TL;DR
Application Security Specialist (Cybersecurity): Supporting application security architecture and risk management for game development with an accent on threat modelling, secure development lifecycle, and vulnerability remediation. Focus on designing security testing plans, collaborating with development teams, and managing security incident response.
Location: Cambridge, UK with hybrid work and weekly office visits
Company
hirify.global is a leading developer and publisher of online games, known for the RuneScape franchise and a commitment to player-first game design and inclusive culture.
What you will do
- Provide guidance on security best practices, compliance, and security testing
- Identify application security risks and requirements for new projects
- Collaborate with architecture and development teams to review design and code for vulnerabilities
- Establish threat modelling capabilities and promote secure coding in the development lifecycle
- Develop and integrate security testing plans into the software development lifecycle
- Participate in security incident response and monitor security metrics and KPIs
Requirements
- Location: Cambridge, UK with hybrid work and weekly office visits
- At least 3 years of software engineering experience and 2 years in application security
- In-depth knowledge of application security vulnerabilities, OWASP framework, and secure web application development
- Experience with Agile development methodologies and security awareness promotion
- Strong communication and relationship-building skills up to senior management levels
- Ability to work independently, prioritize workload, and participate in on-call rotation
Culture & Benefits
- Private healthcare including dental plan
- Minimum 6% pension contributions
- Employee assistance program and onsite counselling
- Life insurance and discretionary annual performance bonus
- Enhanced family leave policies from day one
- Flexible working hours and 25 days annual leave plus bank holidays with buy/sell option
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →