Posted today · be early
Application Security Engineer
Enjoy Gaming LLC
WorldwideremotePosted today
E
Skill Required
Application-Security-EngineerSecurity-EngineerPenetration-TesterCybersecurity-EngineerAppSec-EngineerSenior-Application-Security-EngineerLead-Application-Security-EngineerApplication-Security-ArchitectApplication-Security-EngineeringApplication-Security-AnalystApplication-Security-SpecialistSoftware-Security-EngineerApplication-Security-LeadSecurity EngineerApplication DevelopersecurityPenetration TestingSOCData StructuresOWASPCD pipelinesEngineeringTestNGdesignExpressGitNmap.NETKafkaRedisCI/CDCloudDesign PatternsAWSGCPandCICDAIFulltime
Key highlights
- Competitive Salary in EUR with annual performance reviews
- 5+ years of Application Security Engineer experience required
- Flexible Remote Work offered
- Background in red teaming, penetration testing, application security, and software development required
- Medical insurance and psychologist support included
- 20 working days paid vacation plus 10 additional paid days off and 10 paid sick days
Role overview
Enjoy Gaming is a software provider focused on creating high-quality digital entertainment experiences, including Slots and Live Games, with a team of experienced professionals in game development, product, and design driven by innovation and quality. The company values ownership, excellence, and drive, and is looking for a sharp Application Security Engineer to act as the technical guardian for its games and platforms; you will not just send reports but dive deep into web and desktop applications, hunt game-level vulnerabilities, and collaborate with Architects, Studio, Slots, and Platform Developers to engineer more resilient systems.
Responsibilities
- Own and maintain application security pipelines: SCA (Github/Trivy), DAST (Nessus, Acunetix, Wiz), and SAST
- Triage findings from these tools and drive them to remediation
- Perform penetration tests on new platform features, new internal applications, and new slots and live games
- Run basic red team activities, including leaked credential reviews and external attack surface audits
- Review complex auth flows with various third parties for cryptographic and security issues
- Review/Triage application code for security issues (85% NestJS / 15% .NET)
- Own security risk in existing code and applications
- Act as the application-level security expert during incident response and be ready to deliver hotfixes yourself when needed
- Prepare quarterly SAST/DAST vulnerability scan reports for stakeholders/regulators and take part in audit meetings
- Own the Secure Coding and Application Security areas of our ISMS
- Meet regularly with development teams, learn about upcoming features early, and advise on secure design
Requirements
- 5+ years of Application Security Engineer experience
- Background in red teaming, penetration testing, application security, and software development
- Able to independently find vulnerabilities in web and desktop applications, triage them, and, where needed, fix them
- Solid grounding in data structures, algorithms, and systems architecture designs
- Previous security testing experience with Kafka/Redis/BullMQ/PubSub as message/streaming tools
- Codes independently, can navigate unfamiliar web application frameworks
- Experience using AI tools to aid with vulnerability hunting
- Comfortable talking to developers and turning findings into practical, actionable advice
Nice to have
- CRTO, OSCP, or OSWE certifications or similar
- Knowledge of Cloud Platforms (GCP/AWS)
- Understanding of CI/CD pipelines
- Hands-on experience with Trivy, Nessus, Acunetix, or Wiz
- Experience in iGaming or another regulated industry
Benefits
- Flexible Remote Work: balance productivity and comfort
- Comprehensive Benefits: including medical insurance, psychologist support, and Polish, Slovak-speaking clubs
- Generous Paid Time Off: 20 working days of paid vacation, plus 10 additional paid days off, 10 paid sick days, and all national holidays in your country
- Professional Development Support: reimbursement for courses, trainings, and certifications
- Well-being Perks: support for language classes, sports, massages, or life coaching
Additional details
- Please note that feedback on your application will be provided within two weeks if a positive decision is made regarding your candidacy.
- I give my consent following the Law on the Protection of Personal Data dated June 1, 2010, No. 2297, effective from January 1, 2011, for the processing of information classified as personal data.
- Originally posted on Himalayas