Security Engineer, Application Security

GameChanger

United States

Remote

USD 110,000 - 170,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote US work
Unlimited vacation
Tech stipend
WFH stipend
Health benefits
Parental leave
Wellness stipend
DICK'S Sporting Goods discount

Job summary

GameChanger is seeking a Security Engineer to partner with our software engineering organization and lead application security across the SDLC. You will champion secure design, drive DevSecOps across CI/CD, and work with platform teams to implement secure API patterns and tooling.

You will operate vulnerability management, track security KPIs, and translate findings into actionable leadership insights. This is a remote-first role with benefits, reporting to Security Engineering Manager.

Qualifications

  • 3+ years in application security engineering.
  • Experience building internal security developer platforms.
  • Experience securing AWS deployments with container/Kubernetes security and IaC scanning.

Responsibilities

  • Embed security into every phase of the SDLC.
  • Conduct secure reviews for features, APIs, and infrastructure.
  • Lead threat modeling and pave roads for secure development.
  • Manage security tooling across CI/CD and IaC pipelines.
  • Collaborate with DevOps for secure cloud deployments and WAF/CDN controls.
  • Communicate risk to engineering and leadership.

Skills

AppSec engineering
Threat modeling
CI/CD tooling
AWS security
Kubernetes security
Security by design
AI/ML security tooling

Tools

GitHub Actions
Terraform
Kubernetes
NowSecure

Job description

About GameChanger:

We believe in the life changing impact youth sports have on and off the field. Sports encourage leadership, teamwork, responsibility, and confidence – important life lessons that have the power to propel our youth toward meaningful futures. We recognize that without coaches, parents, and volunteers, organized youth sports could not exist. By building the first and best place to experience the youth sports moments important to our community, we are helping families elevate the next generation through youth sports. So if you love sports and their community building potential, or building cool products is your sport, GameChanger is the team for you. We are a remote first, dynamic tech company based in New York City, and we are solving some of the biggest challenges in youth sports today.

The Position:

We’re looking for a Security Engineer to join our InfoSec team and become the primary security partner for our software engineering organization. Reporting to the Security Engineering Manager, you’ll operate application security across the SDLC, champion secure design and development practices, and bring DevSecOps discipline to how we build and ship software. This is a high-impact, highly collaborative role. You’ll work closely with platform and product engineers to make security a part of how we build and deliver. You will also be a member of our weekly on-call rotation.

What You’ll Do:
Application security
  • Embed security into every phase of the SDLC
  • Champion security requirements for the responsible and secure integration of Gen AI and agentic AI tools within our product stack
  • Conduct security-by-design engagements for new features, APIs, platform initiatives, and infrastructure changes
  • Perform secure code reviews providing engineers with clear, actionable findings and remediation guidance
  • Partner with architecture and platform teams to establish secure API patterns (REST and GraphQL)
  • Contribute to and maintain secure coding guidelines, API security standards, and security architectural patterns that serve as the “paved roads” for all engineering teams
  • Give useful code review feedback, write documentation that outlasts the ticket, and run the occasional workshop or lunch-and-learn for engineers
DevSecOps
  • Integrate and maintain security tooling across CI/CD pipelines
  • Enforce security quality gates in delivery pipelines
  • Harden the CI/CD platform components, including configuration and hardening of GitHub Actions and runner environments
  • Identify opportunities to leverage AI for increasing engineering productivity and agentic security workflows
  • Work alongside DevOps engineers to ensure cloud infrastructure is defined and deployed securely via IaC (terraform, k8s)
  • Implement and validate security controls for containerized workloads
  • Support the implementation of application-layer network security controls, such as Web Application Firewalls (WAFs) and CDN security, to protect application endpoints
Vulnerability & Risk Management
  • Operate the application vulnerability management lifecycle
  • Triage and prioritize findings from our sources (including; GHAS, NowSecure, Wiz, BugCrowd, penetration tests) by business impact and exploitability
  • Proactively identify systemic risks and facilitate cross-functional initiatives to address root causes
  • Track security-specific KPIs (e.g., MTTR, vulnerability density, and security coverage of CI/CD pipelines) and translate them into actionable insights for engineering and business leadership
  • Effectively communicate security risk clearly to both engineering and business leaders
What You’ll Bring:
  • 3+ years in application security engineering
  • Proven experience building and operating internal security developer platforms or tooling that reduces developer friction
  • Demonstrated ability to use AI/ML-driven tools to enhance security effectiveness and scalability
  • Hands-on experience leading threat modeling engagements and designing paved roads
  • Proven track record integrating security tooling into CI/CD pipelines
  • Working knowledge of OWASP Top 10s (web, mobile, API, LLM)
  • Hands-on experience securing deployments in AWS with container and Kubernetes security, IaC scanning, and policy-as-code approaches
  • Demonstrated expertise in security-by-design in TypeScript, Swift, and/or Kotlin
  • Track record of implementing secure primitives in mobile ecosystems (iOS/Android)
  • Beneficial certifications: AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent.
Who You Are:
  • Pragmatic defender. You understand that security must enable the business, not block it. You look for “secure by default” solutions and know how to make the right path the easy path for engineers.
  • Force multiplier. You don’t solve every security problem yourself. You coach, document, and build systems that make the engineers around you more secure by default.
  • Clear communicator. You can trace a BOLA vulnerability chain to a frontend engineer and translate the same risk into business terms for a VP; and you know which conversation you’re in.
  • Automation-first. If you have to do it twice, you’d rather write the script.
  • Long-view oriented. You think about medium-to-long-term system health, not just the current sprint, and you proactively address root causes rather than patching symptoms repeatedly.
  • Collaborative and cross-functional. You bring product, business, and operational context into your security decisions, not just security best practices in isolation.
  • Approachable. You foster open dialogue, encourage diverse perspectives, and make it easy for engineers to surface security concerns without fear of judgment or friction.
Perks:
  • Work remotely throughout the US* or from our well-furnished, modern office in Manhattan, NY.
  • Unlimited vacation policy.
  • Paid volunteer opportunities.
  • Technology stipend - $4,000 every 2 years after your start to make sure you have the latest and greatest technology.
  • WFH stipend - $500 annually to make your WFH situation comfortable.
  • Monthly physical, mental, wellness & learning stipend offered through Holisticly.
  • Monthly lifestyle stipend offered through Fringe.
  • Full health benefits - medical, dental, vision, prescription, FSA, HRA, HSA, and coverage for family/dependents.
  • Retirement savings - Traditional and Roth 401K plans are offered through Vanguard, with an immediate company match.
  • Life insurance - basic life, supplemental life, and dependent life.
  • Disability leave - short-term disability and long-term disability.
  • Company paid parental leave - up to 20 weeks for birthing parents and up to 12 weeks for non-birthing parents.
  • Family building benefits offered through Progyny.
  • DICK'S Sporting Goods and their family of brands teammate discount.

* DICK'S Sporting Goods has company-wide practices to monitor and protect the company from significant compliance and monetary implications as it pertains to employer state tax liabilities. Due to said guidelines put in place, we are unable to hire in AK, DE, HI, IA, LA, MS, MT, OK, and SC.

We are an equal opportunity employer and value diversity in our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

IMPORTANT NOTICE:

All official recruitment communications from GameChanger will come from an email address ending in @gc.com or no-reply@ashby.hq.com. If you receive communication from any other domain, please be cautious, as it is likely fraudulent.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Application Security
Security Engineer, Application Security

Far Coder • Northern (KY)

Hybrid
USD 120,000 - 140,000
Remote US
Office in Manhattan
Unlimited vacation
+7
Senior Product Designer, Studio Team
Senior Product Designer, Studio Team

Socket.dev • United States

Remote
USD 140,000 - 160,000
Remote work throughout the US
Unlimited vacation
Health benefits
+6
Senior Engineering Manager, Video Enablement
Senior Engineering Manager, Video Enablement

Far Coder • Northern (KY)

Hybrid
USD 209,000 - 235,000
Unlimited vacation
Paid volunteer opportunities
Technology stipend
+3
Senior Engineering Manager, Video Enablement
Senior Engineering Manager, Video Enablement

GC • Northern (KY)

Hybrid
USD 209,000 - 235,000
Remote work throughout the US
Unlimited vacation
Technology stipend
+5
Senior Engineering Manager, Video Enablement
Senior Engineering Manager, Video Enablement

Youth Sports Business Report Co. • Northern (KY)

Hybrid
USD 209,000 - 235,000
Remote work across US
Unlimited vacation
Volunteer opportunities
+12
Senior Backend Software Engineer, Subscriptions Enablement
Senior Backend Software Engineer, Subscriptions Enablement

Socket.dev • United States

Remote
USD 140,000 - 155,000
Remote work
Unlimited vacation
Technology stipend
+6
Staff Software Engineer, Video Enablement
Staff Software Engineer, Video Enablement

GameChanger • United States

Remote
USD 200,000 - 230,000
Unlimited vacation policy
Technology stipend
Full health benefits
+1
Engineering Manager, Platform Security
Engineering Manager, Platform Security

United States Digital Space LLC • San Francisco (CA)

On-site
USD 248,000 - 310,000
Equity
Benefits
Security Engineer New United States - Remote
Security Engineer New United States - Remote

Chainguard • United States

Remote
USD 105,000 - 123,000
Flexible & Remote-First
Stock options
Health insurance
+2
Senior Security Engineer (Cloud) United States - Remote
Senior Security Engineer (Cloud) United States - Remote

Chainguard • United States

Remote
USD 137,000 - 160,000
Flexible & Remote-First Culture
Stock options on hire and promotion
100% Covered Health Insurance
+2