Security Engineer, Application Security
Quick Summary
Application security Embed security into every phase of the SDLC Champion security
We believe in the life changing impact youth sports have on and off the field. Sports encourage leadership, teamwork, responsibility, and confidence – important life lessons that have the power to propel our youth toward meaningful futures. We recognize that without coaches, parents, and volunteers, organized youth sports could not exist. By building the first and best place to experience the youth sports moments important to our community, we are helping families elevate the next generation through youth sports.
So if you love sports and their community building potential, or building cool products is your sport, GameChanger is the team for you. We are a remote first, dynamic tech company based in New York City, and we are solving some of the biggest challenges in youth sports today.
We’re looking for a Security Engineer to join our InfoSec team and become the primary security partner for our software engineering organization. Reporting to the Security Engineering Manager, you’ll operate application security across the SDLC, champion secure design and development practices, and bring DevSecOps discipline to how we build and ship software. This is a high-impact, highly collaborative role. You’ll work closely with platform and product engineers to make security a part of how we build and deliver. You will also be a member of our weekly on-call rotation.
Responsibilities
~1 min readEmbed security into every phase of the SDLC
Champion security requirements for the responsible and secure integration of Gen AI and agentic AI tools within our product stack
Conduct security-by-design engagements for new features, APIs, platform initiatives, and infrastructure changes
Perform secure code reviews providing engineers with clear, actionable findings and remediation guidance
Partner with architecture and platform teams to establish secure API patterns (REST and GraphQL)
Contribute to and maintain secure coding guidelines, API security standards, and security architectural patterns that serve as the “paved roads” for all engineering teams
Give useful code review feedback, write documentation that outlasts the ticket, and run the occasional workshop or lunch-and-learn for engineers
Support the implementation of application-layer network security controls, such as Web Application Firewalls (WAFs) and CDN security, to protect application endpoints
Integrate and maintain security tooling across CI/CD pipelines
Operate the application vulnerability management lifecycle
Triage and prioritize findings from our sources (including; GHAS, NowSecure, Wiz, BugCrowd, penetration tests) by business impact and exploitability
Proactively identify systemic risks and facilitate cross-functional initiatives to address root causes
Track security-specific KPIs (e.g., MTTR, vulnerability density, and security coverage of CI/CD pipelines) and translate them into actionable insights for engineering and business leadership
Effectively communicate security risk clearly to both engineering and business leaders
3+ years in application security engineering with experience in mobile ecosystems (iOS/Android)
Proven experience building and operating internal security developer platforms or tooling that reduces developer friction
Demonstrated ability to use AI/ML-driven tools to enhance security effectiveness and scalability
Hands-on experience leading threat modeling engagements and designing paved roads
Proven track record integrating security tooling into CI/CD pipelines
Working knowledge of OWASP Top 10s (web, mobile, API, LLM)
Hands-on experience securing deployments in AWS with container and Kubernetes security, IaC scanning, and policy-as-code approaches
Demonstrated expertise in security-by-design in TypeScript, Swift, and/or Kotlin
Beneficial certifications: AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent.
Pragmatic defender. You understand that security must enable the business, not block it. You look for “secure by default” solutions and know how to make the right path the easy path for engineers.
Force multiplier. You don’t solve every security problem yourself. You coach, document, and build systems that make the engineers around you more secure by default.
Clear communicator. You can trace a BOLA vulnerability chain to a frontend engineer and translate the same risk into business terms for a VP; and you know which conversation you’re in.
Automation-first. If you have to do it twice, you’d rather write the script.
Long-view oriented. You think about medium-to-long-term system health, not just the current sprint, and you proactively address root causes rather than patching symptoms repeatedly.
Collaborative and cross-functional. You bring product, business, and operational context into your security decisions, not just security best practices in isolation.
Approachable. You foster open dialogue, encourage diverse perspectives, and make it easy for engineers to surface security concerns without fear of judgment or friction.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- September 22, 2026
- First seen
- September 25, 2026
- Last seen
- October 6, 2026
Posting Health
- Days active
- 10
- Repost count
- 0
- Trust Level
- 34%
- Scored at
- October 6, 2026
Signal breakdown
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.