Security Engineer at Chess
Job Description
About Chess.com
Join Chess.com, one of the world's largest gaming sites and the premier platform for playing, learning, and enjoying chess. We are a global team of over 600 fully remote individuals across 60+ countries, dedicated to serving the worldwide chess community. Our mission is to support more than 250 million chess players with the best possible product, content, and tools. We are a passionate tech, gaming, and content company committed to the game, valuing our mission driven, flat, life celebrating, and no corporate culture.
About The Role
As a Security Engineer at Chess.com, you will play a critical role in safeguarding our technology infrastructure and enhancing the security posture of our dynamic gaming platform. This position focuses on proactively identifying, assessing, and mitigating security vulnerabilities, while also serving as a trusted security advisor to various engineering teams. Your work will directly contribute to protecting user data, maintaining platform integrity, and embedding secure development practices throughout our product development lifecycle. This role is essential for building and sustaining robust security defenses within our fast paced, remote first technology environment, ensuring security expertise is integrated into daily operations and strategic decisions.
Key Responsibilities
- Lead the vulnerability management program by triaging, reproducing, and assessing security vulnerabilities identified through Bug Bounty programs, collaborating with engineering teams for prioritization and remediation.
- Conduct comprehensive threat modeling in partnership with engineering teams to analyze proposed solutions, ensuring designs meet industry security standards and identifying potential attack vectors early.
- Manage security incident response by reviewing penetration testing results and SIEM reports, translating technical findings into actionable remediation tasks, and tracking resolution through completion.
- Optimize security infrastructure through timely updates to Web Application Firewalls (WAF) and other security systems, aligning configurations with the current threat landscape and organizational requirements.
- Drive security tool evaluation and implementation by researching, evaluating, and recommending security software solutions, leading vendor demonstrations, and managing procurement processes from requirements to deployment.
- Provide expert security consultation and guidance to development teams, ensuring security best practices are integrated into the software development lifecycle and architectural decisions.
- Maintain security awareness and documentation by communicating security updates, progress reports, and recommendations to stakeholders, and keeping current security policies and procedures up to date.
Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent professional experience.
- Minimum of 3+ years of professional experience specifically in web application security.
- Demonstrated expertise with security testing tools such as Burp Suite or similar web request analysis and tampering tools.
- Strong written communication skills in English, with the ability to clearly explain complex technical security concepts to diverse audiences.
- Proven experience working effectively in fully distributed/remote team environments.
- Ability to collaborate cross functionally with engineering and development teams.
Preferred Skills and Qualifications
- Previous hands on experience managing or participating in Bug Bounty programs.
- Programming experience in PHP or JavaScript.
- Experience with penetration testing methodologies and tools.
- Knowledge of SIEM platforms and security monitoring systems.
- Familiarity with Web Application Firewall (WAF) configuration and management.
- Understanding of secure software development lifecycle (SDLC) practices.
- Experience with Jira or similar project management and issue tracking systems.
- Strong sense of ownership and accountability within a flat organizational structure.
- Passion for continuous learning and staying current with evolving security threats and technologies.
Opportunity Details
- This is a full time opportunity.
- We are 100% remote, work from anywhere in the world!
Ready to Apply?
Take the next step in your career journey.
Apply NowYou will be redirected to the company's application page
Link verified about 18 hours ago
💜 Please mention that you found the job on True Work From Home, this helps us grow. Thanks!
More Security Engineer Jobs
Discover similar opportunities that match your skills
Platform Security Engineer
IT Engineer - Remote
Staff Software Engineer, SecureChain
Staff Security Engineer
DevSecOps Engineer
Offensive Security Engineer
Software Engineer - Blockchain Security
Senior Platform Engineer - Remote
About Chess
Chess.com is the world's leading online chess platform, offering a comprehensive experience for players of all levels. With over 200 million members globally, it serves as a hub for casual games, competitive tournaments, and educational resources.
View Company Profile