Security Engineer
Full Time
18 hours ago
Mid LevelEngineeringWorldwide
$80K - $120K

USD per year

Job Description

Security Engineer Job Description

About Us

  • Chess.com is one of the largest gaming sites globally and the #1 platform for playing, learning, and enjoying chess.
  • Team of 600+ fully remote people in 60+ countries.
  • Supports 250M+ chess players worldwide.
  • Tech, gaming, and content company with a mission-driven, flat, life-celebrating, no-corporate culture.

About The Role

  • Protect technology infrastructure and maintain security posture of the gaming platform.
  • Identify, assess, and mitigate security vulnerabilities.
  • Serve as a trusted security advisor to engineering teams.
  • Safeguard user data, maintain platform integrity.
  • Embed secure development practices throughout product development lifecycle.
  • Integrate security expertise into daily engineering operations and strategic decisions in a fast-paced remote-first environment.

What You'll Do

  • Lead vulnerability management program: triage, reproduce, assess vulnerabilities from Bug Bounty programs; work with engineering teams to prioritize and remediate.
  • Conduct comprehensive threat modeling with engineering teams to analyze solutions and identify attack vectors before implementation.
  • Manage security incident response: review penetration testing results and SIEM reports; translate findings into remediation tasks; track resolution progress.
  • Optimize security infrastructure: update Web Application Firewalls (WAF) and other systems; ensure configurations align with threat landscape and organizational needs.
  • Drive security tool evaluation and implementation: research, evaluate, recommend security software; attend vendor demos; lead procurement from requirements to deployment.
  • Provide security consultation and guidance: serve as subject matter expert to development teams; integrate best practices into software development lifecycle and architecture decisions.
  • Maintain security awareness and documentation: communicate updates, progress reports, recommendations to stakeholders; maintain current policies and procedures.

Qualifications

  • Bachelor's degree in Computer Science, Information Security or related field or equivalent experience.
  • Minimum 3+ years professional experience in web application security.
  • Expertise with security testing tools like Burp Suite or equivalent web request analysis/tampering tools.
  • Strong written communication skills in English; ability to explain technical concepts clearly to diverse audiences.
  • Experience working effectively in fully distributed/remote teams.
  • Proven cross-functional collaboration with engineering/development teams.

Preferred Skills and Qualifications

  • Hands-on experience managing or participating in Bug Bounty programs.
  • Programming experience in PHP or JavaScript.
  • Experience with penetration testing methodologies/tools.
  • Knowledge of SIEM platforms and security monitoring systems.
  • Familiarity with WAF configuration/management.
  • Understanding of secure software development lifecycle (SDLC) practices.
  • Experience with Jira or similar project management/issue tracking systems.
  • Strong sense of ownership/accountability in flat organizational structure.
  • Passion for continuous learning about evolving security threats/technologies.

About the Opportunity

  • Full-time position
  • 100% remote (work from anywhere)
How to Apply
About Chess.com

Chess.com is a leading online platform for playing chess, learning chess strategies, and connecting with a global community of chess enthusiasts.

View Company Profile