The ideal candidate is a seasoned security leader with deep expertise in application security, hands-on familiarity with secure game development practices, and a forward-looking mindset around emerging technologies, including modern code development and AI tools. You will work cross-functionally with engineering, platform, DevOps, and external studios to implement a comprehensive Secured Game Development Lifecycle (SGDLC).
Key Responsibilities
Build and Scale a Modern Application Security Program
- Architect and drive the implementation of secure-by-design principles across CI / CD pipelines, game engines (Unity, Unreal), APIs, and cloud-native environments.
- Integrate security tooling (SAST, DAST, SCA) into developer workflows and automate remediation where possible.
- Establish scalable policies and controls to govern secure coding, build validation, and deployment.
- Lead Partner Studio Security and Governance
- Develop and operationalize a comprehensive governance model for 2nd and 3rd party studios.
- Conduct regular security assessments, establish KPIs, and monitor compliance with contractual security obligations.
- Drive Threat Modeling and Product Risk Management
- Embed threat modeling, privacy review, and risk profiling into the product lifecycle.
- Partner with game and platform teams to ensure security architecture reviews are standard practice.
- Oversee Security Validation and Incident Preparedness
- Implement security testing frameworks for staging and production (including pen testing and dynamic scanning).
- Collaborate with incident response teams to ensure readiness across digital platforms and gaming services.
- Promote a Culture of Developer-Centric Security
- Establish a Security Champions program to extend security best practices into feature and game teams.
- Deliver SSDLC training and provide coaching to internal teams, contingent workers, and external developers.
- Lead Security Tooling Strategy and Technical Partnerships
- Define and execute the tooling roadmap across platforms, including Snyk, Veracode, Coverity, Tenable, Orca, Expel, Splunk, and Sumologic.
- Collaborate with DevOps and infrastructure teams to align security with infrastructure-as-code and serverless architectures.
Qualifications
10+ years of experience in Application / Product Security, including 5+ years in the gaming or interactive entertainment industry.
Expert knowledge of secure game development, including Unity, Unreal, Perforce, and game SDKs.Deep understanding of CI / CD, containerization, cloud security (AWS), and infrastructure-as-code principles.Demonstrated experience working with third-party development studios and overseeing console platform integrations.Hands-on expertise with Generative AI tools secure code assistants, AI copilots, and agentic solutions) in a software development context.Strong command of modern collaboration tools : Jira, Slack, Confluence, Miro, SmartSheet.Proven leadership and communication skills, with the ability to influence technical and non-technical stakeholders.Proven track record of 5+ years of leading and growing security teams in a highly collaborative and matrixed organization.#Wizards
Nearest Major Market : Seattle
Nearest Secondary Market : Bellevue
Job Segment : Embedded, Developer, Cloud, Testing, PLM, Technology, Management