Security Engineer (Application Security)

GameChanger

United States

Remote

USD 120,000 - 190,000

Full time

12 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Unlimited vacation
Remote work
Health insurance
401K
Tech budget
Continued learning
Parental leave
Wellness
Other perks

Job summary

GameChanger is seeking a Security Engineer to join the InfoSec team as the primary security partner for our software engineering organization. You will embed security across the SDLC, champion secure design, and bring DevSecOps discipline to how we build and ship software, including being part of our weekly on-call rotation.

You will collaborate with platform, product, and architecture teams to define secure API patterns, perform secure code reviews, integrate security tooling into CI/CD, and

Qualifications

  • 3+ years in application security engineering.
  • Security-by-design in TypeScript, Swift, and/or Kotlin.
  • Experience securing deployments in AWS with container and Kubernetes security, IaC scanning, and policy-as-code.
  • Proven track record integrating security tooling into CI/CD pipelines.
  • Ability to use AI/ML-driven security tools to enhance effectiveness.

Responsibilities

  • Embed security into every phase of the SDLC.
  • Champion secure design and DevSecOps practices.
  • Perform secure code reviews with actionable remediation guidance.
  • Define secure API patterns (REST and GraphQL).
  • Maintain secure coding guidelines and security architectural patterns.
  • Integrate and maintain security tooling across CI/CD and enforce security gates.
  • Harden CI/CD components such as GitHub Actions and runners.
  • Identify opportunities to leverage AI for security workflows.
  • Operate vulnerability management lifecycle and triage findings by impact.
  • Communicate security risk clearly to engineering and leadership.

Skills

Security-by-design
CI/CD security tooling
Threat modeling
AI/ML security tooling
Clear communication
Automation-first
Cross-functional collaboration

Education

AWS Certified Security Specialty
CKS / GMOB / GWEB

Tools

AWS
Kubernetes
Terraform
Policy-as-code

Job description

  • We’re looking for a Security Engineer to join our InfoSec team and become the primary security partner for our software engineering organization
  • Reporting to the Security Engineering Manager, you’ll operate application security across the SDLC, champion secure design and development practices, and bring DevSecOps discipline to how we build and ship software
  • This is a high-impact, highly collaborative role. You’ll work closely with platform and product engineers to make security a part of how we build and deliver. You will also be a member of our weekly on-call rotation
  • Embed security into every phase of the SDLC
  • Champion security requirements for the responsible and secure integration of Gen AI and agentic AI tools within our product stack
  • Conduct security-by-design engagements for new features, APIs, platform initiatives, and infrastructure changes
  • Perform secure code reviews providing engineers with clear, actionable findings and remediation guidance
  • Partner with architecture and platform teams to establish secure API patterns (REST and GraphQL)
  • Contribute to and maintain secure coding guidelines, API security standards, and security architectural patterns that serve as the “paved roads” for all engineering teams
  • Give useful code review feedback, write documentation that outlasts the ticket, and run the occasional workshop or lunch-and-learn for engineers
  • Integrate and maintain security tooling across CI/CD pipelines
  • Enforce security quality gates in delivery pipelines
  • Harden the CI/CD platform components, including configuration and hardening of GitHub Actions and runner environments
  • Identify opportunities to leverage AI for increasing engineering productivity and agentic security workflows
  • Work alongside DevOps engineers to ensure cloud infrastructure is defined and deployed securely via IaC (terraform, k8s)
  • Implement and validate security controls for containerized workloads
  • Support the implementation of application-layer network security controls, such as Web Application Firewalls (WAFs) and CDN security, to protect application endpoints
  • Operate the application vulnerability management lifecycle
  • Triage and prioritize findings from our sources (including; GHAS, NowSecure, Wiz, BugCrowd, penetration tests) by business impact and exploitability
  • Proactively identify systemic risks and facilitate cross-functional initiatives to address root causes
  • Track security-specific KPIs (e.g., MTTR, vulnerability density, and security coverage of CI/CD pipelines) and translate them into actionable insights for engineering and business leadership
  • Effectively communicate security risk clearly to both engineering and business leaders
Benefits
  • Unlimited Vacation - Take time off work and travel the world. Enjoy unlimited vacation time.
  • Remote Work - GameChanger’s can work from anywhere. You’ll receive a tech budget to make sure you’re set up for success.
  • Health Insurance - We’ll make sure you stay healthy. Health, dental, vision, and other perks like a pre-tax FSA - we’ve got you covered.
  • 401K Plan - We’re always looking ahead and so should you. Did we mention that we match?
  • Tech Budget - You receive a large tech budget every two years. It’s yours to keep.
  • Continued Learning - Tuition reimbursement, an annual flexible learning budget, mentorship opportunities, and more.
  • Parental Leave - Get the time off you need with extended parental leave for both parents.
  • Wellness - Stay fit and healthy on us. We offer a Gympass membership.
  • Other Perks - Monthly Snack Boxes, Dick’s Sporting Goods employee discount, Demo Day, Hack Day, virtual and in person team social events
Requirements
  • Demonstrated expertise in security-by-design in TypeScript, Swift, and/or Kotlin
  • Proven experience building and operating internal security developer platforms or tooling that reduces developer friction
  • Track record of implementing secure primitives in mobile ecosystems (iOS/Android)
  • Working knowledge of OWASP Top 10s (web, mobile, API, LLM)
  • 3+ years in application security engineering
  • Proven track record integrating security tooling into CI/CD pipelines
  • Hands-on experience securing deployments in AWS with container and Kubernetes security, IaC scanning, and policy-as-code approaches
  • Demonstrated ability to use AI/ML-driven tools to enhance security effectiveness and scalability
  • Beneficial certifications: AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent
  • Hands-on experience leading threat modeling engagements and designing paved roads
  • Pragmatic defender. You understand that security must enable the business, not block it.
  • You look for “secure by default” solutions and know how to make the right path the easy path for engineers
  • Clear communicator. You can trace a BOLA vulnerability chain to a frontend engineer and translate the same risk into business terms for a VP; and you know which conversation you’re in
  • Automation-first. If you have to do it twice, you’d rather write the script
  • Long-view oriented. You think about medium-to-long-term system health, not just the current sprint, and you proactively address root causes rather than patching symptoms repeatedly
  • Approachable. You foster open dialogue, encourage diverse perspectives, and make it easy for engineers to surface security concerns without fear of judgment or friction
  • Collaborative and cross-functional. You bring product, business, and operational context into your security decisions, not just security best practices in isolation
  • Force multiplier. You don’t solve every security problem yourself. You coach, document, and build systems that make the engineers around you more secure by default
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Staff DevSecOps Engineer
Staff DevSecOps Engineer

Red Ventures • United States

Hybrid
USD 180,000 - 240,000
Hybrid Schedule
Flexible PTO
Mentorship Culture
+2
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Security Engineer - Member of Technical Staff
Security Engineer - Member of Technical Staff

Simile • San Francisco (CA)

On-site
USD 200,000 - 400,000
Equity grants
Comprehensive medical, dental, and vision coverage
Flexible time off policies
Security Engineer
Security Engineer

AegisAI, Inc. • United States

Remote
USD 120,000 - 180,000
Security Engineer (Full Stack)
Security Engineer (Full Stack)

Hadrian • San Francisco (CA)

On-site
USD 180,000 - 225,000
Relocation stipend
Platinum medical, dental, vision, and
401k
+1
Senior Security Engineer
Senior Security Engineer

Foundation Capital • Phoenix (AZ)

On-site
USD 130,000 - 190,000
Senior Security Engineer (Infrastructure)
Senior Security Engineer (Infrastructure)

Chainguard • New York (NY)

Remote
USD 180,000 - 230,000
Equity/stock options
Unlimited PTO
Remote work with flexible coworking
+2
Senior Security Engineer (Infrastructure)
Senior Security Engineer (Infrastructure)

Chainguard, Inc. • Northern (KY)

On-site
USD 137,000 - 160,000
Flexible & Remote-First Culture
Equity stock options with 10 years to
100% Covered Health Insurance
+2
Backend Engineer (Security)
Backend Engineer (Security)

Remote Worker LTD. • United States

Remote
USD 140,000 - 210,000
Compensation & equity
Async work
Home office setup
+3