Application Security Engineer

ALTENAR KERN LLC
Malta, MT, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Testing (Software) Application Programming Interfaces (APIs) Agile Methodology Artificial Intelligence Software System Penetration Testing Burp Suite Cloud Computing Cyber Security Mobile Application Software Open Web Application Security Systems Development Life Cycle Web Application Security
+6 more
Software Engineering Software Security Information Technology GPT Devsecops Vulnerability Analysis

Job description

We are looking for an Application Security Engineer with strong knowledge of iGaming products to help secure our sportsbook, casinos, player account management (PAM), and mobile platforms.

This role combines product understanding with cybersecurity expertise. You will work closely with Product, Engineering, Compliance, and Operations teams to identify security risks across gaming products and ensure security is embedded throughout the entire product lifecycle.

The ideal candidate understands how iGaming platforms operate end-to-end, from registration, wallet integrations, and bonus systems to sportsbook solutions, casino integrations, and mobile apps., * Ensure that software development and deployment processes comply with relevant security policies, standards, and regulations, thereby protecting the organisation from legal and regulatory issues.

  • Drive ‘Security by Design’ across Sportsbook, Casino, PAM, and mobile platforms by serving as the lead security stakeholder in architectural reviews, effectively balancing product innovation with rigorous risk management.
  • Identify vulnerabilities and abuse scenarios affecting the products such as authentication systems, wallets and payments, bonuses and promotions and mobile applications and APIs.
  • Perform threat modeling and security reviews during product design and release cycles.
  • Collaborate with Risk, Engineering and Compliance teams on remediation efforts.
  • Review and investigate vulnerabilities discovered through penetration testing, automated scans, or incident investigations.
  • Help secure APIs and third-party integrations.
  • Support secure development practices within Agile product teams.
  • Contribute to incident response activities and root cause analysis for security events.
  • Maintain security standards and documentation aligned with regulatory and compliance requirements.

Requirements

Do you have experience in Web Application Security Testing?, * 4+ years of hands-on experience within the iGaming industry, specifically focusing on Sportsbook, Online Casino, or Player Account Management (PAM) platforms.

  • Strong understanding of the gaming ecosystem, including sportsbook and casino products, PAM (Player Account Management) systems, wallet and payment flows, mobile app infrastructure, and the end-to-end player lifecycle.
  • Good understanding of application security principles and common attack vectors.
  • Familiarity with OWASP Top 10, API security, Secure SDLC practices.
  • Ability to identify both technical vulnerabilities and product abuse scenarios.
  • Experience working with cross-functional product and engineering teams.
  • Familiarity with security testing tools such as Burp Suite, Tenable or mobile testing frameworks will be considered a plus.
  • Strong analytical and problem-solving skills.
  • Excellent communication and stakeholder management abilities.
  • Knowledge of cloud infrastructure and DevSecOps practices.
  • Experience with third-party gaming provider integrations.
  • Familiarity with gaming regulations and compliance standards.
  • Familiarity with leveraging AI tools (e.g., ChatGPT, Claude, Gemini) to streamline daily tasks, optimize workflows, and boost overall productivity., * Degree in Computer Science, Information Technology, or a related field.
  • Understanding of gaming regulatory frameworks.
  • Security certifications such as Security+, CEH, CISA, CRISC or CISSP.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

40 sec

Generative pre-trained transformer models powering code completions

lgonta lgonta +1 · World Congress 2024

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all