Senior AppSec Engineer

🕒 May 1

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of PrizePicks

PrizePicks

201 - 500 employees

🎮 Gaming

⚽ Sports

Gaming • Sports

PrizePicks is an innovative platform that offers a dynamic and interactive way to engage in daily fantasy sports and esports. Users can make predictions on player performances across various sports, including NFL, NBA, MLB, CFB, and more, with the opportunity to win up to 1000x their entry fee. PrizePicks operates legally in 43 U. S. states, Washington D. C. , and Canada, providing a wide range of betting options, including Pick 'Em and Pick 'Em Arena, where users compete against each other for cash rewards. The company emphasizes user engagement with features such as recurring promos and the Streak game, which is free to play and allows participants to earn by building daily win streaks. PrizePicks ensures secure transactions and fast payouts, enhancing user experience and satisfaction in the sphere of real money sports betting.

📋 Description

• Own the Pipeline: Support and optimize application security tooling (SAST, SCA, Secrets Detection) within our CI/CD pipelines to provide accurate, actionable, and prioritized alerts to devs. • Be a Security Champion: Act as the primary security partner for Engineering and Product teams, ensuring security is baked in from the design phase through deployment. • Threat Modeling: Lead collaborative threat modeling exercises to identify architectural risks before code is even written. Partner with penetration testing teams to translate these threats into targeted testing scenarios for high-risk functions. • Code-Level Remediation: Don’t just tell devs what is wrong—show them how to fix it by performing deep-dive code reviews and providing actionable remediation guidance. • Secrets Management: Help lead the charge in identifying and removing hard-coded secrets, moving the org toward more secure, automated secret management practices. • Bug Bounty & Research: Help manage our bug bounty program by triaging submissions, working with researchers, and validating fixes with our engineers. • Secure AI Integration: Serve as the security consultant for AI/ML initiatives. Partner with engineering to design secure "LLM-backed" features, focusing on prompt injection prevention, data privacy/sanitization, and secure integration of third-party AI APIs. • Incident Response: Support the team during application-related security incidents, bringing your deep knowledge of code and logic to the table. • Feature Validation: Perform security assessments on new features to help identify logic flaws that automated scanners might miss. Partner with our penetration testing team on high-risk releases to exchange knowledge and continuously sharpen your offensive security skillset. • Strategic Communication: Translate technical vulnerabilities into business risk. You’ll be responsible for documenting and presenting findings in a way that is actionable for engineers and understandable for leadership.

🎯 Requirements

• 3+ years of experience in software development, mobile development, or application security. You are comfortable reading unfamiliar code and can speak Developer fluently. • CI/CD Pipeline Expertise: Hands-on experience integrating security tools (SAST, DAST, SCA, Secrets Detection) into automated workflows (e.g., GitHub Actions, GitLab CI, Jenkins). You know how to tune these tools to prevent alert fatigue. • Deep knowledge of the OWASP Web Security Testing Guide (WSTG) and/or Mobile Application Security Testing Guide (MASTG) and the ability to think like a threat actor. • Experience conducting Threat Modeling to catch flaws before they are built. • Familiarity with the OWASP Top 10 for LLMs. You understand the unique risks of integrating AI into a production stack and can advise on how to build guardrails around model inputs and outputs. • Experience supporting an Incident Response (IR) process, specifically providing the AppSec perspective to help scope an exploit and verify if a patch truly mitigates it. • A deep understanding of how web applications work. You know your way around HTTP headers, JWTs, CORS, and auth flows, and you can validate them manually when the scanners fail. • Proven ability to define risks in both technical and business terms.

🏖️ Benefits

• Company-subsidized medical, dental, & vision plans • 401(k) plan with company match • Annual bonus • Flexible PTO to encourage a healthy work/life balance (2 weeks STRONGLY encouraged!) • Generous paid leave programs, including 16-week paid parental leave and disability benefits • Workplace flexibility and modern work schedules focused on getting the job done, not hours clocked • Company-wide in-person events and team outings • Lifestyle enhancement program • Company equipment provided (Windows & Mac options) • Annual performance reviews with opportunities for growth and career development

Apply Now

Similar Jobs

🕒 May 1

Rangen Group

201 - 500

🌾 Agriculture

🤝 B2B

Continuous Improvement Engineer driving operational excellence across feed production facilities at Rangen Group. Engaging with teams to identify waste and improve manufacturing efficiency.

🕒 May 1

SHI International Corp.

5001 - 10000

🤝 B2B

🔧 Hardware

☁️ SaaS

Network Engineer managing complex network infrastructures focused on Palo Alto firewalls and Fortinet technologies. Join SHI in providing IT solutions and services globally.

Azure

Cloud

Firewalls

Switching

TCP/IP

🕒 May 1

Leidos

10,000+ employees

🔒 Cybersecurity

🔬 Science

Senior Substation Physical Engineer designing electrical projects for power systems industry. Involves working on 12kV to 500kV utility projects with a remote work option.

🕒 May 1

Leidos

10,000+ employees

🔒 Cybersecurity

🔬 Science

Senior & Lead Transmission Line Engineers at Leidos working on high-voltage electric transmission systems. Engaging in design projects, engineering analyses, and client collaborations.

🕒 May 1

Leidos

10,000+ employees

🔒 Cybersecurity

🔬 Science

Senior Transmission Line Engineer working on high-voltage electric transmission line design projects for large utilities. Collaborating with a dynamic team to solve engineering challenges in a fast-paced environment.