Senior Application Security Platform Engineer

Rockstar Games
New York, NY, United States
about 2 months ago
Apply on www.jobmonkeyjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$121,400.0 - $166,700.0
Working hours
Regular working hours

Tech stack

Microsoft Windows C Sharp (Programming Language) C++ (Programming Language) Static Program Analysis Continuous Integration Linux Github Information Systems Security Architecture Professional Python (Programming Language) Open Web Application Security Web Application Security Software Engineering
+9 more
Policy as Code Diagnostic Tools Pulumi Delivery Pipeline Software Security Kubernetes Teamcity Terraform Static Application Security Testing

Job description

  • Architect and support secure software development lifecycle operations embedded in software development pipelines.
  • Provide technical security guidance to developers, team leads, and producers.
  • Drive remediation efforts behind internally and publicly identified vulnerabilities.

Requirements

  • 5+ years of experience working in a professional, academic or research environment identifying and remediating security bugs/flaws, assisted by automated pipelines.
  • Knowledge of common web security vulnerabilities (e.g., OWASP Top 10), client-side security landscape, attack techniques and remediation tactics/strategies.
  • Experience implementing and tuning SAST, SCA, IaC and Secrets Detection tools effectively, especially fine-tuning static analysis detections with custom rule engines (CodeQL, Semgrep).
  • Expertise deploying within CI/CD platforms (TeamCity or GitHub Actions) and container orchestration frameworks (e.g. Kubernetes), including establishing appropriate security controls in them
  • Experience in establishing monitoring and observability techniques of build pipelines and their outputs.
  • Experience with both Windows and Linux operating systems.
  • Proficiency in C#, Python., * Hands-on experience building or deploying security agents using frameworks likeLangChain or LangGraph to automate complex multi-step security tasks.
  • Familiarity with using Infrastructure as Code languages (Terraform, Pulumi) to deploy secure architecture.
  • Experience enforcing security guardrails with Policy as Code (e.g. OPA) engines to existing and new CI/CD workflows.
  • Understanding of C++ and associated compilers.
  • Experience in establishing CI/CD controls for cloud-native pipelines and runtime environments.

Benefits & conditions

Subject to those same considerations, the total compensation package for this position may also include other elements, including a bonus and/or equity awards, in addition to a full range of medical, financial, and/or other benefits. Details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an “at-will position” and the company reserves the right to modify base salary (as well as any other discretionary payment or compensation or benefit program) at any time, including for reasons related to individual performance, company or individual department/team performance, and market factors.

*NY Base Pay Range

$121,400-$166,700 USD

About the company

At Rockstar Games, we create world-class entertainment experiences.

Become part of a team working on some of the most rewarding, large-scale creative projects to be found in any entertainment medium - all within an inclusive, highly-motivated environment where you can learn and collaborate with some of the most talented people in the industry.

Rockstar is on the lookout for a passionate Senior Security Platform Engineer who is skilled at diving into complex software designs to identify security flaws and vulnerabilities.

This is a full-time, in-office position based out of Rockstar’s NYC headquarters in Downtown Manhattan., * The Rockstar Games Application Security team partners with numerous development teams across the company to incorporate security practices throughout the software development lifecycle.

  • We strive to understand the threat landscape affecting our development studios, the gaming industry, and the world at large to define secure development standards and guidelines to safeguard our business and protect our players.
  • We independently assess our application code and builds through various techniques (static analysis, dynamic analysis, software composition analysis, etc.) to identify potential vulnerabilities and design flaws and work with development teams to remediate.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobmonkeyjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:55 min

Contrasting Terraform with Pulumi and cloud-specific tools

Devlin Duldulao · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:20 min

Overview of infrastructure as code tools

Alexander Bubeck · World Congress 2023

Videos

See all

Related articles

See all