> Markdown version of [/jobs/ext/2177623-security-engineer](https://www.wearedevelopers.com/jobs/ext/2177623-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** GameChanger Media, Inc. - **Location:** New York, NY, United States (Remote available) - **Experience:** Experienced - **Salary:** $120,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Application Firewall, Software System Penetration Testing, Architectural Patterns, Cloud Computing, Code Review, Cyber Security, Continuous Integration, DevOps, Github, Network Security, Machine Learning, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, TypeScript, Policy as Code, Delivery Pipeline, Large Language Models, Software Security, Mttr, Kotlin, Containerization, Kubernetes, Build Tools, Graphql, Front End Software Development, Terraform, Devsecops - **Published:** August 22, 2026 - **Apply:** https://www.dice.com/job-detail/f0df8217-1230-49b8-9bd5-71a1d2665976 ## About the Role * 3+ years in application security engineering * Proven experience building and operating internal security developer platforms or tooling that reduces developer friction * Demonstrated ability to use AI/ML-driven tools to enhance security effectiveness and scalability * Hands-on experience leading threat modeling engagements and designing paved roads * Proven track record integrating security tooling into CI/CD pipelines * Working knowledge of OWASP Top 10s (web, mobile, API, LLM) * Hands-on experience securing deployments in AWS with container and Kubernetes security, IaC scanning, and policy-as-code approaches * Demonstrated expertise in security-by-design in TypeScript, Swift, and/or Kotlin * Track record of implementing secure primitives in mobile ecosystems (iOS/Android) * Beneficial certifications: AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent. ## Description We're looking for a Security Engineer to join our InfoSec team and become the primary security partner for our software engineering organization. Reporting to the Security Engineering Manager, you'll operate application security across the SDLC, champion secure design and development practices, and bring DevSecOps discipline to how we build and ship software. This is a high-impact, highly collaborative role. You'll work closely with platform and product engineers to make security a part of how we build and deliver. You will also be a member of our weekly on-call rotation., * Champion security requirements for the responsible and secure integration of Gen AI and agentic AI tools within our product stack * Conduct security-by-design engagements for new features, APIs, platform initiatives, and infrastructure changes * Perform secure code reviews providing engineers with clear, actionable findings and remediation guidance * Partner with architecture and platform teams to establish secure API patterns (REST and GraphQL) * Contribute to and maintain secure coding guidelines, API security standards, and security architectural patterns that serve as the "paved roads" for all engineering teams * Give useful code review feedback, write documentation that outlasts the ticket, and run the occasional workshop or lunch-and-learn for engineers DevSecOps * Integrate and maintain security tooling across CI/CD pipelines * Enforce security quality gates in delivery pipelines * Harden the CI/CD platform components, including configuration and hardening of GitHub Actions and runner environments * Identify opportunities to leverage AI for increasing engineering productivity and agentic security workflows * Work alongside DevOps engineers to ensure cloud infrastructure is defined and deployed securely via IaC (terraform, k8s) * Implement and validate security controls for containerized workloads * Support the implementation of application-layer network security controls, such as Web Application Firewalls (WAFs) and CDN security, to protect application endpoints Vulnerability & Risk Management * Operate the application vulnerability management lifecycle * Triage and prioritize findings from our sources (including; GHAS, NowSecure, Wiz, BugCrowd, penetration tests) by business impact and exploitability * Proactively identify systemic risks and facilitate cross-functional initiatives to address root causes * Track security-specific KPIs (e.g., MTTR, vulnerability density, and security coverage of CI/CD pipelines) and translate them into actionable insights for engineering and business leadership * Effectively communicate security risk clearly to both engineering and business leaders, * Pragmatic defender. You understand that security must enable the business, not block it. You look for "secure by default" solutions and know how to make the right path the easy path for engineers. * Force multiplier. You don't solve every security problem yourself. You coach, document, and build systems that make the engineers around you more secure by default. * Clear communicator. You can trace a BOLA vulnerability chain to a frontend engineer and translate the same risk into business terms for a VP; and you know which conversation you're in. * Automation-first. If you have to do it twice, you'd rather write the script. * Long-view oriented. You think about medium-to-long-term system health, not just the current sprint, and you proactively address root causes rather than patching symptoms repeatedly. * Collaborative and cross-functional. You bring product, business, and operational context into your security decisions, not just security best practices in isolation. * Approachable. You foster open dialogue, encourage diverse perspectives, and make it easy for engineers to surface security concerns without fear of judgment or friction., * DICK'S Sporting Goods has company-wide practices to monitor and protect the company from significant compliance and monetary implications as it pertains to employer state tax liabilities. Due to said guidelines put in place, we are unable to hire in AK, DE, HI, IA, LA, MS, MT, OK, and SC. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)