Web Application Security Engineer at Chess.com
Job Description
About Chess.com
Chess.com is one of the largest gaming sites in the world and the top platform for playing, learning, and enjoying chess. Our team of more than 600 fully remote people spans 60+ countries, working hard to serve the global chess community. We support over 250 million chess players worldwide with the best possible product, content, and tools. We are a tech company, a gaming company, and a content company, and we do it all with passion and commitment to the game. Above all, we prize our mission driven, flat, life celebrating, no corporate culture and we look forward to meeting you and learning more about what you can bring to the team.
About The Role
The Security Engineer plays a critical role in protecting our technology infrastructure and maintaining the security posture of our gaming platform. This position exists to proactively identify, assess, and mitigate security vulnerabilities while serving as a trusted security advisor to engineering teams across the organization. The role directly impacts our ability to safeguard user data, maintain platform integrity, and ensure secure development practices are embedded throughout our product development lifecycle. This position is essential for building and maintaining robust security defenses in a fast paced, remote first technology environment where security expertise must be seamlessly integrated into daily engineering operations and strategic decision making processes.
What You Will Do
- Lead the vulnerability management program by triaging, reproducing, and assessing security vulnerabilities submitted through Bug Bounty programs, working directly with engineering teams to prioritize and remediate discovered security gaps
- Conduct comprehensive threat modeling by collaborating with engineering teams to analyze proposed solutions, ensuring designs meet security industry standards and identifying potential attack vectors before implementation
- Manage security incident response by reviewing penetration testing results and SIEM reports, translating technical findings into actionable remediation tasks, and tracking resolution progress through completion
- Optimize security infrastructure by applying updates to Web Application Firewalls (WAF) and other security systems, ensuring configurations align with the current threat landscape and organizational needs
- Drive security tool evaluation and implementation by researching, evaluating, and recommending security software solutions, attending vendor demonstrations, and leading procurement processes from requirements gathering through deployment
- Provide security consultation and guidance by serving as a subject matter expert to development teams, ensuring security best practices are integrated into the software development lifecycle and architectural decisions
- Maintain security awareness and documentation by communicating security updates, progress reports, and recommendations to stakeholders through established channels and keeping security policies and procedures current
Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent professional experience
- Minimum 3+ years of professional experience specifically in web application security
- Demonstrated expertise with security testing tools such as Burp Suite or equivalent web request analysis and tampering tools
- Strong written communication skills in English with the ability to clearly explain technical security concepts to diverse audiences
- Experience working effectively in fully distributed and remote team environments
- Proven ability to collaborate cross functionally with engineering and development teams
Preferred Skills And Qualifications
- Previous hands on experience managing or participating in Bug Bounty programs
- Programming experience in PHP or JavaScript
- Experience with penetration testing methodologies and tools
- Knowledge of SIEM platforms and security monitoring systems
- Familiarity with Web Application Firewall (WAF) configuration and management
- Understanding of secure software development lifecycle (SDLC) practices
- Experience with Jira or similar project management and issue tracking systems
- Strong sense of ownership and accountability in a flat organizational structure
- Passion for continuous learning and staying current with evolving security threats and technologies
About The Opportunity
- This is a full time opportunity
- We are 100% remote (work from anywhere!)
You can learn more about us here:
- Chess Is For Everyone!
- Our Values
Ready to Apply?
Take the next step in your career journey.
Apply NowYou will be redirected to the company's application page
Link verified about 16 hours ago
💜 Please mention that you found the job on True Work From Home, this helps us grow. Thanks!
More Security Engineer Jobs
Discover similar opportunities that match your skills