> Markdown version of [/jobs/ext/726775-security-engineer](https://www.wearedevelopers.com/jobs/ext/726775-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** FanDuel Inc - **Location:** New York, NY, United States - **Salary:** $134,000.0 - $168,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Build Automation, Microsoft Azure, Code Review, Continuous Integration, Integrated Development Environments, Python (Programming Language), Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, Data Processing, Large Language Models, Software Security, Mitre Att&ck, Solid Principles, Software Coding - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=88f6614d34b1da73 ## About the Role Do you have experience in Tooling?, * Hands-on security engineering experience embedded in the software development lifecycle, with a working understanding of how risk surfaces across design, build, and deployment stages. * Solid coding skills in at least one modern language (Python, Go, or similar). * Strong understanding of software design principles and secure coding practices, with the ability to build security tooling that is maintainable, scalable, and built to production standards. * Experience designing and implementing AI Agents or similar automated systems that enforce security controls across engineering workflows. * Familiarity with AI/LLM security risks including prompt injection, model supply chain vulnerabilities, and data exposure, with an appetite to grow your expertise as the threat landscape evolves. * Familiarity with modern cloud infrastructure (AWS, GCP, or Azure) and software development environments. * Working knowledge of industry frameworks (OWASP, MITRE ATT&CK, NIST, or similar) and a practical sense of when and how to apply them. * Ability to perform risk analyses that help cross-functional partners weigh trade-offs and make informed decisions. * Ability to review code for security vulnerabilities across one or more modern languages, with familiarity in common weakness patterns such as injection, authentication flaws, and insecure data handling. ## Description Our roster has an opening with your name on it As a Security Engineer on our Software Security team, you'll deliver security projects that support quarterly team goals and reduce risk across the products and services FanDuel ships. Working closely with engineering teams across the organization, you'll identify risk, design solutions, and build the tooling and automation that make secure development repeatable at scale. You're equally comfortable writing code and reviewing systems for security gaps, and you bring hands-on curiosity and growing expertise in AI/LLM security as that space rapidly evolves. In addition to the specific responsibilities outlined above, employees may be required to perform other such duties as assigned by the Company. This ensures operational flexibility and allows the Company to meet evolving business needs. THE GAME PLAN Everyone on our team has a part to play * Deliver security projects that support quarterly team goals, working independently and seeking input when the path forward isn't clear. * Partner with engineering teams to identify security risks early, from design and code review through CI/CD, deployment, and production. * Build automation and tooling that makes secure development the path of least resistance for engineering teams across FanDuel. * Design and implement AI Agents that automate and enforce security controls across the SDLC. * Apply emerging AI/LLM security knowledge to identify, assess, and mitigate risks in AI-powered products, including prompt injection, model supply chain, and data exposure threats. * Collaborate with partner teams to champion security standards, best practices, and risk trade-offs. * Adapt your role to fill technical gaps as the program evolves. * Other duties as required. ## Related Videos - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [GenAI Is a Junior Dev With Root Access](https://www.wearedevelopers.com/videos/100191-genai-is-a-junior-dev-with-root-access) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)