AppSec Engineer

theScore • North Jersey

Company

theScore

Location

North Jersey

Type

Full Time

Job Description

theScore, a wholly-owned subsidiary ofĀ PENN EntertainmentĀ , empowers millions of sports fans through its digital media and sports betting products. Its media app ā€˜theScore’ is one of the most popular in North America, delivering fans highly personalized live scores, news, stats, and betting information from their favorite teams, leagues, and players.Ā theScore’s sports betting app ā€˜theScore Bet Sportsbook & Casino’ delivers an immersive and holistic mobile sports betting and iCasino experience. theScore Bet is currently live in the Company's home province of Ontario.Ā theScore also creates and distributes innovative digital content through its web, social and esports platforms.

About the Role & Team
As part of the theScore team, you will be working with a team of smart, friendly, and dedicated Engineers, Product Managers and Designers determined to deliver some of the best apps the market has to offer. We want you to be challenged and to get the full experience of what it’s like to work at theScore! We are looking for an Application Security Engineer to join our Application Security team, to work cross-functionally across engineering. They are also a sister team to the Site Reliability Engineering team. This role will be responsible for designing, servicing, and implementing security measures to secure theScore’s software systems, applications, code, and any related components.

About the Work

  • Collaborate with release and change management, SRE, Engineering, and compliance teams
  • Work with security/internal/external/state auditors to demonstrate compliance
  • Maintain a working knowledge of OWASP top 10 and MITRE top 25 CWE
  • Develop standards for security tooling focused on the application layer (SAST, DAST, SCA, MAST, RASP)
  • Build/implement secure artifact workflows in the SDLC to ensure governance and compliance standards are being met
  • Create technical approaches to implementing Application Security control technologies
  • Contribute to theScore’s Application Security program to support our continued growth
  • Define and report on security metrics, their delivery, and improvements
  • Work with service teams to conduct threat models of theScore’s internal and customer facing applications
  • Assist service teams in understanding and remediating security findings (code bashing)
  • Other duties as required.

About You

  • 3+ years of Application Security or DevSecOps experience
  • 2+ years of GCP or AWS experience
  • Experience with software supply chain security (SBOMs, Artifact Signing, Attestations)
  • Programming experience in Python or Go
  • Experience with implementing security tooling in CI/CD
  • Experience supporting RESTful APIs and securing containerized workloads (GKE, EKS)
  • Experience working in regulated environments (PCI-DSS, SOC 2, etc)
    #LI-Hybrid

Ā 

Ā 

theScore is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability or age.

Ā 

Apply Now

Date Posted

03/13/2024

Views

4

Back to Job Listings ā¤ļøAdd To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Product Support Engineer - SPHERE

Views in the last 30 days - 0

SPHERE Technology Solutions is hiring a Product Support Engineer to provide technical support and guidance to clients and product stakeholders The rol...

View Details

C++ and JUCE Audio Developer - Art+Logic

Views in the last 30 days - 0

ArtLogic a custom software development company founded in 1991 is seeking a Software Audio Engineer for longterm projects The ideal candidate should h...

View Details

Senior Data Scientist - Data Products (LLMs) - Wealthsimple

Views in the last 30 days - 0

Wealthsimple a leading Canadian fintech company is seeking a Data Scientist with expertise in Natural Language Processing Reinforcement Learning and L...

View Details

Project Cost Engineer (00402) - PMA Consultants

Views in the last 30 days - 0

PMA is seeking a Project Cost Engineer for a hybrid role involving database management project management cost controls and client relationship manage...

View Details

Senior Software Engineer - Canonical

Views in the last 30 days - 0

Canonical a leading provider of open source software and operating systems is seeking open source enthusiasts to join their Ubuntu Engineering Server ...

View Details

Software Engineer - packaging - optimize Ubuntu Server for public clouds - Canonical

Views in the last 30 days - 0

Canonical a leading provider of open source software and operating systems is seeking enthusiastic engineers to work on the Ubuntu distribution for pu...

View Details