Rockstar Games
Senior Application Security Platform Engineer
Manhattan, New York, United States · Senior · Full-time
Sponsorship not specified$121k-$167kDetected 12 days ago
C++C#GitKubernetesTerraformCI/CDGitHub ActionsLinuxPlatform EngineeringLangGraphAI OrchestrationCybersecurityResearch
About the role
- This is a full-time, in-office position based out of Rockstar's NYC headquarters in Downtown Manhattan.
- HOW TO APPLY Please apply with a resume and cover letter demonstrating how you meet the skills above.
- If we would like to move forward with your application, a Rockstar recruiter will reach out to you to explain next steps and guide you through the process.
Responsibilities
- Architect and support secure software development lifecycle operations embedded in software development pipelines.
- Provide technical security guidance to developers, team leads, and producers.
- Drive remediation efforts behind internally and publicly identified vulnerabilities.
- The Rockstar Games Application Security team partners with numerous development teams across the company to incorporate security practices throughout the software development lifecycle.
- We independently assess our application code and builds through various techniques (static analysis, dynamic analysis, software composition analysis, etc.) to identify potential vulnerabilities and design flaws and work with development teams to remediate.
Requirements
- 5+ years of experience working in a professional, academic or research environment identifying and remediating security bugs/flaws, assisted by automated pipelines.
- Knowledge of common web security vulnerabilities (e.g., OWASP Top 10), client-side security landscape, attack techniques and remediation tactics/strategies.
- Experience implementing and tuning SAST, SCA, IaC and Secrets Detection tools effectively, especially fine-tuning static analysis detections with custom rule engines (CodeQL, Semgrep).
- Expertise deploying within CI/CD platforms (TeamCity or GitHub Actions) and container orchestration frameworks (e.g. Kubernetes), including establishing appropriate security controls in them
- Experience with both Windows and Linux operating systems.
- Proficiency in C#, Python.
- Please note that these are desirable skills and are not required to apply for the position.
- Familiarity with using Infrastructure as Code languages (Terraform, Pulumi) to deploy secure architecture.
- Experience enforcing security guardrails with Policy as Code (e.g. OPA) engines to existing and new CI/CD workflows.
- Experience in establishing CI/CD controls for cloud-native pipelines and runtime environments.
Compensation
- The pay range for this position in New York State (inclusive of New York City) at the start of employment is expected to be between the range below* per year.
Benefits
- We encourage applications from all suitable candidates regardless of age, disability, gender identity, sexual orientation, religion, belief, race, or any other protected category.
- Details of participation in these benefit plans will be provided if an employee receives an offer of employment.
Company info
- We strive to understand the threat landscape affecting our development studios, the gaming industry, and the world at large to define secure development standards and guidelines to safeguard our business and protect our players.
Equal opportunity
- equal opportunity, dignity and respect.
- If you need more information about Rockstar's reasonable accommodation policies or process, or need to request an accommodation, please notify your recruiter during the interview process.
Apply directly at Rockstar Games →Create a free account for alerts like thisView Rockstar Games immigration profile
This listing is sourced directly from Rockstar Games's careers page and normalized into a canonical job model.