TL;DR
Application Security Engineer (Gaming): Identifying and remediating security flaws and vulnerabilities in complex software designs across the software development lifecycle with an accent on understanding the threat landscape and defining secure development standards. Focus on conducting automated and manual security assessments and driving remediation efforts for identified vulnerabilities.
Location: Onsite in Dundee, Scotland
Company
hirify.global creates world-class entertainment experiences.
What you will do
- Track trends in the security community and stay abreast of emerging threats.
- Provide technical security guidance to developers, team leads and producers.
- Create and maintain threat models of applications and features.
- Conduct automated and manual security assessments of applications and services.
- Drive remediation efforts behind internally and publicly identified vulnerabilities.
- Support maintaining public and private bug bounty programs.
Requirements
- 3+ years of experience in identifying and remediating security bugs/flaws.
- Strong knowledge of principles and techniques for both manual and automated application security assessments of desktop and web applications.
- Good knowledge of common web security vulnerabilities (e.g., OWASP Top 10), attack techniques and remediation tactics.
- Good understanding of common low-level vulnerabilities (e.g. use-after-free and buffer overflows) and mitigations.
- Proficiency in C#.
- Familiarity with the software development lifecycle (SDLC) and securing its components.
Nice to have
- Background in reverse engineering and exploit research & development.
- Experience with scripting and process automation.
- Experience with authentication protocols such as OAuth2 and OIDC.
- Proficiency in C++ and JavaScript/TypeScript.
Culture & Benefits
- Inclusive, highly-motivated environment.
- Opportunity to learn and collaborate with talented people in the industry.
- Commitment to creating a work environment that promotes equal opportunity, dignity and respect.
- Provides reasonable accommodations to qualified job applicants with disabilities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →