Required Application security specialist
About the department
The infosec department is responsible for the Confidentiality, Integrity and Availability of the company's information, systems and processes. It's in charge of establishing controls, building trust and relationships with other departments in the company and making sure that acceptable risk levels are met. The infosec department is working in a huge scale, cloud based environment and supporting the company in delivering the best game experience for over 400 millions gamers world wide.
Responsibilities:
Own our product security: Games and Business solutions developed in-house
Work closely with our R&D teams to Drive a secure development lifecycle and integration of security features into all phases of games and app design and development
In charge of creating Threat Modeling for new games and applications developed: Identify security requirements, Pinpoint security threats and vulnerabilities, assess risks criticality and lead mitigation plan and initiatives to minimize risk to an acceptable level
Own SAST and DAST systems, run scans, analyze results and lead mitigation plans
Research new application security technologies and features and their relevance for our development efforts.
Requirements: 10+ years of experience in Application Security
5+ years Application Penetration Tests, Code review
Experience with secure coding techniques
Deep knowledge in web & application security
Deep knowledge with at least 2 of the following development languages: Java, JavaScript, Python, C, C#, SQL
Great knowledge and understanding of Cloud, DevOps and Containers technology
Desired:
Experience with application security in a gaming company
Cyber security certifications: CISSP, CCSK, etc.
This position is open to all candidates.