Senior Application Security Engineer

hace 5 meses


Barcelona, España Fortis Games A tiempo completo

**Who we are**

At Fortis Games we aspire to make great games that bring people together while redefining how game companies work. We believe in building a sense of belonging through our games, their communities, and how we operate and treat each other. Through our game communities, we will create powerful connections and lasting memories. We will foster a culture of diversity, equity and belonging where together our diverse skills, experiences and background impact the games we make.

We are an early but mighty organization with a leadership team of game industry veterans. There are many opportunities for you to have a big impact on the products we'll be making as well as the overall direction of the company. If you're passionate about tackling difficult problems with direct and thoughtful communication and team first mentality, we may be the right place for you.

**About the role**:
**What you will do**:

- Own the Application Security technology stack and associated processes and procedures
- Help maintain our build & deployment processes
- Provide architectural guidance and leadership on best practices regarding security in software development, shared services, user interface design frameworks, high performance solutions, server side development, integrations, tools and technologies
- Implement, tune and help game teams understand the output from static analysis tools
- Collaborate with engineers, consultants and leadership to address security risks and provide mitigation recommendations within the Secure Development Lifecycle (SDLC).
- Perform validation of security controls to ensure consistency with compliance and industry standard methodologies.
- Perform hands on security testing of products and services to proactively discover risks and supervise them to resolution.
- Understand, balance and communicate business risk with security risk.
- Track project progress through project management software such as ClicklUp JIRA, Confluence and Google suite
- Build relationships with cross functional teams to execute projects on time and with high quality
- Perform audits and assessments to identify risk and create a remediation plan
- Build reports and communicate security posture to all levels of the organization
- Manage multiple projects concurrently and maintain project & technology-level documentation

**Required qualifications**:

- Comfortable with ambiguity
- Experience working with internal and external partners and vendors to achieve goals on aggressive timelines
- Experience working on complex projects with multiple stakeholders, timelines and budgets
- Self motivated and proactive with demonstrated creative and critical thinking skills
- Excellent communication, organizational, leadership and collaboration skills
- Prior experience working on a Security Operations, Software Development or Application Security team
- Prior experience at a mobile gaming organization a plus
- Expert knowledge with architecting and implementing security solutions into software development lifecycle (SDLC) and CI/CD pipelines
- Building and architecting build & deploy processes, infrastructure-as-code (IaC), and CI/CD pipelines
- Experience implementing, tuning and helping software teams understand the output from SCA, SAST, DAST tools
- Experience with SBOM generation tools
- Hands-on secure code review
- Educate and integrate security in a non-blocking way throughout the development cycle
- Review code and hunt for security vulnerabilities before we release products to players
- Understanding of vulnerability management in development, such as triage, analysis, and remediation
- Experience with open-source software security
- Good communication, organization, time-management, and prioritization skills
- Champion Product Security initiatives to engineers
- Define security test strategies for complex systems, identifying security vulnerabilities
- Develop powerful security tools and automation systems
- Experience with international security and privacy requirements such as GDPR
- Understanding of common security flaws, CWEs
- Knowledge of automated attack tools and developing mitigation techniques.
- Experience of security architecture and design reviews.
- Experience with multiple languages such as C#, Typescript, Javascript, etc. and understand how to detect and remedy related security issues such as OWASP top 10.
- Experience with Unity, WebGL, iOS, and Android
- Able to work both independently as well with development teams and multi-task effectively.
- Work well with other people, see the value of a team, and partner effectively with all stakeholders
- Know how write reliable software in Python or another language and consider automation whenever possible
- Aim to always be learning new things and share this passion with those around you

**Why join us**

There are many reasons to join us, but here are a few:

- We strongly believe we are changing how games studios operate and at the core of what we do is maki



  • Barcelona, España Mygwork A tiempo completo

    Senior Application Security Engineer, Application SecurityBarcelona, Catalonia, ESThis job is with Amazon, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.DESCRIPTION:At Amazon, security is central to maintaining customer trust and delivering...


  • Barcelona, España Mygwork A tiempo completo

    .Senior Application Security Engineer Barcelona This job is with Oracle, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.As a Senior Application Security Engineer with a focus on Incident Investigation, you will be part of the Product Security team...


  • Barcelona, España Mygwork A tiempo completo

    .Senior Application Security Engineer Barcelona This job is with Oracle, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. As a Senior Application Security Engineer with a focus on Incident Investigation, you will be part of the Product Security team...


  • Barcelona, España Oracle A tiempo completo

    .Oracle Oracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services.As a Senior Application Security Engineer with a focus on Incident Investigation, you will be part of the Product Security team and work closely with NetSuite's SOC. You will be the Application Security expert in incident investigations, deep...


  • Barcelona, España Oracle A tiempo completo

    .Oracle Oracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services. As a Senior Application Security Engineer with a focus on Incident Investigation, you will be part of the Product Security team and work closely with NetSuite's SOC. You will be the Application Security expert in incident investigations, deep...


  • Barcelona, España Antal International A tiempo completo

    **_The Role:_** - As a Senior Security Engineer, you will play a pivotal role in establishing and spearheading our company's appsec program, ensuring the security of our products and services. You will be responsible for conducting comprehensive security assessments, identifying and remediating vulnerabilities, and collaborating with our product and tech...


  • Barcelona, España Oracle A tiempo completo

    Oracle Oracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services.As a Senior Application Security Engineer with a focus on Incident Investigation, you will be part of the Product Security team and work closely with NetSuite's SOC.You will be the Application Security expert in incident investigations, deep...


  • Barcelona, España Oracle A tiempo completo

    Oracle Oracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services. As a Senior Application Security Engineer with a focus on Incident Investigation, you will be part of the Product Security team and work closely with NetSuite's SOC. You will be the Application Security expert in incident investigations, deep...


  • Barcelona, España Oracle A tiempo completo

    OracleOracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services.As a Senior Application Security Engineer with a focus on Incident Investigation, you will be part of the Product Security team and work closely with NetSuite's SOC. You will be the Application Security expert in incident investigations, deep...


  • Barcelona, España Oracle A tiempo completo

    OracleOracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services.As a Senior Application Security Engineer with a focus on Incident Investigation, you will be part of the Product Security team and work closely with NetSuite’s SOC. You will be the Application Security expert in incident investigations, deep...


  • Barcelona, España Oracle A tiempo completo

    OracleOracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services.As a Senior Application Security Engineer with a focus on Incident Investigation, you will be part of the Product Security team and work closely with NetSuite’s SOC. You will be the Application Security expert in incident investigations, deep...


  • Barcelona, España Oracle A tiempo completo

    Oracle Oracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services.As a Senior Application Security Engineer with a focus on Incident Investigation, you will be part of the Product Security team and work closely with NetSuite’s SOC. You will be the Application Security expert in incident investigations, deep...


  • Barcelona, Barcelona, España ProtonMail A tiempo completo

    About the RoleWe are seeking a highly skilled and experienced Application Security Engineer to join our team at ProtonMail. As a key member of our security team, you will be responsible for ensuring the security and integrity of our applications and services.Your primary focus will be on performing penetration tests on our products, identifying...


  • Barcelona, Barcelona, España Automatic Data Processing, Inc. A tiempo completo

    Job Title: Lead Application Security EngineerSalary Range: $150,000 - $220,000 per yearAutomatic Data Processing, Inc. is seeking a highly skilled Lead Application Security Engineer to join our team. In this role, you will be responsible for leading the design, development, and maintenance of secure applications and systems.You will work closely with our...


  • Barcelona, España Oracle A tiempo completo

    Your role As a Senior Application Security Engineer, you will use data collected from a variety of information security tools and sources (including web application logs, intrusion detection system alerts, firewall and network traffic logs, and host system logs) to analyze events that occur within the enterprise, perform threat analysis, and improve our...


  • Barcelona, Barcelona, España Mygwork A tiempo completo

    At Mygwork, we're committed to creating a safe and trustworthy environment for our customers. As a Senior Application Security Specialist, you'll play a critical role in maintaining the security of our applications and services. Your expertise will help us identify and mitigate potential threats, ensuring the confidentiality, integrity, and availability of...

  • Security Engineer

    hace 1 día


    Barcelona, España Allianz A tiempo completo

    At Allianz Technology, our Information Security Operations team is the driving force behind our cybersecurity strategy, developing global solutions to protect Allianz from evolving threats. As part of this mission, Allianz Vulnerability Management (AVM) plays a key role in detecting, analyzing, and reporting vulnerabilities across business and technological...


  • Barcelona, Barcelona, España Protonmail A tiempo completo

    About ProtonProton is a technology company that aims to make privacy accessible to everyone. We are the creators of Proton Mail, a secure email service, and Proton VPN, a secure virtual private network.Job DescriptionWe are looking for a skilled Cybersecurity Expert to join our Security team at Proton. As a Cybersecurity Expert, you will be responsible for...


  • Barcelona, Barcelona, España Mygwork A tiempo completo

    Job Title: Senior Application Security SpecialistAbout the Role:We are seeking a highly skilled Senior Application Security Specialist to join our Product Security team. As a key member of the team, you will be responsible for leading incident investigations, coordinating with different teams, and ensuring a steady pace to the remediation of events.Key...


  • Barcelona, Barcelona, España Mygwork A tiempo completo

    Job SummaryWe are seeking a highly skilled Senior Application Security Specialist to join our Product Security team. As a key member of our team, you will be responsible for leading incident investigations, coordinating with different teams, and ensuring a steady pace to the remediation of events.Key ResponsibilitiesLead incident investigations and determine...