Senior AppSec Engineer

4 Months ago • 5-5 Years • Cyber Security

Job Summary

Job Description

Senior AppSec Engineer needed for Penn Interactive in Philadelphia. Must have 5+ years experience with Application Security and DevOps. Experience with GCP or AWS, software supply chain security, and programming in Python or Go is required.
Must have:
  • Application Security
  • DevOps Experience
  • GCP or AWS
  • Software Supply Chain
Good to have:
  • CI/CD Workflows
  • Kubernetes Clusters
  • RESTful APIs
  • Containerized Workloads
Perks:
  • Competitive Compensation
  • Fun Work Environment

Job Details

Penn Interactive (PI) is an interactive gaming company headquartered in Philadelphia. PI is the digital arm of PENN Entertainment (NASDAQ: PENN), the largest regional casino operator in the U.S.). Our mission is to challenge the norms of the gaming industry by building an immersive interactive gaming experience that is responsible, innovative, and fun. We are committed to helping our team members grow and succeed.  We believe that hiring talented individuals that love what they do will help us win!

About the Role & Team

As part of the team, you will be working with a team of smart, friendly, and dedicated Engineers, Product Managers and Designers determined to deliver some of the best apps the market has to offer. We want you to be challenged and to get the full experience of what it is like to work at theScore! We are looking for a Senior Application Security Engineer to join our Application Security team. Our team takes a hands-on approach to solving complex security problems in conjunction with writing policies and procedures. You will work cross-functionally across the entire engineering organization. You will share your unique expertise with the team and be able to grow and expand that expertise. We have a wide variety of security challenges, and we are looking for someone who is excited to tackle them. Come join us and help us build the best sports apps in the world!

About the Work

  • Collaborate with release and change management, SRE, Engineering, and compliance teams
  • Work with security/internal/external/state auditors to demonstrate compliance
  • Maintain a working knowledge of OWASP top 10 and MITRE top 25 CWE
  • Develop standards for security tooling focused on the application layer (SAST, DAST, SCA, MAST, RASP)
  • Build/implement secure artifact workflows in the SDLC to ensure governance and compliance standards are being met
  • Create technical approaches to implementing Application Security control technologies
  • Contribute to theScore’s Application Security program to support our continued growth
  • Define and report on security metrics, their delivery, and improvements
  • Work with service teams to conduct threat models of theScore’s internal and customer facing applications
  • Assist service teams in understanding and remediating security findings (code bashing)
  • Other duties as required.

About You

  • 5+ years of Application Security or DevOps experience
  • 5+ years of GCP or AWS experience
  • Experience with software supply chain security (SBOMs, Artifact Signing, Attestations)
  • Programming experience in Python or Go
  • Experience with implementing security tooling in CI/CD
  • Experience creating complex CI/CD workflows (building for multiple architectures, local caching, making automated source code changes based on workflow output)
  • Experience supporting RESTful APIs and securing containerized workloads (GKE, EKS)
  • Experience working in regulated environments (PCI-DSS, SOC 2, etc.)
  • Experience leading technical projects and seeing them through to completion
  • Excellent communication skills and a history of working well with other teams
  • Optional: Experience maintaining Kubernetes clusters, or managing Kubernetes deployments

What We Offer

  • Competitive compensation package.
  • Fun, relaxed work environment.
  • Education and conference reimbursements.
  • Opportunities for career progression and mentoring others.

    #LI-HYBRID

Check out our LinkedIn page!

Recently being recognized as a top workplace in the United States, we believe people work their best when they can be themselves. We are looking for hungry, innovative thinkers to help us challenge the status quo of the gaming industry.  Diversity, equity, and inclusion are vital to all of our processes, programs, and structures. Your story, who you are, and your experience matter here.

Similar Jobs

vi - Data Infrastructure Engineer

vi

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
3 Months ago
PwC - Senior Associate _ Automation Tester_ Emerging  Technologies_ Advisory_ Bengaluru

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Warner Bros. Games - Software Engineer II (Database Reliability Engineering Team), Bangalore

Warner Bros. Games

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Blizzard Entertainment - Associate Software Engineer, Production Technology

Blizzard Entertainment

Irvine, California, United States (Hybrid)
3 Months ago
Trend Micro - (Sr.) Software Engineer

Trend Micro

Taipei City, Taiwan (On-Site)
4 Months ago
Infoblox - Principal Software Architect

Infoblox

Austin, Texas, United States (Hybrid)
3 Months ago
PwC - IN-Manager_AWS Engineer_Advisory Corporate_Advisory_Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
PwC - IN_Associate _ Internal Audit _Internal Audit Services_ Advisory_ Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

ION - Senior Security Architect

ION

Pisa, Tuscany, Italy (On-Site)
4 Months ago
ByteDance - Site Reliability Engineer (Cloud) - Infrastructure Engineering

ByteDance

Singapore (On-Site)
3 Months ago
Hatch - Software Developer - WPF

Hatch

Gurugram, Haryana, India (On-Site)
3 Months ago
Brightly - Principal Software Engineer (PSE) - iOS

Brightly

Noida, Uttar Pradesh, India (On-Site)
4 Months ago
Nielsen - Sr DevOps Engineer (AM-TECH-DA-40)

Nielsen

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Smarsh - Lead Machine Learning Engineer

Smarsh

New York, New York, United States (Hybrid)
4 Months ago
Dotdash Meredith - Senior Software Engineer, 1

Dotdash Meredith

Karnataka, India (On-Site)
4 Months ago
Trend Micro - Sr. Microsoft Dynamic Engineer

Trend Micro

Taipei City, Taiwan (On-Site)
4 Months ago
Appier - Software Engineer, System Integration

Appier

Taipei City, Taiwan (On-Site)
3 Months ago
Omnissa - C++ Engineering Manager

Omnissa

Bengaluru, Karnataka, India (Hybrid)
5 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Philadelphia, Pennsylvania, United States

ZeniMax Media - Senior Manager, Workplace Services

ZeniMax Media

Rockville, Maryland, United States (On-Site)
3 Months ago
Next Level Business Services - SAP VIM Consultant

Next Level Business Services

Saint Paul, Minnesota, United States (On-Site)
4 Months ago
Google - Program Manager II, Network Optimization, Google Cloud

Google

Atlanta, Georgia, United States (On-Site)
3 Months ago
ByteDance - Network Engineer, High Performance GPU Network Direction - Ashburn, VA

ByteDance

Ashburn, Virginia, United States (On-Site)
3 Months ago
Penumbra - QA Manager - DHR Review

Penumbra

Alameda, California, United States (On-Site)
4 Months ago
ION - Senior Network Engineer

ION

Clifton, New Jersey, United States (On-Site)
4 Months ago
eBay - Senior Counsel, Payments

eBay

San Jose, California, United States (Hybrid)
4 Months ago
Salesforce - Small, Medium and Growth Business - Account Executive - Atlanta

Salesforce

Atlanta, Georgia, United States (On-Site)
4 Months ago
Scopely - VP of Product - WWE Champions

Scopely

United States (Remote)
3 Months ago
Sphere Entertainment Co. - VFX Producer

Sphere Entertainment Co.

Burbank, California, United States (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

ION - Markets Governance, Risk and Controls Manager

ION

India (On-Site)
4 Months ago
undefined - Cloud SecOps Engineer

Bengaluru, Karnataka, India (On-Site)
4 Months ago
PwC - IN_Manager _Technical Delivery Manager_ Emerging Technologies_ Advisory_ Bengaluru

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Trellix - Associate Customer Success Engineer

Trellix

Kuala Lumpur, Federal Territory Of Kuala Lumpur, Malaysia (On-Site)
3 Months ago
ION - Markets Product Security Engineer - UK

ION

London, England, United Kingdom (On-Site)
4 Months ago
Balbix - Senior/Staff/Principal Full Stack Engineer

Balbix

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Trend Micro - Sr. Information Security Specialist

Trend Micro

Irving, Texas, United States (On-Site)
3 Months ago
barracuda-networks-inc - Security Automation Engineer

barracuda-networks-inc

Bengaluru, Karnataka, India (On-Site)
4 Months ago
PwC - Transformation Risk and Advisory Manager

PwC

Toronto, Ontario, Canada (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Penn Interactive (PI) is an interactive gaming company headquartered in Philadelphia,PA with offices in Greenfield, MA, and Cherry Hill, NJ. As the digital arm of PENN Entertainment (NASDAQ: PENN), North America’s leading provider of integrated entertainment, sports content, and casino gaming experiences, we are poised for fast-paced growth in the sports betting and online casino space. We have teamed up with theScore to create a unique and exciting sports betting experience through our retail books and the Sportsbook mobile apps.

Philadelphia, Pennsylvania, United States (On-Site)

Cherry Hill, New Jersey, United States (Hybrid)

Philadelphia, Pennsylvania, United States (On-Site)

Philadelphia, Pennsylvania, United States (Hybrid)

Philadelphia, Pennsylvania, United States (Hybrid)

Philadelphia, Pennsylvania, United States (Hybrid)

Philadelphia, Pennsylvania, United States (Hybrid)

Philadelphia, Pennsylvania, United States (Hybrid)

Detroit, Michigan, United States (On-Site)

View All Jobs

Get notified when new jobs are added by PENN Interactive

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug