3h ago
New

Principal Appsec Engineer

EngineeringSecurity Engineer
0 views0 saves0 applied

Quick Summary

Overview

We are on a mission to pioneer the world’s next era of play. As we grow across Europe and Latin America, we’re building The Playstack - the technology powering the next generation of sports, gaming,

Technical Tools
EngineeringSecurity Engineer

We are on a mission to pioneer the world’s next era of play. As we grow across Europe and Latin America, we’re building The Playstack - the technology powering the next generation of sports, gaming, and fan experiences. Join us, and help make it the most widely used platform in the world! From operations, to marketing, to product, we are looking for talented people who will shape how millions of customers play, watch, and connect every day.

Product Security is responsible for preventing vulnerabilities before code ships, absorbing on-demand security-testing load, and making security testing part of everything that reaches production. This role owns the team's deep offensive capability, running adversary emulation and bypass testing against production systems and providing the technical depth behind the team's hardest architecture reviews. Reporting to the Product Security Lead, the Principal AppSec Engineer sets the bar for pentest quality that engineers execute against.
 
What the role involves
  • Run adversary emulation and bypass testing against production systems to identify exploitable weaknesses.
  • Own the standardised pentest playbooks used for urgent "launching next week" requests and personally handle the highest-complexity engagements.
  • Lead in-depth architecture and design reviews for high-risk features, threat-modelling before code is written and producing security requirements and sign-off.
  • Mature and scale AI-assisted pentest tooling (e.g. NEO, regression code scanning) to increase testing coverage.
  • Mentor less experienced AppSec engineers in pentest methodology and adversarial thinking.
  • Feed confirmed bypass and pentest findings to Detection Engineering & Threat Hunting so each becomes a shipped detection.
  • Contribute to the vendor security testing element of the shared vendor intake process for high-risk vendors.
What we are looking for
  • 6+ years' experience in offensive security — pentesting, red teaming, or adversary emulation — ideally including production/live-environment experience.
  • Strong architecture review skills, with the ability to threat-model a system from a design document rather than only testing a finished build.
  • Familiarity with the modern AppSec tooling landscape (SAST/DAST, AI-assisted pentest tools).
  • Comfortable acting as the technical escalation point for the team's hardest problems.
Nice to have
  • Experience running or contributing to bug bounty triage or vulnerability-disclosure programmes.
What we offer
  • Medical / Health Insurance
  • Open Annual Leave
  • Employee Assistance Programme
  • Training & Learning Development

We are a global technology group, dedicated to building the future of entertainment and fan-centric experiences. With commercial markets in Brazil, Belgium, Poland, Romania, Greece and Serbia, and a network of offices across Spain, Croatia, Malta, Gibraltar, the Netherlands and the UK, we are a truly international organization. Our purpose at Super has evolved from sports and betting into creating the platform that stretches into the wider world of technology-driven entertainment. With a growing and diverse team of more than 5,000 people, we create immersive, responsible, and personalised experiences for millions of customers worldwide.

Everything we do at Super is rooted in doing what is right: for customers, for each other, and for our long-term vision. Our Culture Manifesto is our North Star. It captures our purpose, mission, and the six core beliefs that shape how we think, make decisions, and act every day. Want to explore our culture in more detail? Visit our careers page: super.xyz/careers 

Super is committed to the highest standards of compliance, safety, and responsibility. As such, we are active members of the International Betting Integrity Association (IBIA) and the European Gaming & Betting Association (EGBA).

At Super, we operate as a high-performing team. We hire and grow talent based on ability and potential, regardless of background and identity because we know diverse perspectives, drive better performance.

Location & Eligibility

Where is the job
Croatia
On-site within the country
Who can apply
Open to applicants worldwide

Listing Details

Posted
September 29, 2026
First seen
September 29, 2026
Last seen
September 29, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
60%
Scored at
September 29, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Principal Appsec Engineer