide you through the process.

Rockstar is committed to creating a work environment that promotes equal opportunity, dignity and respect. In line with this commitment, Rockstar will provide reasonable accommodations to qualified job applicants with disabilities during the recruitment process in order for such applicants to be considered for the position for which they are applying, as well as to qualified employees to enable them to perform the essential functions of their roles. If you need more information about Rockstar’s reasonable accommodation policies or process, or need to request an accommodation, please contact the Human Resources Department.

If you’ve got the right skills for the job, we want to hear from you. We encourage applications from all suitable candidates regardless of age, disability, gender identity, sexual orientation, religion, belief, race, or any other protected category.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.