Senior Security Engineer - Application Security

6 Days ago • 5 Years + • Cyber Security

About the job

Job Description

As a Senior Security Engineer, you will collaborate with Engineering teams to enhance web application firewall and application security programs. Responsibilities include advancing WAF controls, overseeing web/mobile application security, identifying/mitigating threats, and shaping security strategies. You will integrate security into the SDLC (SAST, DAST, Secure Code Reviews), manage CDN and WAF security (DoS/DDoS mitigation, credential-stuffing prevention), perform security reviews for Android/iOS apps, secure production workloads (containers, Kubernetes), and participate in security escalation rotations. The role requires strong experience in application security, DevOps, and cloud security technologies.
Must have:
  • 5+ years AppSec experience
  • SAST/DAST/DevSecOps expertise
  • WAF/CDN/DDoS mitigation
  • Secure Code Reviews
  • Cloud security (AWS/GCP)
  • Mobile App Security
Good to have:
  • Experience with Terraform, Jenkins, Artifactory, Octopus Deploy
  • Experience with Docker and Kubernetes
Perks:
  • Bonus
  • Equity
  • Benefits

We’re defining what it means to build and deliver the most extraordinary sports and entertainment experiences. Our global team is trailblazing new markets, developing cutting-edge products, and shaping the future of responsible gaming.

Here, “impossible” isn’t part of our vocabulary. You’ll face some of the toughest but most rewarding challenges of your career. They’re worth it. Channeling your inner grit will accelerate your growth, help us win as a team, and create unforgettable moments for our customers.

The Crown Is Yours

As a Senior Security Engineer, you'll collaborate closely with Engineering teams to drive and evolve our web application firewall and application security programs. In this role, you'll focus on advancing the security of our web application firewall controls, overseeing comprehensive web and mobile application security, and proactively identifying and mitigating emerging threats. Your work will be instrumental in shaping our security strategies and contributing to the continuous growth and resilience of our technology infrastructure.

What you'll do as a Senior Security Engineer:

  • Integrate security into the SDLC process, conducting SAST, DAST, and Secure Code Reviews throughout all development phases.

  • Manage and enhance security for the CDN and WAF, including DoS/DDoS mitigation, credential-stuffing prevention, and overall cloud security posture improvement.

  • Perform and oversee security reviews for Android and iOS applications, including vulnerability research, reproduction, and remediation.

  • Secure our production workloads, including containers and container orchestration systems like Kubernetes.

  • Participate in periodic off-hours escalation rotations for application security.

What you'll bring

  • At least 5 years of experience in running Application Security program including SAST, DAST, DevOps practices, and integrating security inside CI/CD pipeline.

  • Ability to secure DevOps platforms such as Terraform, Jenkins, Artifactory, Octopus Deploy, and container technologies like Docker, Kubernetes, and their cloud-managed counterparts (AWS EKS, GCP GKE).

  • Experience and knowledge managing CDN, WAF, DDoS, password spraying, and bot prevention technologies (e.g., Akamai botman, Fastly, Cloudflare)

  • Proficient in working with developers to remediate web and mobile application security vulnerabilities on Web, iOS, and Android platforms.

#LI-BF1

Join Our Team

We’re a publicly traded (NASDAQ: DKNG) technology company headquartered in Boston. As a regulated gaming company, you may be required to obtain a gaming license issued by the appropriate state agency as a condition of employment. Don’t worry, we’ll guide you through the process if this is relevant to your role.

The US base salary range for this full-time position is 110,200.00 USD - 137,800.00 USD, plus bonus, equity, and benefits as applicable. Our ranges are determined by role, level, and location. The compensation information displayed on each job posting reflects the range for new hire pay rates for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific pay range and how that was determined during the hiring process. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
View Full Job Description
$110.2K - $137.8K/yr (Outscal est.)
$124.0K/yr avg.
United States

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

United States (Remote)

Boston, Massachusetts, United States (On-Site)

Plovdiv, Plovdiv Province, Bulgaria (On-Site)

Missoula, Montana, United States (On-Site)

Plovdiv, Plovdiv Province, Bulgaria (On-Site)

Sofia, Sofia City Province, Bulgaria (On-Site)

Plovdiv, Plovdiv Province, Bulgaria (On-Site)

Plovdiv, Plovdiv Province, Bulgaria (Hybrid)

View All Jobs

Get notified when new jobs are added by DraftKings

Similar Jobs

Luxoft - .Net Software Developer

Luxoft, Singapore (On-Site)

Nagarro - QA-AUTOMATION

Nagarro, Egypt (On-Site)

Intelsat - Senior Software Engineer

Intelsat, India (Hybrid)

Nagarro - Senior Staff Engineer, Java Fullstack

Nagarro, Saudi Arabia (On-Site)

Level AI - Software Engineer - Machine Learning

Level AI, India (Hybrid)

Forcepoint - Security Researcher II

Forcepoint, India (On-Site)

Barbaricum - Information Systems Security Engineer

Barbaricum, United States (On-Site)

Mattel  Inc  - Manager GRC

Mattel Inc , United States (On-Site)

Qualys - Cloud Security Engineer

Qualys, India (On-Site)

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Luxoft - JIRA Developer

Luxoft, United States (Remote)

ICE - Software Engineer

ICE, India (Hybrid)

Qatar Airways - DevOps Engineer

Qatar Airways, India (On-Site)

Playtech - ProdOps Engineer

Playtech, (On-Site)

Playrix - Golang Tech Lead

Playrix, Ukraine (Remote)

bosh group india - Automic Workload Expert

bosh group india, India (On_site)

Luxoft - Senior Java Developer

Luxoft, Ukraine (Remote)

Revenera - Senior Site Reliability Engineer

Revenera, India (Hybrid)

Nagarro - Associate Staff Engineer, NodeJS

Nagarro, India (Remote)

Playrix - Senior QA Engineer (Render Team)

Playrix, Georgia (Remote)

Get notifed when new similar jobs are uploaded

Jobs in United States

Nintendo - Localization Specialist (Japanese)

Nintendo, United States (Hybrid)

Meta - Product Manager, Machine Learning

Meta, United States (Remote)

Next Level Business Services - Cassandra Admin

Next Level Business Services, United States (On-Site)

Netflix - Managing Editor, Product Creative Studio Live

Netflix, United States (On-Site)

Obsidian Entertainment - Environment Artist - Summer Internship

Obsidian Entertainment, United States (On-Site)

Microsoft - Site Reliability Engineering Manager

Microsoft, United States (On-Site)

Smarsh - Sales Development Representative I

Smarsh, United States (Hybrid)

Netflix - Data Science Manager, Content and Studio DSE

Netflix, United States (Remote)

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Get notifed when new similar jobs are uploaded