Описание
Scopely is a integral video game and interactive entertainment company that creates, develops, publishes, and live-operates games across mobile, web, PC, and console. Its portfolio includes MONOPOLY GO!, Pokémon GO, Stumble Guys, Star Trek™ Fleet Command, MARVEL Strike Force, and other games, supported by the proprietary Playgami technology platform. Задачи
Partner with game studios to develop comprehensive security strategies for game design and development; Conduct threat modeling, vulnerability assessments, and security audits across all phases of game development; Design and implement security controls and countermeasures to mitigate risks and ensure compliance with company policies, standards, and industry norms; Collaborate with game teams to advocate for secure coding practices and integrate security throughout the software development lifecycle; Coordinate and participate in penetration tests and game feature security assessments; Provide expert-level technical guidance to game teams securing games and backend infrastructure; Translate business priorities, technical constraints, and threat intelligence into actionable security roadmaps; Identify and implement AI opportunities for vulnerability management, security operations, and product security processes; Build AI-driven workflows, tools, and agents to reduce manual effort and improve speed and accuracy; Use AI to support vulnerability triage, risk classification, remediation guidance, and findings analysis; Partner with Security Operations to improve detection, triage, investigation, and response through automation and AI-assisted analysis; Integrate AI capabilities into security platforms such as Wiz, SIEM, Jira,
and IAM systems; Develop reusable AI-enabled components that scale across teams and studios; Establish guardrails for safe and effective AI use in security, including data handling, quality control, and human review; Define success metrics for AI-enabled workflows, including productivity gains, response times, remediation throughput, and signal quality; Design and implement scalable security solutions across cloud and backend systems; Work with information security domain owners to ensure games follow relevant security policies, standards, and regulatory requirements; Develop and maintain documentation on security architectures, processes, and decisions for technical and non-technical stakeholders; Improve security engineering efficiency through automation and tooling; Stay updated on security technologies, trends, threats, and AI capabilities; Interact with game studio leaders to understand roadmaps, risk posture, and how information security can support secure execution; Develop security-related roadmaps with game teams; Report to Information Security and Studio management on the threat landscape and security posture of games; Act as a thought leader using qualitative and quantitative risk assessment frameworks; Lead or assist with security incidents and investigations. Требования
8+ Years of experience in Product Security, software development,
or cybersecurity; Proven experience securing large-scale software applications and systems; Strong experience building automation and security tooling; Hands-on experience applying AI/LLMs to operational workflows, including designing, evaluating, and safely deploying AI-assisted systems; Ability to communicate business risk and technical information clearly to technical and non-technical audiences; Expert knowledge of modern programming languages such as Python and C#; Strong understanding of application and product security, vulnerability management, and penetration testing methodologies; Strong understanding of API and backend security; Experience with mobile application penetration testing, including traffic interception, runtime analysis, and API security; Experience with modern development ecosystems, CI/CD pipelines, APIs, and developer platforms; Hands-on experience with AWS shared responsibility, IAM, access control, and cloud network security; Strong understanding of securing cloud workloads through configuration, deployment, and auditing; Deep knowledge of Linux security practices; Ability to think like both an attacker and defender; Excellent analytical, problem-solving, and decision-making skills; Exceptional communication and leadership skills with the ability to influence across teams; Nice to have: Experience architecting and managing high-scale, high-velocity workloads in AWS, familiarity with OWASP, NIST Cybersecurity Framework, GDPR, CCPA, and ISO 27001, experience at a game company, experience applying AI to security, automation, or developer workflows, familiarity with RAG architectures, vector databases such as pgvector, and AI-assisted code analysis or pentesting. Условия
Hybrid role based in Barcelona, Catalonia, Spain, with the security team covering Spain and Portugal; No conditions specified.
#J-18808-Ljbffr
📌 appsec engineer (Madrid)
🏢 Enfint
📍 Madrid