Security Engineer, Application Security

GAMECHANGER PARTNERS, LLC
New York, NY, United States
8 days ago
Apply on jobs.ashbyhq.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$120,000.0 - $140,000.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Application Firewall Software System Penetration Testing Architectural Patterns Computer Vision Cloud Computing Code Review Continuous Integration DevOps
+19 more
Github Network Security Machine Learning Open Web Application Security Secure Coding TypeScript Policy as Code Delivery Pipeline Large Language Models Software Security Mttr Kotlin Containerization Kubernetes Build Tools Graphql Front End Software Development Terraform Devsecops

Job description

We’re looking for a Security Engineer to join our InfoSec team and become the primary security partner for our software engineering organization. Reporting to the Security Engineering Manager, you’ll operate application security across the SDLC, champion secure design and development practices, and bring DevSecOps discipline to how we build and ship software. This is a high-impact, highly collaborative role. You’ll work closely with platform and product engineers to make security a part of how we build and deliver. You will also be a member of our weekly on-call rotation., * Champion security requirements for the responsible and secure integration of Gen AI and agentic AI tools within our product stack

  • Conduct security-by-design engagements for new features, APIs, platform initiatives, and infrastructure changes
  • Perform secure code reviews providing engineers with clear, actionable findings and remediation guidance
  • Partner with architecture and platform teams to establish secure API patterns (REST and GraphQL)
  • Contribute to and maintain secure coding guidelines, API security standards, and security architectural patterns that serve as the “paved roads” for all engineering teams
  • Give useful code review feedback, write documentation that outlasts the ticket, and run the occasional workshop or lunch-and-learn for engineers

DevSecOps

  • Integrate and maintain security tooling across CI/CD pipelines
  • Enforce security quality gates in delivery pipelines
  • Harden the CI/CD platform components, including configuration and hardening of GitHub Actions and runner environments
  • Identify opportunities to leverage AI for increasing engineering productivity and agentic security workflows
  • Work alongside DevOps engineers to ensure cloud infrastructure is defined and deployed securely via IaC (terraform, k8s)
  • Implement and validate security controls for containerized workloads
  • Support the implementation of application-layer network security controls, such as Web Application Firewalls (WAFs) and CDN security, to protect application endpoints

Vulnerability & Risk Management

  • Operate the application vulnerability management lifecycle
  • Triage and prioritize findings from our sources (including; GHAS, NowSecure, Wiz, BugCrowd, penetration tests) by business impact and exploitability
  • Proactively identify systemic risks and facilitate cross-functional initiatives to address root causes
  • Track security-specific KPIs (e.g., MTTR, vulnerability density, and security coverage of CI/CD pipelines) and translate them into actionable insights for engineering and business leadership
  • Effectively communicate security risk clearly to both engineering and business leaders, * Pragmatic defender. You understand that security must enable the business, not block it. You look for “secure by default” solutions and know how to make the right path the easy path for engineers.
  • Force multiplier. You don’t solve every security problem yourself. You coach, document, and build systems that make the engineers around you more secure by default.
  • Clear communicator. You can trace a BOLA vulnerability chain to a frontend engineer and translate the same risk into business terms for a VP; and you know which conversation you’re in.
  • Automation-first. If you have to do it twice, you’d rather write the script.
  • Long-view oriented. You think about medium-to-long-term system health, not just the current sprint, and you proactively address root causes rather than patching symptoms repeatedly.
  • Collaborative and cross-functional. You bring product, business, and operational context into your security decisions, not just security best practices in isolation.
  • Approachable. You foster open dialogue, encourage diverse perspectives, and make it easy for engineers to surface security concerns without fear of judgment or friction., * DICK’S Sporting Goods has company-wide practices to monitor and protect the company from significant compliance and monetary implications as it pertains to employer state tax liabilities. Due to said guidelines put in place, we are unable to hire in AK, DE, HI, IA, LA, MS, MT, OK, and SC., Maintain and improve GameChanger’s backend API server and SDK. Implement API/SDK changes, improve developer ergonomics, optimize performance and scalability, design critical systems, document and mentor teammates, and participate in on-call rotation.

Requirements

  • 3+ years in application security engineering
  • Proven experience building and operating internal security developer platforms or tooling that reduces developer friction
  • Demonstrated ability to use AI/ML-driven tools to enhance security effectiveness and scalability
  • Hands-on experience leading threat modeling engagements and designing paved roads
  • Proven track record integrating security tooling into CI/CD pipelines
  • Working knowledge of OWASP Top 10s (web, mobile, API, LLM)
  • Hands-on experience securing deployments in AWS with container and Kubernetes security, IaC scanning, and policy-as-code approaches
  • Demonstrated expertise in security-by-design in TypeScript, Swift, and/or Kotlin
  • Track record of implementing secure primitives in mobile ecosystems (iOS/Android)
  • Beneficial certifications: AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent.

Benefits & conditions

Operate application security across the SDLC, including secure design, code reviews, threat modeling, API security, DevSecOps tooling, CI/CD security gates, cloud and container security, vulnerability management, and risk communication. Partner with engineering teams on secure coding standards, AWS, Kubernetes, Terraform, mobile ecosystems, and responsible AI integration. Participate in an on-call rotation and develop scalable security platforms, paved roads, documentation, and developer training. The summary above was generated by AI About GameChanger:

We believe in the life changing impact youth sports have on and off the field. Sports encourage leadership, teamwork, responsibility, and confidence - important life lessons that have the power to propel our youth toward meaningful futures. We recognize that without coaches, parents, and volunteers, organized youth sports could not exist. By building the first and best place to experience the youth sports moments important to our community, we are helping families elevate the next generation through youth sports.

So if you love sports and their community building potential, or building cool products is your sport, GameChanger is the team for you. We are a remote first, dynamic tech company based in New York City, and we are solving some of the biggest challenges in youth sports today., * Work remotely throughout the US* or from our well-furnished, modern office in Manhattan, NY.

  • Unlimited vacation policy.
  • Paid volunteer opportunities.
  • Technology stipend - $4,000 every 2 years after your start to make sure you have the latest and greatest technology.
  • WFH stipend - $500 annually to make your WFH situation comfortable.
  • Monthly physical, mental, wellness & learning stipend offered through Holisticly.
  • Monthly lifestyle stipend offered through Fringe.
  • Full health benefits - medical, dental, vision, prescription, FSA, HRA, HSA, and coverage for family/dependents.
  • Retirement savings - Traditional and Roth 401K plans are offered through Vanguard, with an immediate company match.
  • Life insurance - basic life, supplemental life, and dependent life.
  • Disability leave - short-term disability and long-term disability.
  • Company paid parental leave - up to 20 weeks for birthing parents and up to 12 weeks for non-birthing parents.
  • Family building benefits offered through Progyny.
  • DICK’S Sporting Goods and their family of brands teammate discount.

The target salary range for this position is between $120,000 and $140,000. This is part of a total compensation package that includes incentive, equity, and benefits for eligible roles. Individual pay may vary from the target range and is determined by several factors including experience, internal pay equity, and other relevant business considerations. We constantly review all teammate pay to ensure a great compensation package that is fair and equal across the board., Remote United States 140K-170K Annually Senior level 140K-170K Annually Senior level Computer Vision * Digital Media * Kids + Family * Mobile * Software * Sports Own and evolve the Subscriptions and Payments backend: design APIs, integrate providers, improve reliability and scalability, lead architecture and code reviews, collaborate cross-functionally, and participate in on-call rotations. Top Skills: AWSNode.jsPostgresRedisTypescript GameChanger, Remote United States 140K-160K Annually Senior level 140K-160K Annually Senior level Computer Vision * Digital Media * Kids + Family * Mobile * Software * Sports Founding product designer running rapid validation sprints to test new business ideas. Plan and execute qualitative and quantitative research, build low- to high-fidelity prototypes (including coded/AI-assisted), recruit customers for tests, synthesize evidence, and deliver clear go/no-go recommendations and handoffs. Shape the Studio playbook and collaborate cross-functionally as needed. Top Skills: Ai ToolsFigma

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.ashbyhq.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · World Congress 2021

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all