> Markdown version of [/jobs/ext/1952832-principal-ai-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/1952832-principal-ai-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Ai Product Security Engineer - **Company:** Scopely - **Location:** Barcelona, Spain - **Contract:** Franchise - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software Applications, Software System Penetration Testing, JIRA, Bioinformatics, C Sharp (Programming Language), Cloud Computing, Static Program Analysis, Cyber Security, Databases, Continuous Integration, Linux, Video Game Development, Identity and Access Management, Mobile Application Software, Information Systems Security Architecture Professional, Python (Programming Language), Network Security, Open Web Application Security, Software Product Management, Cloud Services, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Data Processing, Large Language Models, Software Security, Backend, Vulnerability Analysis, Programming Languages - **Published:** August 6, 2026 - **Apply:** https://www.buscojobs.com.es/principal-ai-product-security-engineer-en-barcelona-ID-366165992 ## About the Role 8+ years of experience in Product Security, software development, or cybersecurity Proven track record in securing large-scale software applications and systems Strong experience building automation and security tooling Hands?on experience applying AI/LLMs to operational workflows, including designing, evaluating, and safely deploying AI?assisted systems is highly desirable Ability to effectively communicate business risk and technical information clearly to both technical and non-technical audiences Technical Expertise Expertise in modern programming languages such as Python and C# Strong understanding of: Application and product security Vulnerability management and pentesting methodologies API and backend security Experience with mobile application penetration testing, including traffic interception, runtime analysis and API security. Experience with modern development ecosystems, CI/CD pipelines, APIs, and developer platforms. Strong, hands?on experience with cloud computing environments including: AWS shared responsibility model IAM and access control Network security in the cloud Strong understanding of securing cloud workloads including configuration, deployment, and auditing Deep knowledge of Linux security practices Additional Strengths Demonstrated ability to think like both an attacker and defender Experience architecting for and managing high?scale, high?velocity workloads in AWS preferred Familiarity with security frameworks (e.G., OWASP, NIST Cybersecurity Framework) and compliance regulations (e.G., GDPR, CCPA, ISO *****) Excellent analytical, problem?solving, and decision?making skills Exceptional communication and leadership skills, with the ability to influence across teams Bonus Points Experience applying AI to security, automation, or developer workflows Previous experience at a game company Familiarity with: RAG architectures Vector databases (e.G., pgvector) AI?assisted code analysis or pentesting Please ensure that the résumé/CV you attach is written in English. ## Description Scopely is looking for a Principal Security Engineer to join our Information Security team in Spain/Portugal on a hybrid basis.Our security team is dedicated to ensuring the security of our top games. This involves collaborating closely with game studios to develop and implement comprehensive security strategies throughout the game design and development lifecycle.In addition, this role will drive the application of AI to transform how security is delivered across Product Security, Security Operations, and Security Engineering, improving efficiency, scalability, and impact.What You Will DoGame & Product Security LeadershipPartner with game studios to develop comprehensive security strategies for game design and developmentConduct threat modeling, vulnerability assessments, and security audits across all phases of game developmentDesign and implement security controls and countermeasures to mitigate risks and ensure compliance with company policies, standards, and industry normsCollaborate with game teams to advocate for secure coding practices and integrate security at every level of the software development lifecycleCoordinate and participate in penetration tests and game feature security assessmentsProvide expert-level technical guidance to game teams to assist in securing games and backend infrastructureTranslate business priorities, technical constraints, and threat intelligence into actionable security roadmapsAI-Driven Security Transformation & AutomationIdentify and implement opportunities to apply AI to:Vulnerability triage, prioritization, and remediationSecurity operations workflows (alert analysis, investigation, response)Product security processes (code analysis, findings analysis, pentesting support)Build AI-driven workflows, tools, and agents to reduce manual effort and improve speed and accuracyUse AI to improve vulnerability management through triage support, risk classification, remediation guidance, and findings analysisPartner with Security Operations to improve detection, triage,investigation and response through automation and AI-assisted analysisIntegrate AI capabilities into existing security platforms (e.G., Wiz, SIEM, Jira, IAM systems)Develop reusable AI-enabled components that scale across teams and studiosEstablish practical guardrails for the safe and effective use of AI in security, including data handling, quality control, and human reviewDefine success metrics for AI-enabled workflows, including productivity gains, response times, remediation throughput, and signal qualitySecurity Engineering & Platform EnablementDesign and implement scalable security solutions across cloud and backend systemsWork closely with information security domain owners to ensure games adhere to all relevant security policies, standards, and regulatory requirementsDevelop and maintain comprehensive documentation on security architectures, processes, and decisions for technical and non-technical stakeholdersImprove security engineering efficiency through automation and toolingStay updated with the latest security technologies, trends, threats, and AI capabilities, continuously improving security practicesStakeholder Engagement & LeadershipFrequently interact with game studio leaders to understand their roadmaps, risk posture, and how information security can enable them to execute their vision securelyDevelop security-related roadmaps in partnership with game teamsRegularly report to Information Security and Studio management on the threat landscape and security posture of gamesAct as a thought leader using both qualitative and quantitative risk assessment frameworksLead and/or assist in security incidents and investigationsWhat We're Looking For8+ years of experience in Product Security, software development, or cybersecurityProven track record in securing large-scale software applications and systemsStrong experience building automation and security toolingHands?on experience applying AI/LLMs to operational workflows, including designing, evaluating, and safely deploying AI?assisted systems is highly desirableAbility to effectively communicate business risk and technical information clearly to both technical and non-technical audiencesTechnical ExpertiseExpertise in modern programming languages such as Python and C#Strong understanding of:Application and product securityVulnerability management and pentesting methodologiesAPI and backend securityExperience with mobile application penetration testing, including traffic interception, runtime analysis and API security.Experience with modern development ecosystems, CI/CD pipelines, APIs, and developer platforms.Strong, hands?on experience with cloud computing environments including:AWS shared responsibility modelIAM and access controlNetwork security in the cloudStrong understanding of securing cloud workloads including configuration, deployment, and auditingDeep knowledge of Linux security practicesAdditional StrengthsDemonstrated ability to think like both an attacker and defenderExperience architecting for and managing high?scale, high?velocity workloads in AWS preferredFamiliarity with security frameworks (e.G., OWASP, NIST Cybersecurity Framework) and compliance regulations (e.G., GDPR, CCPA, ISO *****)Excellent analytical, problem?solving, and decision?making skillsExceptional communication and leadership skills, with the ability to influence across teamsBonus PointsExperience applying AI to security, automation, or developer workflowsPrevious experience at a game companyFamiliarity with:RAG architecturesVector databases (e.G., pgvector)AI?assisted code analysis or pentestingPlease ensure that the résumé/CV you attach is written in English.About ScopelyScopely is a leading video game and global interactive entertainment company, home to many of the world's most beloved and enduring experiences, including two of the most successful mobile games of all-time "MONOPOLY GO!" and "Pokémon GO," along with "Stumble Guys," "Star TrekTM Fleet Command," "MARVEL Strike Force," "WWE Champions," the Scrabble franchise, "Yahtzee With Buddies," and many others. Across mobile, web, PC, and console, Scopely creates, develops, publishes, and live?operates one of the most diversified and award?winning portfolios in the games industry - bringing hundreds of millions of players together through a shared love of play.Founded in ****, Scopely is powered by its exceptional team - including thousands of world?class gamemakers around the globe, a distinctive tenet?driven culture, and its proprietary technology platform, Playgami. Together, these strengths have fueled Scopely's position as the #1 mobile games company in the U.S. and #2 globally, generating more than $10 billion in lifetime revenue. Whether building global sensations like "MONOPOLY GO!" from the ground up, or expanding through strategic acquisitions, including the FoxNext, GSN, and Scopely Explore games businesses - Scopely consistently delivers experiences players love today and return to for years to come.Recognized multiple times as one of the "100 Most Influential Companies in the World" by TIME magazine and one of Fast Company's "World's Most Innovative Companies" and "Best Workplaces for Innovators," Scopely believes that video games can be a force for good - creating meaningful connections, vibrant communities, and making life better through play.Scopely has global operations and partners across four continents in more than a dozen countries worldwide. For more information, visit:Notice to Candidates: Scopely will never request payment or financial information during the application or hiring process. Please apply only through our official website and verify that all Talent Partner communications come from an email address ending in @scopely.Com.Should you have any questions or encounter any fraudulent requests/emails/websites, please immediately contact ******. Our job applicant privacy policies are available here: California Privacy Notice and EEA/UK Privacy Notice.Employment at Scopely is based solely on a person's merit and qualifications. Scopely does not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), or any other basis protected by law. We also consider qualified applicants with arrest or conviction records, consistent with applicable federal, state and local law.#J-*****-Ljbffr ## Related Videos - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)