04 ago
|
Scopely
|
Barcelona
ppES - Barcelona, Spain; ES - Spain; PT - Portugal /p pScopely is looking for a bPrincipal Security Engineer /b to join our Information Security team in Spain/Portugal on a hybrid basis. /p pOur security team is dedicated to ensuring the security of our top games. This involves collaborating closely with game studios to develop and implement comprehensive security strategies throughout the game design and development lifecycle. /p pIn addition, this role will drive the application of AI to transform how security is delivered across bProduct Security, Security Operations, and Security Engineering /b, improving efficiency, scalability, and impact. /p h3Game Product Security Leadership /h3 ul liPartner with game studios to develop comprehensive security strategies for game design and development /li liConduct threat modeling, vulnerability assessments, and security audits across all phases of game development /li liDesign and implement security controls and countermeasures to mitigate risks and ensure compliance with company policies, standards, and industry norms /li liCollaborate with game teams to advocate for secure coding practices and integrate security at every level of the software development lifecycle /li liCoordinate and participate in penetration tests and game feature security assessments /li liProvide expert-level technical guidance to game teams to assist in securing games and backend infrastructure /li liTranslate business priorities, technical constraints, and threat intelligence into actionable security roadmaps /li /ul h3AI-Driven Security Transformation Automation /h3 ul liIdentify and implement opportunities to apply AI to: /li liVulnerability triage, prioritization, and remediation /li liSecurity operations workflows (alert analysis, investigation, response) /li liProduct security processes (code analysis, findings analysis, pentesting support) /li liBuild AI-driven workflows, tools, and agents to reduce manual effort and improve speed and accuracy /li liUse AI to improve vulnerability management through triage support, risk classification, remediation guidance, and findings analysis /li liPartner with Security Operations to improve detection, triage, investigation and response through automation and AI-assisted analysis /li liIntegrate AI capabilities into existing security platforms (e.g., Wiz, SIEM, Jira, IAM systems)
/li liDevelop reusable AI-enabled components that scale across teams and studios /li liEstablish practical guardrails for the safe and effective use of AI in security, including data handling, quality control, and human review /li liDefine success metrics for AI-enabled workflows, including productivity gains, response times, remediation throughput, and signal quality /li /ul h3Security Engineering Platform Enablement /h3 ul liDesign and implement scalable security solutions across cloud and backend systems /li liWork closely with information security domain owners to ensure games adhere to all relevant security policies, standards, and regulatory requirements /li liDevelop and maintain comprehensive documentation on security architectures, processes, and decisions for technical and non-technical stakeholders /li liImprove security engineering efficiency through automation and tooling /li liStay updated with the latest security technologies, trends, threats, and AI capabilities, continuously improving security practices /li /ul h3Stakeholder Engagement Leadership /h3 ul liFrequently interact with game studio leaders to understand their roadmaps, risk posture, and how information security can enable them to execute their vision securely /li liDevelop security-related roadmaps in partnership with game teams /li liRegularly report to Information Security and Studio management on the threat landscape and security posture of games /li liAct as a thought leader using both qualitative and quantitative risk assessment frameworks /li liLead and/or assist in security incidents and investigations /li /ul h3What We're Looking For /h3 ul li8+ years of experience in Product Security, software development, or cybersecurity /li liProven track record in securing large-scale software applications and systems /li liStrong experience building automation and security tooling /li liHands‑on experience applying AI/LLMs to operational workflows, including designing, evaluating,
and safely deploying AI‑assisted systems is highly desirable /li liAbility to effectively communicate business risk and technical information clearly to both technical and non-technical audiences /li /ul h3Technical Expertise /h3 ul liExpertise in modern programming languages such as Python and C# /li liStrong understanding of: /li liApplication and product security /li liVulnerability management and pentesting methodologies /li liAPI and backend security /li liExperience with mobile application penetration testing, including traffic interception, runtime analysis and API security. /li liExperience with modern development ecosystems, CI/CD pipelines, APIs, and developer platforms. /li liStrong, hands‑on experience with cloud computing environments including: /li liAWS shared responsibility model /li liIAM and access control /li liNetwork security in the cloud /li liStrong understanding of securing cloud workloads including configuration, deployment, and auditing /li liDeep knowledge of Linux security practices /li /ul h3Additional Strengths /h3 ul liDemonstrated ability to think like both an attacker and defender /li liExperience architecting for and managing high‑scale, high‑velocity workloads in AWS preferred /li liFamiliarity with security frameworks (e.g., OWASP, NIST Cybersecurity Framework) and compliance regulations (e.g., GDPR, CCPA, ISO 27001) /li liExcellent analytical, problem‑solving, and decision‑making skills /li liExceptional communication and leadership skills, with the ability to influence across teams /li /ul h3Bonus Points /h3 ul liExperience applying AI to security, automation, or developer workflows /li liPrevious experience at a game company /li liFamiliarity with: /li liAI‑assisted code analysis or pentesting /li /ul pEmployment at Scopely is based solely on a person's merit and qualifications. Scopely does not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), or any other basis protected by law. We also consider qualified applicants with arrest or conviction records, consistent with applicable federal, state, and local law. /p /p #J-18808-Ljbffr
📌 Principal AI Product Security Engineer ES - Barcelona, Spain; ES - Spain; PT - Portugal
🏢 Scopely
📍 Barcelona