Jobs›Application Security

Application Security Engineer

Enjoy Gaming LLC · Work from home
Work from home
PayPay not listed
WhereWork from home
TypeFull timeSenior
Posted6 OctYesterday, via Himalayas
Kaam checked
No fee, deposit or pay-to-apply signs
Good spoken and written English expected
Day work
No vehicle or licence needed
Skills they list12 named
Application Security EngineerSecurity EngineerPenetration TesterCybersecurity EngineerAppSec EngineerSenior Application Security EngineerLead Application Security EngineerApplication Security ArchitectApplication Security EngineeringApplication Security AnalystApplication Security SpecialistSoftware Security Engineer
About this job

Enjoy Gaming is a software provider focused on creating high-quality digital entertainment experiences, including Slots and Live Games. Our team brings together experienced professionals in game development, product, and design, driven by a passion for innovation and quality.

At Enjoy Gaming, we value ownership, excellence, and drive. These principles shape the way we work, collaborate, and build products.

Join us and be part of our innovative journey in the gaming world!

We’re looking for a sharp Application Security Engineer to join our team and act as the technical guardian for our games and platforms. If you have an attacker's mindset but know how to build and defend alongside engineering teams, this role is for you. In this position, you won’t just be sending reports to the teams or management. You’ll be diving deep into web and desktop applications, hunting down game-level vulnerabilities, and collaborating closely with our Architects, Studio, Slots, and Platform Developers to engineer more resilient systems.

Requirements

What we're looking for

5+ years of Application Security Engineer experience

Background in red teaming, penetration testing, application security, and software development

Able to independently find vulnerabilities in web and desktop applications, triage them, and, where needed, fix them

Solid grounding in data structures, algorithms, and systems architecture designs

Previous security testing experience with Kafka/Redis/BullMQ/PubSub as message/streaming tools

Codes independently, can navigate unfamiliar web application frameworks

Experience using AI tools to aid with vulnerability hunting

Comfortable talking to developers and turning findings into practical, actionable advice

Nice to have

CRTO, OSCP, or OSWE certifications or similar

Knowledge of Cloud Platforms (GCP/AWS)

Understanding of CI/CD pipelines

Hands-on experience with Trivy, Nessus, Acunetix, or Wiz

Experience in iGaming or another regulated industry

What You Will Do

Own and maintain our application security pipelines: SCA (Github/Trivy), DAST (Nessus, Acunetix, Wiz), and SAST

Triage findings from these tools and drive them to remediation

Perform penetration tests on new platform features, new internal applications, and new slots and live games

Run basic red team activities, including leaked credential reviews and external attack surface audits

Review complex auth flows with various third parties for cryptographic and security issues

Review/Triage application code for security issues ( 85% NestJS / 15% .NET )

Own security risk in existing code and applications

Act as the application-level security expert during incident response and be ready to deliver hotfixes yourself when needed

Prepare our quarterly SAST/DAST vulnerability scan reports for stakeholders/regulators and take part in audit meetings

Own the Secure Coding and Application Security areas of our ISMS

Meet regularly with development teams, learn about upcoming features early, and advise on secure design

What We Offer

Competitive Salary in EUR
with annual performance reviews to recognize your growth
Flexible Remote Work
balance productivity and comfort
Comprehensive Benefits
including medical insurance, psychologist support, and Polish, Slovak-speaking clubs

Generous Paid Time Off: 20 working days of paid vacation, plus 10 additional paid days off, 10 paid sick days, and all national holidays in your country

Professional Development Support: reimbursement for courses, trainings, and certifications

Well-being Perks
support for language classes, sports, massages, or life coaching

Please note that feedback on your application will be provided within two weeks if a positive decision is made regarding your candidacy.

I give my consent following the Law on the Protection of Personal Data dated June 1, 2010, No. 2297, effective from January 1, 2011, for the processing of information classified as personal data.

Originally posted on Himalayas

Never pay to get work. If a listing asks for a fee, it is a scam. The ten signs →

Apply on Himalayas
Opens himalayas.app in a new tab