Chess.com logo
Chess.com
Posted 5 days agoVerified live 1d ago

Security Engineer

Brief overview

Remote
UndergradOr in progress
3+ yrsMinimum
Web Application SecurityBurp SuiteVulnerability ManagementThreat ModelingBug Bounty ProgramsPenetration TestingSecurity Information and Event Management (SIEM)Web Application Firewall (WAF) ConfigurationSecure Software Development Lifecycle (SDLC)PHPJavaScriptJira

About the company

Chess.com logo
Chess.comchess.com

Chess.com is an online community for chess players to learn and discuss strategy and play with others in real-time.

Job description

Summary

Chess.com is a global gaming and technology company focused on providing a platform for playing, learning, and enjoying chess. The Security Engineer will protect the technology infrastructure and gaming platform by identifying and mitigating vulnerabilities, managing security incidents, and advising engineering teams on secure development practices. The role also involves optimizing security infrastructure, evaluating security tools, and maintaining security documentation and awareness.

Responsibilities

  • Lead vulnerability management program by triaging, reproducing, and assessing security vulnerabilities submitted through Bug Bounty programs, working directly with engineering teams to prioritize and remediate discovered security gaps
  • Conduct comprehensive threat modeling by collaborating with engineering teams to analyze proposed solutions, ensuring designs meet security industry standards and identifying potential attack vectors before implementation
  • Manage security incident response by reviewing penetration testing results and SIEM reports, translating technical findings into actionable remediation tasks, and tracking resolution progress through completion
  • Optimize security infrastructure by applying updates to Web Application Firewalls (WAF) and other security systems, ensuring configurations align with current threat landscape and organizational needs
  • Drive security tool evaluation and implementation by researching, evaluating, and recommending security software solutions, attending vendor demonstrations, and leading procurement processes from requirements gathering through deployment
  • Provide security consultation and guidance by serving as subject matter expert to development teams, ensuring security best practices are integrated into software development lifecycle and architectural decisions
  • Maintain security awareness and documentation by communicating security updates, progress reports, and recommendations to stakeholders through established channels and maintaining current security policies and procedures

Skills

  • Bachelor's degree in Computer Science, Information Security, or related technical field, or equivalent professional experience
  • Minimum 3+ years of professional experience specifically in web application security
  • Demonstrated expertise with security testing tools such as Burp Suite or equivalent web request analysis and tampering tools
  • Strong written communication skills in English with ability to clearly explain technical security concepts to diverse audiences
  • Experience working effectively in fully distributed/remote team environments
  • Proven ability to collaborate cross-functionally with engineering and development teams
  • Previous hands-on experience managing or participating in Bug Bounty programs
  • Programming experience in PHP or JavaScript
  • Experience with penetration testing methodologies and tools
  • Knowledge of SIEM platforms and security monitoring systems
  • Familiarity with Web Application Firewall (WAF) configuration and management
  • Understanding of secure software development lifecycle (SDLC) practices
  • Experience with Jira or similar project management and issue tracking systems
  • Strong sense of ownership and accountability in a flat organizational structure
  • Passion for continuous learning and staying current with evolving security threats and technologies

Qualifications

Must Haves

  • Bachelor's degree in Computer Science, Information Security, or related technical field, or equivalent professional experience
  • Minimum 3+ years of professional experience specifically in web application security
  • Demonstrated expertise with security testing tools such as Burp Suite or equivalent web request analysis and tampering tools
  • Strong written communication skills in English with ability to clearly explain technical security concepts to diverse audiences
  • Experience working effectively in fully distributed/remote team environments
  • Proven ability to collaborate cross-functionally with engineering and development teams

Nice to Haves

  • Previous hands-on experience managing or participating in Bug Bounty programs
  • Programming experience in PHP or JavaScript
  • Experience with penetration testing methodologies and tools
  • Knowledge of SIEM platforms and security monitoring systems
  • Familiarity with Web Application Firewall (WAF) configuration and management
  • Understanding of secure software development lifecycle (SDLC) practices
  • Experience with Jira or similar project management and issue tracking systems
  • Strong sense of ownership and accountability in a flat organizational structure
  • Passion for continuous learning and staying current with evolving security threats and technologies

Benefits

  • 100% remote (work from anywhere!)

More jobs like this