appsec engineer
14 hours ago
Barcelona
Scopely is a global video game and interactive entertainment company that creates, develops, publishes, and live-operates games across mobile, web, PC, and console. Its portfolio includes MONOPOLY GO!, Pokémon GO, Stumble Guys, Star Trek™ Fleet Command, MARVEL Strike Force, and other games, supported by the proprietary Playgami technology platform. • Partner with game studios to develop comprehensive security strategies for game design and development;, • Conduct threat modeling, vulnerability assessments, and security audits across all phases of game development;, • Design and implement security controls and countermeasures to mitigate risks and ensure compliance with company policies, standards, and industry norms;, • Collaborate with game teams to advocate for secure coding practices and integrate security throughout the software development lifecycle;, • Coordinate and participate in penetration tests and game feature security assessments;, • Provide expert-level technical guidance to game teams securing games and backend infrastructure;, • Translate business priorities, technical constraints, and threat intelligence into actionable security roadmaps;, • Identify and implement AI opportunities for vulnerability management, security operations, and product security processes;, • Build AI-driven workflows, tools, and agents to reduce manual effort and improve speed and accuracy;, • Use AI to support vulnerability triage, risk classification, remediation guidance, and findings analysis;, • Partner with Security Operations to improve detection, triage, investigation, and response through automation and AI-assisted analysis;, • Integrate AI capabilities into security platforms such as Wiz, SIEM, Jira, and IAM systems;, • Develop reusable AI-enabled components that scale across teams and studios;, • Establish guardrails for safe and effective AI use in security, including data handling, quality control, and human review;, • Define success metrics for AI-enabled workflows, including productivity gains, response times, remediation throughput, and signal quality;, • Design and implement scalable security solutions across cloud and backend systems;, • Work with information security domain owners to ensure games follow relevant security policies, standards, and regulatory requirements;, • Develop and maintain documentation on security architectures, processes, and decisions for technical and non-technical stakeholders;, • Improve security engineering efficiency through automation and tooling;, • Stay updated on security technologies, trends, threats, and AI capabilities;, • Interact with game studio leaders to understand roadmaps, risk posture, and how information security can support secure execution;, • Develop security-related roadmaps with game teams;, • Report to Information Security and Studio management on the threat landscape and security posture of games;, • Act as a thought leader using qualitative and quantitative risk assessment frameworks;, • Lead or assist with security incidents and investigations., • 8+ Years of experience in Product Security, software development, or cybersecurity;, • Proven experience securing large-scale software applications and systems;, • Strong experience building automation and security tooling;, • Hands-on experience applying AI/LLMs to operational workflows, including designing, evaluating, and safely deploying AI-assisted systems;, • Ability to communicate business risk and technical information clearly to technical and non-technical audiences;, • Expert knowledge of modern programming languages such as Python and C#;, • Strong understanding of application and product security, vulnerability management, and penetration testing methodologies;, • Strong understanding of API and backend security;, • Experience with mobile application penetration testing, including traffic interception, runtime analysis, and API security;, • Experience with modern development ecosystems, CI/CD pipelines, APIs, and developer platforms;, • Hands-on experience with AWS shared responsibility, IAM, access control, and cloud network security;, • Strong understanding of securing cloud workloads through configuration, deployment, and auditing;, • Deep knowledge of Linux security practices;, • Ability to think like both an attacker and defender;, • Excellent analytical, problem-solving, and decision-making skills;, • Exceptional communication and leadership skills with the ability to influence across teams;, • Nice to have: Experience architecting and managing high-scale, high-velocity workloads in AWS, familiarity with OWASP, NIST Cybersecurity Framework, GDPR, CCPA, and ISO 27001, experience at a game company, experience applying AI to security, automation, or developer workflows, familiarity with RAG architectures, vector databases such as pgvector, and AI-assisted code analysis or pentesting. Hybrid role based in Barcelona, Catalonia, Spain, with the security team covering Spain and Portugal; No conditions specified. #J-18808-Ljbffr