Information Security Engineer

ProbablyMonsters Inc
Dallas, TX, United States
about 2 months ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Compensation
$95,000.0 - $138,000.0
Working hours
Regular working hours
Job source

Tech stack

Training Data Microsoft Windows Active Directory Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Proxy Servers Antivirus Softwares Software System Penetration Testing Microsoft Azure Cloud Computing Security Configuration Management
+58 more
Code Review Cyber Security Computer Networks System Configuration Data Centers Information Leak Prevention Linux Programming Tools Disaster Recovery Domain Name System (DNS) Multi-Factor Authentication Identity and Access Management Information Security Management Intrusion Detection and Prevention Intrusion Detection Systems Network Security Windows Servers Network Segmentation Open Web Application Security Perforce Azure Active Directory Ansible Zero Trust Network Access Security Information and Event Management Single Sign-On TCP/IP Software Vulnerability Management Network Routers Computer Gaming Load Balancing Computer Network Technologies GitHub Copilot System Availability Large Language Models Software Security Mttr Generative AI HybridCloud Firewalls (Computer Science) Git Web Filtering Falcon Platform GWAPT Containerization Kubernetes Information Technology Cybercrime Machine Learning Operations CIS Benchmarks Puppet Terraform GPT Api Management Security Orchestration, Automation & Response Jenkins Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

ProbablyMonsters is currently seeking an Information Security Engineer to help secure the data, assets, and systems that enable us to make world-class games and ensure they remain available for our players. Do you enjoy tackling unique challenges and creating solutions to empower your team’s workflow while reducing risk? Are you looking for an opportunity to leave your mark on the world around you? If so, we may be looking for you! Our Information Security Engineering team supports organizations across our family of studios to provide architectural feedback, analyze systems and policies, maintain and deploy new information security systems, provide user education, and respond to security incidents in studio and production environments. Join our family of studios and build solutions and systems to protect the availability and integrity of our teams, our assets, and our customers., * Selection, implementation, and refinement of existing and new information security systems; to include vulnerability management solutions, security event management, endpoint security and antivirus, network security monitoring and content filtering, and forensics capabilities within the infrastructure; developing and utilizing automation where possible

  • Review and monitor existing network, systems, and tools for compliance with company security standards
  • Evaluate new technologies and processes that enhance security capabilities
  • Confer with users to discuss issues such as access needs, evaluating new tools, and investigating security violations
  • Train users and promote security awareness to ensure system security and to improve server and network efficiency
  • Assess and govern the security posture of AI/ML systems in use across studios, including LLM integrations, AI-assisted development tools, and generative AI platforms; develop and enforce AI usage policies to mitigate risks such as data leakage, prompt injection, model abuse, and insecure AI outputs
  • Implement and maintain a Zero Trust security architecture across studio and cloud environments, including identity-centric access controls, micro-segmentation, and continuous verification principles
  • Lead security operations center (SOC) functions including threat detection, triage, and response using SIEM, SOAR, and XDR platforms; develop and maintain playbooks for common incident types

Requirements

Do you have experience in MFA?, * You are a security professional who is comfortable working in dynamic, technology-heavy environments.

  • You are an effective communicator with experience working across teams and departments, seeking ways to promote a culture of trust and respect.
  • You are a team player who enjoys collaborating to solve problems.
  • You are someone with strong time management and prioritization skills.
  • You are an automation and systems advocate that’s always on the lookout for ways to eliminate manual processes.
  • You are comfortable working with light supervision and in situations with ambiguous requirements. You are a gamer or someone familiar with video gaming and the games industry.
  • enjoy engaging with teams to identify their needs and provide them with insight.
  • You are curious and delighted by discoveries and trends in the security space., * In-depth understanding of information technology and information security practices, including the areas of application security, policy development, security-related research, physical security, systems integrity, and disaster recovery
  • Ability to rapidly learn new technologies and business functions. Good analytical skills and the ability to multi-task
  • Experience selecting, maintaining, configuring, and operating vulnerability management, security event management, endpoint security and antivirus, firewall, network security monitoring, and content filtering solutions
  • Experience implementing security applications, including installation, configuration, and automation of processes
  • Experience with networking technologies, such as firewalls, routers, load balancers, and proxies
  • Knowledge of network-based protocols such as TCP/IP, HTTP, HTTPS, DNS
  • Knowledge of datacenter and cloud live production best practices and experience working in live high availability customer-facing production environments
  • Experience with securing Microsoft Windows environments, Active Directory controls, and permissions, and group policies
  • Experience configuring, hardening, and maintaining Linux and Windows server operating systems
  • Ability to be flexible with changing needs and priorities and the ability to proactively detect and resolve problems or issues with systems, tools, and processes
  • Foundational understanding of AI/ML security risks, including prompt injection, model inversion, training data poisoning, and insecure API integrations; ability to evaluate and enforce safe use policies for generative AI tools such as GitHub Copilot, ChatGPT, and similar platforms
  • Experience with identity and access management (IAM) including privileged access management (PAM), multi-factor authentication (MFA), single sign-on (SSO), and identity governance in hybrid environments
  • Familiarity with data privacy regulations and frameworks (GDPR, CCPA, NIST CSF, SOC 2) and experience translating compliance requirements into technical controls
  • Hands-on experience with CrowdStrike Falcon platform modules, including Endpoint Detection and Response (EDR/Falcon Insight), Identity Protection (Falcon Identity Threat Protection), Cloud Security (Falcon Cloud Security/CSPM), Exposure Management and Vulnerability Management (Falcon Spotlight), and SaaS Security (Falcon SaaS Security Posture Management); ability to configure, tune, and operationalize detections and policies across these modules

PREFERRED SKILLS:

  • Experience with AWS and Azure cloud security in a hybrid cloud and on-prem environment
  • Experience with the security features and tools of Microsoft 365 and Azure AD
  • Experience with Development Security Operations, Threat Modeling, security assessments, security code review technology like SAST/DAST/IAST and evaluating mitigating controls for code development solutions such as Git, Perforce and Jenkins
  • Experience with network-based detective controls like NDR, IDS, IPS, and various SIEMS
  • Experience with security automation/configuration management using either Ansible, Puppet, Chef, Terraform, or an equivalent
  • Experience with performing vulnerability scans and assessments on multiple operating systems
  • Game Studio or Gaming Platform experience a plus
  • Experience performing incident response, threat hunting and computer system forensics
  • Understanding of Risk Management
  • Experience with continuous security assessment testing technologies
  • Understanding of CIS controls, benchmarks and hardening practices
  • Experience with Vendor risk management assessment
  • Experience evaluating and securing AI/ML systems and platforms, including assessing LLM integrations, model APIs, and AI-powered developer tools for security risk; familiarity with OWASP LLM Top 10 and emerging AI security frameworks
  • Experience with cloud-native security tooling (CSPM, CWPP, CNAPP) for securing containerized workloads and Kubernetes environments across AWS and Azure
  • Experience with supply chain security practices including software composition analysis (SCA), SBOM generation, and securing CI/CD pipelines against dependency and build-time attacks
  • Familiarity with Zero Trust architecture principles and experience implementing ZTNA solutions, microsegmentation, and identity-aware proxies
  • Experience with data loss prevention (DLP) solutions and insider threat programs, especially in environments with sensitive IP such as unreleased game assets and source code
  • Familiarity with CrowdStrike Falcon AI-Driven Detection and Response (AIDR) capabilities, including AI-native threat detection, automated investigation workflows, and Charlotte AI; understanding how AI-augmented SOC tooling can accelerate alert triage and reduce mean time to respond (MTTR)
  • Experience with continuous penetration testing platforms (e.g., Pentera, NodeZero, Cymulate, or similar) to automate attack simulation, validate security controls, and prioritize remediation efforts on an ongoing basis
  • One or more of following certifications a plus: OSCP, OSCE, GSEC, GPEN, GWAPT, CWAPT AWS Certified Security, Azure Security Engineer, CISSP, or equivalent; AI security-relevant credentials such as Certified AI Security Professional (CAISP) or equivalent training a plus

Benefits & conditions

Pulled from the full job description

  • AD&D insurance
  • Parental leave
  • 401(k)
  • Health insurance
  • Vision insurance
  • Dental insurance
  • Flexible spending account, * We provide a rich benefits package: *

  • Medical Coverage - health, dental, and vision.
  • Healthcare spending accounts, dependent care spending accounts, life and AD&D insurance.
  • 401(k) with an annual contribution by the Company.
  • Paid holidays and vacation, bereavement leaves, and parental leave.

Eligibility to participate in these benefits may vary for part-time and temporary full-time employees and interns with the Company.

Compensation:

  • This is a full-time, benefits-eligible, exempt (salaried) position.
  • The full salary range for this position is $95,000 - $138,000 per year. When an offer is made, many factors are considered, such as your unique experience and skills, where you live, where the work will be performed, what similar jobs pay, and internal equity.
  • In addition to base pay, employees in this role may be eligible for additional incentives, such as short- and long-term incentives. Incentive compensation is not guaranteed.

About the company

ProbablyMonsters is a AAA independent video game company that aims to change the way games are made. We unite a diverse roster of development teams in a healthy, rewarding culture. We believe empowered creators build the most engaging games and deliver the best player experiences.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · WWC 2021

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

40 sec

Generative pre-trained transformer models powering code completions

lgonta lgonta +1 · WWC 2024

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all