Senior AppSec Engineer
Company
theScore
Location
Other US Location
Type
Full Time
Job Description
theScore, a wholly-owned subsidiary ofĀ PENN EntertainmentĀ , empowers millions of sports fans through its digital media and sports betting products. Its media app ātheScoreā is one of the most popular in North America, delivering fans highly personalized live scores, news, stats, and betting information from their favorite teams, leagues, and players.Ā theScoreās sports betting app ātheScore Bet Sportsbook & Casinoā delivers an immersive and holistic mobile sports betting and iCasino experience. theScore Bet is currently live in the Company's home province of Ontario.Ā theScore also creates and distributes innovative digital content through its web, social and esports platforms.
Ā About the Role & Team
As part of the theScore team, you will be working with a team of smart, friendly, and dedicated Engineers, Product Managers and Designers determined to deliver some of the best apps the market has to offer. We want you to be challenged and to get the full experience of what it is like to work at theScore! We are looking for a Senior Application Security Engineer to join our Application Security team. Our team takes a hands-on approach to solving complex security problems in conjunction with writing policies and procedures. You will work cross-functionally across the entire engineering organization. You will share your unique expertise with the team and be able to grow and expand that expertise. We have a wide variety of security challenges, and we are looking for someone who is excited to tackle them. Come join us and help us build the best sports apps in the world!
About the Work
- Collaborate with release and change management, SRE, Engineering, and compliance teams
- Work with security/internal/external/state auditors to demonstrate compliance
- Maintain a working knowledge of OWASP top 10 and MITRE top 25 CWE
- Develop standards for security tooling focused on the application layer (SAST, DAST, SCA, MAST, RASP)
- Build/implement secure artifact workflows in the SDLC to ensure governance and compliance standards are being met
- Create technical approaches to implementing Application Security control technologies
- Contribute to theScoreās Application Security program to support our continued growth
- Define and report on security metrics, their delivery, and improvements
- Work with service teams to conduct threat models of theScoreās internal and customer facing applications
- Assist service teams in understanding and remediating security findings (code bashing)
- Other duties as required.
About You
- 5+ years of Application Security or DevOps experience
- 5+ years of GCP or AWS experience
- Experience with software supply chain security (SBOMs, Artifact Signing, Attestations)
- Programming experience in Python or Go
- Experience with implementing security tooling in CI/CD
- Experience creating complex CI/CD workflows (building for multiple architectures, local caching, making automated source code changes based on workflow output)
- Experience supporting RESTful APIs and securing containerized workloads (GKE, EKS)
- Experience working in regulated environments (PCI-DSS, SOC 2, etc.)
- Experience leading technical projects and seeing them through to completion
- Excellent communication skills and a history of working well with other teams
- Optional: Experience maintaining Kubernetes clusters, or managing Kubernetes deployments
What We Offer
- Competitive compensation package.
- Fun, relaxed work environment.
- Education and conference reimbursements.
- Parental leave top
- Opportunities for career progression and mentoring others.
#LI-REMOTE
Ā
Candidates residing in Ontario requiring special accommodation can email [email protected]
theScore is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability or age.
Ā
Date Posted
09/23/2024
Views
1
Similar Jobs
Senior Engineering Manager, Micros Foundations - Atlassian
Views in the last 30 days - 0
Atlassian is seeking a Senior Engineering Manager to lead a team of Backend Software Engineers The role involves guiding technical decisions prioritiz...
View DetailsSenior Frontend Engineer - Simply Business
Views in the last 30 days - 0
Simply Business is seeking a Senior Frontend Engineer to join their Front End Tooling team The role involves developing products using best practices ...
View DetailsSenior Professional Services Consultant - Cloudflare
Views in the last 30 days - 0
The role of a Professional Services Consultant for Application Security and Performance at Cloudflare involves providing advisory and handson keyboard...
View DetailsSenior Software Engineer (Scala/Java) - HERE Technologies
Views in the last 30 days - 0
HERE Technologies is seeking an experienced backend engineer with strong Java or Scala skills to join the Map Processing Pipelines team The role invol...
View DetailsSenior Product Analyst - FinCrime Platform - WISE
Views in the last 30 days - 0
Wise is seeking a Senior Product Analyst for its FinCrime Platform The role involves driving analytics efforts in the Financial Crime Platform product...
View DetailsSenior Data Analyst - Customer Experience - WISE
Views in the last 30 days - 0
Wise is a global technology company aiming to revolutionize international money transfers by offering minimal fees maximum ease and full speed They ar...
View Details