> Markdown version of [/jobs/ext/2483544-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2483544-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Rockstar Games - **Location:** Dundee, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Authentication Protocols, Automation of Tests, Burp Suite, C Sharp (Programming Language), C++ (Programming Language), Computer Networks, Linux, Fat Client, Fiddler (Software), OAuth, OpenID, Open Web Application Security, Systems Development Life Cycle, Reverse Engineering, Web Application Security, Software Engineering, TCP/IP, TypeScript, Web Applications, WebSocket, WinDBg, Windows Desktop, Scripting, Software Security, Information Technology, Web Technologies - **Published:** August 6, 2026 - **Apply:** https://www.totaljobs.com/job/application-security-engineer/rockstar-games-job107801577 ## About the Role * 3+ years of experience working in a professional, academic or research environment identifying and remediating security bugs/flaws. * Strong knowledge of the principles and techniques for both manual and automated application security assessments of desktop and web applications. * Good knowledge of common web security vulnerabilities (e.g., OWASP Top 10), attack techniques and remediation tactics/strategies. * Good understanding of common low-level vulnerabilities (e.g. use-after-free and buffer overflows)and common mitigations. * Good understanding of networking and web technologies (e.g. WebSockets, HTTPS, TCP/IP, UDP) and security controls relevant to them. * Familiarity with Windows and Linux operating systems fundamentals. * Familiarity with the software development lifecycle (SDLC) and working knowledge of components to secure the SLDC. * Practical experience with client network traffic testing tools and techniques e.g., Burp Suite, Fiddler and Bruno. * Practical experience with thick client testing tools and techniques e.g. Procmon, Strings2, Dependencies. * Proficiency in C#. * Excellent communication skills., * BSc/MSc in a computer science or related field. * Background in reverse engineering and exploit research & development and relevant tools such as Ghidra, IDA, x64dbg and WinDbg. * Experience with scripting and process automation. An understanding of effective practices for securing the SDLC that considers developer experience, sustainability and compliments release velocity. * Experience with authentication protocols and extensions such as OAuth2 and OIDC. * Experience in results-oriented, retail driven environment with strict deadlines and ship dates. * Familiarity with bug bounty programs/responsible disclosure programs, either running one or as a researcher. * Proficiency in C++ and JavaScript/TypeScript. ## Description * Track trends in the security community and stay abreast of emerging threats. * Provide technical security guidance to developers, team leads and producers. * Create and maintain threat models of applications and features to systematically understand how they can be attacked to prioritize control development. * Conduct automated and manual security assessments of applications and services. * Drive remediation efforts behind internally and publicly identified vulnerabilities. * Support maintaining Rockstar Games' public and private bug bounty programs. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Blindspots and How to Learn About Them - Anna Oliveira](https://www.wearedevelopers.com/videos/1754-security-blindspots-and-how-to-learn-about-them-anna-oliveira) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 105 - Security First](https://www.wearedevelopers.com/magazine/393-dev-digest-105-security-first) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)