PrizePicks is a sports betting company offering a fantasy platform where users can select players and teams to place bets on. With the mission of becoming the most loved fan engage
Senior AppSec Engineer
Location
United States
Posted
66 days ago
Salary
$130K - $180K / year
Seniority
Senior
Job Description
Senior AppSec Engineer
PrizePicks
• Own the Pipeline: Support and optimize application security tooling (SAST, SCA, Secrets Detection) within our CI/CD pipelines to provide accurate, actionable, and prioritized alerts to devs. • Be a Security Champion: Act as the primary security partner for Engineering and Product teams, ensuring security is baked in from the design phase through deployment. • Threat Modeling: Lead collaborative threat modeling exercises to identify architectural risks before code is even written. Partner with penetration testing teams to translate these threats into targeted testing scenarios for high-risk functions. • Code-Level Remediation: Don’t just tell devs what is wrong—show them how to fix it by performing deep-dive code reviews and providing actionable remediation guidance. • Secrets Management: Help lead the charge in identifying and removing hard-coded secrets, moving the org toward more secure, automated secret management practices. • Bug Bounty & Research: Help manage our bug bounty program by triaging submissions, working with researchers, and validating fixes with our engineers. • Secure AI Integration: Serve as the security consultant for AI/ML initiatives. Partner with engineering to design secure "LLM-backed" features, focusing on prompt injection prevention, data privacy/sanitization, and secure integration of third-party AI APIs. • Incident Response: Support the team during application-related security incidents, bringing your deep knowledge of code and logic to the table. • Feature Validation: Perform security assessments on new features to help identify logic flaws that automated scanners might miss. Partner with our penetration testing team on high-risk releases to exchange knowledge and continuously sharpen your offensive security skillset. • Strategic Communication: Translate technical vulnerabilities into business risk. You’ll be responsible for documenting and presenting findings in a way that is actionable for engineers and understandable for leadership.
Job Requirements
- 3+ years of experience in software development, mobile development, or application security. You are comfortable reading unfamiliar code and can speak Developer fluently.
- CI/CD Pipeline Expertise: Hands-on experience integrating security tools (SAST, DAST, SCA, Secrets Detection) into automated workflows (e.g., GitHub Actions, GitLab CI, Jenkins). You know how to tune these tools to prevent alert fatigue.
- Deep knowledge of the OWASP Web Security Testing Guide (WSTG) and/or Mobile Application Security Testing Guide (MASTG) and the ability to think like a threat actor.
- Experience conducting Threat Modeling to catch flaws before they are built.
- Familiarity with the OWASP Top 10 for LLMs. You understand the unique risks of integrating AI into a production stack and can advise on how to build guardrails around model inputs and outputs.
- Experience supporting an Incident Response (IR) process, specifically providing the AppSec perspective to help scope an exploit and verify if a patch truly mitigates it.
- A deep understanding of how web applications work. You know your way around HTTP headers, JWTs, CORS, and auth flows, and you can validate them manually when the scanners fail.
- Proven ability to define risks in both technical and business terms.
Benefits
- Company-subsidized medical, dental, & vision plans
- 401(k) plan with company match
- Annual bonus
- Flexible PTO to encourage a healthy work/life balance (2 weeks STRONGLY encouraged!)
- Generous paid leave programs, including 16-week paid parental leave and disability benefits
- Workplace flexibility and modern work schedules focused on getting the job done, not hours clocked
- Company-wide in-person events and team outings
- Lifestyle enhancement program
- Company equipment provided (Windows & Mac options)
- Annual performance reviews with opportunities for growth and career development
Related Guides
Related Categories
Related Job Pages
More Engineer Jobs
• Develop and operate robust, scalable, and secure network solutions • Responsible for the design, deployment, and operation of high-security network infrastructures • Plan customized network setups in close collaboration with customers • Configure and optimize complex routing scenarios using BGP, MPLS, and IPv6 • Develop and maintain automation for efficient updates • Perform fault analysis and continuously improve monitoring to ensure high availability
Engineer – HPC Platform
Xenon SevenHuman Experts Implementing Artificial Intelligence #AI #ArtificialIntelligence #HumanIntelligence
**What You’ll Be Doing** - You will be a leader the engineering and operations of design, build, and maintain scalable HPC platforms. - You will play a crucial role in enabling HPC infrastructure and experiences. - Collaborate with researchers and scientists to optimize performance and streamline workflows. - Leverage tooling and automation for orchestration, resource scheduling, data access, and reproducibility. - Evolve and operate public cloud and on-premises environments with a focus on availability and performance for HPC workloads. - Define and monitor infrastructure metrics, resource utilization, among others.
Engineer – HPC Platform
Xenon SevenHuman Experts Implementing Artificial Intelligence #AI #ArtificialIntelligence #HumanIntelligence
• You will be a leader the engineering and operations of design, build, and maintain scalable HPC platforms. • You will play a crucial role in enabling HPC infrastructure and experiences. • Collaborate with researchers and scientists to optimize performance and streamline workflows. • Leverage tooling and automation for orchestration, resource scheduling, data access, and reproducibility. • Evolve and operate public cloud and on-premises environments with a focus on availability and performance for HPC workloads. • Define and monitor infrastructure metrics, resource utilization, among others.
• Collaborate with multiple teams to ensure data integrity and validation using the right tools and automation. • Be proficient in pre-screening raw data, vital checks on completeness and integrity of data, field tests on Aggregation, Reconciliation tests and Report testing. • Evaluate the quality of data received from data sources to ensure that it meets company standards. • Review Data Models, Data Mappings, and Architectural Documentation to execute effective system integration testing. • Work closely with Business Analysts, Architects, Development team and Product Owners to ensure data housed in multiple source systems is loaded to target accurately. • Develops validation scripts for automated execution, while creating actionable data quality reports that measure trends over time. • Build new scripts and troubleshoot existing scripts. • Solve complex record and run issues including complex correlation problems. • Verify and validate data accuracy, completeness, and consistency using Extract/Transform/Load (ETL) tools and SQL queries. • Analyzes and troubleshoots erroneous results, determines the root cause of defects, logs the defects JIRA/QTest and enables defect management, including working with the development team on the resolution of Software related defects. • Drive opportunities and lead efforts to improve existing test processes or create new to increase efficiency and productivity in test case development, scheduling, or deployment. • Analyze test results and prioritize and log defects with appropriate information. • Manage multiple projects/deadlines with changing priorities. • Other duties as assigned.


