gamedevjobs logo
Explore Jobs

Senior Application Security Engineer

Rockstar Games


Rockstar Games is seeking a Senior Application Security Engineer to identify security flaws and vulnerabilities in complex software designs. The successful candidate will work with development teams to incorporate security practices throughout the software development lifecycle, assess application code and builds, and remediate potential vulnerabilities and design flaws. The position requires a BSc/MSc in computer science or a related field, 5+ years of experience identifying and remediating security bugs/flaws, and extensive knowledge of common software security vulnerabilities and remediation tactics/strategies. The position is full-time and permanent, based in New York City, and offers a competitive salary and benefits package.

Job description

At Rockstar Games, we create world-class entertainment experiences.  

A career at Rockstar Games is about being part of a team working on some of the most creatively rewarding and ambitious projects to be found in any entertainment medium. You would be welcomed to a dedicated and inclusive environment where you can learn and collaborate with some of the most talented people in the industry.  

Rockstar is on the lookout for talented Senior Application Security Engineer who possess a passion for diving into complex software designs to identify security flaws and vulnerabilities. This is a full-time permanent position based out of Rockstar’s unique game development studio in the heart of New York City.  


  • The Rockstar Games Application Security team partners with numerous development teams across the company to incorporate security practices throughout the software development lifecycle.
  • We strive to understand the threat landscape affecting our development studios, the gaming industry, and the world at large to define secure development standards and guidelines to safeguard our business and protect our players.  
  • We independently assess our application code and builds through various techniques (static analysis, dynamic analysis, software composition analysis, etc.) to identify potential vulnerabilities and design flaws and work with development teams to remediate.   


  • Track trends in the security community and stay abreast of emerging threats.  
  • Provide technical security guidance to developers, team leads and producers.   
  • Engage development teams to identify security requirements for new products and features while ensuring other requirements don’t introduce an unintended security impact.  
  • Create threat models of new applications and features to systematically understand how they can be attacked in order to prioritize control development. 
  • Conduct automated and manual security assessments.  
  • Drive remediation efforts behind internally and publicly identified vulnerabilities. 
  • Support maintaining Rockstar Games’ public and private bug bounty programs.


  • BSc/MSc in a computer science or related field.  
  • Experience working in Agile development teams.
  • 5+ year(s) of experience working in a professional, academic or freelance environment (e.g. bug bounty) identifying and remediating security bugs/flaws. 
  • Experience in results-oriented, retail driven environment with strict deadlines and ship dates. 
  • Strong written and verbal communication skills.  


  • Extensive knowledge of common software security vulnerabilities (e.g., OWASP Top 10), attack techniques and remediation tactics/strategies. 
  • Understanding of the software development lifecycle (SDLC) and working knowledge of components to secure the SLDC.
  • Experience working in or establishing secure CI/CD pipelines and the concept of shifting security left in the SDLC.
  • Working knowledge of the principles and techniques for both manual and automated application security assessments.
  • Understanding of a variety of web technologies including: JSON, WebSockets, HTTP/2, DNS, RESTful APIs.


Please note that these are desirable skills and are not required to apply for the position.  

  • Experience with scripting and process automation.  
  • An understanding of effective practices for securing the SDLC that considers developer experience, sustainability and compliments release velocity.
  • Experience with penetration testing and offensive security tools and techniques,
    • e.g., Burp Suite, Metasploit, Wireshark. 
  • Proficiency in C++/C#/.NET and JavaScript preferred. 
  • Industry certifications preferred (CISSP, GSEC, OSCP, CEH, etc.). 


Please apply with a resume and cover letter demonstrating how you meet the skills above. If we would like to move forward with your application, a Rockstar recruiter will reach out to you to explain next steps and guide you through the process.

Rockstar is proud to be an equal opportunity employer, and we are committed to hiring, promoting, and compensating employees based on their qualifications and demonstrated ability to perform job responsibilities.

If you’ve got the right skills for the job, we want to hear from you. We encourage applications from all suitable candidates regardless of age, disability, gender identity, sexual orientation, religion, belief, or race.

The pay range for this position in New York City at the start of employment is expected to be between the range below* per year. However, base pay offered is based on market location, and may vary further depending on individualized factors for job candidates, such as job-related knowledge, skills, experience, and other objective business considerations. Subject to those same considerations, the total compensation package for this position may also include other elements, including a bonus and/or equity awards, in addition to a full range of medical, financial, and/or other benefits. Details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an "at-will position" and the company reserves the right to modify base salary (as well as any other discretionary payment or compensation or benefit program) at any time, including for reasons related to individual performance, company or individual department/team performance, and market factors.


*NYC Pay Range
$120,500—$168,700 USD

Location: Manhattan, New York, United States

Country: United States

Date found: 2023-04-29

If you're tired of sifting through endless job postings, try our AI-powered job search tool!

It's a game-changer.

Subscribe to all DevOps jobs in United States