> Markdown version of [/jobs/ext/2126415-application-security-platform-engineer](https://www.wearedevelopers.com/jobs/ext/2126415-application-security-platform-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Platform Engineer - **Company:** Rockstar Games - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $121,400.0 - $166,700.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, C Sharp (Programming Language), C++ (Programming Language), Static Program Analysis, Continuous Integration, Linux, Github, Information Systems Security Architecture Professional, Python (Programming Language), Open Web Application Security, Web Application Security, Software Engineering, Policy as Code, Diagnostic Tools, Pulumi, Delivery Pipeline, Software Security, Kubernetes, Teamcity, Terraform, Static Application Security Testing - **Published:** August 19, 2026 - **Apply:** https://job-boards.greenhouse.io/rockstargames/jobs/7782765003 ## About the Role * 5+ years of experience working in a professional, academic or research environment identifying and remediating security bugs/flaws, assisted by automated pipelines. * Knowledge of common web security vulnerabilities (e.g., OWASP Top 10), client-side security landscape, attack techniques and remediation tactics/strategies. * Experience implementing and tuning SAST, SCA, IaC and Secrets Detection tools effectively, especially fine-tuning static analysis detections with custom rule engines (CodeQL, Semgrep). * Expertise deploying within CI/CD platforms (TeamCity or GitHub Actions) and container orchestration frameworks (e.g. Kubernetes), including establishing appropriate security controls in them * Experience in establishing monitoring and observability techniques of build pipelines and their outputs. * Experience with both Windows and Linux operating systems. * Proficiency in C#, Python., * Hands-on experience building or deploying security agents using frameworks like LangChain or LangGraph to automate complex multi-step security tasks. * Familiarity with using Infrastructure as Code languages (Terraform, Pulumi) to deploy secure architecture. * Experience enforcing security guardrails with Policy as Code (e.g. OPA) engines to existing and new CI/CD workflows. * Understanding of C++ and associated compilers. * Experience in establishing CI/CD controls for cloud-native pipelines and runtime environments. ## Description * Architect and support secure software development lifecycle operations embedded in software development pipelines. * Provide technical security guidance to developers, team leads, and producers. * Drive remediation efforts behind internally and publicly identified vulnerabilities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Why segmenting your infrastructure into tiers makes your infrastructure design better](https://www.wearedevelopers.com/videos/1960-why-segmenting-your-infrastructure-into-tiers-makes-your-infrastructure-design-better) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)