Senior Application Security Platform Engineer
Rockstar GamesAbout the role
<p>At Rockstar Games, we create world-class entertainment experiences. </p> <p>Become part of a team working on some of the most rewarding, large-scale creative projects to be found in any entertainment medium - all within an inclusive, highly-motivated environment where you can learn and collaborate with some of the most talented people in the industry.</p> <p>Rockstar is on the lookout for a passionate Senior Security Platform Engineer who is skilled at diving into complex software designs to identify security flaws and vulnerabilities.</p> <p>This is a full-time, in-office position based out of Rockstar’s NYC headquarters in Downtown Manhattan. </p> <h4><strong>WHAT WE DO</strong></h4> <ul> <li>The Rockstar Games Application Security team partners with numerous development teams across the company to incorporate security practices throughout the software development lifecycle.</li> <li>We strive to understand the threat landscape affecting our development studios, the gaming industry, and the world at large to define secure development standards and guidelines to safeguard our business and protect our players.</li> <li>We independently assess our application code and builds through various techniques (static analysis, dynamic analysis, software composition analysis, etc.) to identify potential vulnerabilities and design flaws and work with development teams to remediate.</li> </ul> <h4><strong>RESPONSIBILITIES</strong></h4> <ul> <li>Architect and support secure software development lifecycle operations embedded in software development pipelines.</li> <li>Provide technical security guidance to developers, team leads, and producers.</li> <li>Drive remediation efforts behind internally and publicly identified vulnerabilities.</li> </ul> <h4><strong>REQUIREMENTS</strong></h4> <ul> <li>5+ years of experience working in a professional, academic or research environment identifying and remediating security bugs/flaws, assisted by automated pipelines.</li> <li>Knowledge of common web security vulnerabilities (e.g., OWASP Top 10), client-side security landscape, attack techniques and remediation tactics/strategies.</li> <li>Experience implementing and tuning SAST, SCA, IaC and Secrets Detection tools effectively, especially fine-tuning static analysis detections with custom rule engines (CodeQL, Semgrep).</li> <li>Expertise deploying within CI/CD platforms (TeamCity or GitHub Actions) and container orchestration frameworks (e.g. Kubernetes), including establishing appropriate security controls in them</li> <li>Experience in establishing monitoring and observability techniques of build pipelines and their outputs.</li> <li>Experience with both Windows an
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s