AppSec Engineer

Penn Interactive • Philadelphia, PA

Company

Penn Interactive

Location

Philadelphia, PA

Type

Full Time

Job Description

Penn Interactive (PI) is an interactive gaming company headquartered in Philadelphia. PI is the digital arm of PENN Entertainment (NASDAQ: PENN), the largest regional casino operator in the U.S.). Our mission is to challenge the norms of the gaming industry by building an immersive interactive gaming experience that is responsible, innovative, and fun. We are committed to helping our team members grow and succeed.  We believe that hiring talented individuals that love what they do will help us win!

About the Role & Team
As part of the theScore team, you will be working with a team of smart, friendly, and dedicated Engineers, Product Managers and Designers determined to deliver some of the best apps the market has to offer. We want you to be challenged and to get the full experience of what it’s like to work at theScore! We are looking for an Application Security Engineer to join our Application Security team, to work cross-functionally across engineering. They are also a sister team to the Site Reliability Engineering team. This role will be responsible for designing, servicing, and implementing security measures to secure theScore’s software systems, applications, code, and any related components.

About the Work

  • Collaborate with release and change management, SRE, Engineering, and compliance teams
  • Work with security/internal/external/state auditors to demonstrate compliance
  • Maintain a working knowledge of OWASP top 10 and MITRE top 25 CWE
  • Develop standards for security tooling focused on the application layer (SAST, DAST, SCA, MAST, RASP)
  • Build/implement secure artifact workflows in the SDLC to ensure governance and compliance standards are being met
  • Create technical approaches to implementing Application Security control technologies
  • Contribute to theScore’s Application Security program to support our continued growth
  • Define and report on security metrics, their delivery, and improvements
  • Work with service teams to conduct threat models of theScore’s internal and customer facing applications
  • Assist service teams in understanding and remediating security findings (code bashing)
  • Other duties as required.

About You

  • 3+ years of Application Security or DevSecOps experience
  • 2+ years of GCP or AWS experience
  • Experience with software supply chain security (SBOMs, Artifact Signing, Attestations)
  • Programming experience in Python or Go
  • Experience with implementing security tooling in CI/CD
  • Experience supporting RESTful APIs and securing containerized workloads (GKE, EKS)
  • Experience working in regulated environments (PCI-DSS, SOC 2, etc)
    #LI-HYBRID

https://www.linkedin.com/company/penn-interactive-pi/

Recently being recognized as a top workplace in the United States, we believe people work their best when they can be themselves. We are looking for hungry, innovative thinkers to help us challenge the status quo of the gaming industry.  Diversity, equity, and inclusion are vital to all of our processes, programs, and structures. Your story, who you are, and your experience matter here.

Apply Now

Date Posted

03/13/2024

Views

6

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Software Engineer - JPMorganChase

Views in the last 30 days - 0

The job description outlines a role that involves designing developing and implementing software solutions to solve business problems The role encompa...

View Details

Enterprise Engineer Sr - Akami Security Suite - The PNC Financial Services Group

Views in the last 30 days - 0

PNC is seeking an Enterprise Engineer Sr with expertise in Akamai Security Suite to manage configure and optimize security solutions The role involves...

View Details

Data Engineer Senior - Data and Automation (Hadoop, Google Cloud, Pyspark, Python, SQL) - The PNC Financial Services Group

Views in the last 30 days - 0

PNC is seeking a Data Engineer Senior to join their Data and Automation organization The role involves architecting developing testing and optimizing ...

View Details

Senior Software Engineer-Java/React/SQ - The PNC Financial Services Group

Views in the last 30 days - 0

PNC is seeking a Senior Software Engineer with 3 years of experience in full stack engineering The role involves detailed technical design and develop...

View Details

Software Engineer Sr-Python/Ansible/React/SQL - The PNC Financial Services Group

Views in the last 30 days - 0

PNC is seeking a Senior Software Engineer for a position based in one of its technology hubs The role involves providing detailed technical design and...

View Details

Infrastructure Engineer Sr. SD-WAN Focus - The PNC Financial Services Group

Views in the last 30 days - 0

PNC is seeking a Network Engineer with extensive knowledge in routing protocols SDWAN and data networking engineering The role involves designing buil...

View Details