Application Security Engineer
위치: Vancouver, BC, Canada
Requisition Number: 175674
Position Title: Software Engineer III - Security
EA's Secure Product Engineering & Anti-Cheat Response (SPEAR) team ensures that all EA products are developed with security and gameplay integrity as a top priority. We partner with platform development teams and game studios to ensure that our players can enjoy playing games securely and fairly.
We are looking for a Senior Security Engineer to improve the security and gameplay integrity posture of a multi-platform, live service title, and its supporting services. You will report to the Senior Manager of the Verification and Pentest team, and maintain close relationships with SPEAR's Architecture and Design, and Gameplay Integrity Operations teams. Embedded in and working with the game studio, you will focus on the title through multiple iterative stages of product and service design, development and playtesting. The design reviews, threat modelling and security assessments you perform will cover everything from web applications, to network infrastructure, to thick clients and servers. You will help studio partners to make security-focused design and implementation choices. You will find and help to fix security and gameplay integrity issues at scale, protecting our our data, employee data and our players. You understand security principles, hands-on experience of vulnerability assessment, and a passion to learn new technologies, challenge assumptions, and create new solutions.
- Deliver design reviews and static and dynamic assessments on products running on PC, web, mobile and consoles, identifying and driving the remediation of security and gameplay integrity issues.
- Partner with SPEAR teams on the scoping and delivery of complex and specialist assessments, making best use of SPEAR subject matter expertise.
- Develop a broad and deep technical understanding of a single EA title, and central service dependencies, using that understanding to guide your reviews and recommendations.
- Correctly rate the security or gameplay integrity impact of discovered vulnerabilities and articulate remediation steps to product teams.
- Guide remediation of vulnerabilities by directly engaging studio developers, providing guidance on fixes and preventative security test cases.
- Partner with SPEAR to translate important industry security and gameplay security trends into applicable recommendations to the studio development team.
- Develop educational materials to the studio development team, to raise security IQ.
- Hands-on experience with security assessment tools and understanding of their applicability and limitations in different assessment scenarios.
- Experience in 2 or more of the following domains and expertise in at least one: Networking, OS Internals, Cloud Architecture, Web frameworks, or Mobile Architecture
- Knowledge of best practices and common pitfalls in one or more of: cryptography, authentication mechanisms, authorization controls and DevSecOps
- Knowledge of multiple of the following exploitation techniques and expertise in at least one: XSS, SQLi, IDOR, MitM, DoS, BOF, or ROP
- Experience in rating and discussing vulnerabilities according to their CVSS scoring
- Experience engaging and explaining the importance of security issues and initiate new efforts in mitigating vulnerabilities at-scale
- Bachelor's degree in Computer Science or Information Security, or equivalent industry experience
Community / Marketing Title: Application Security Engineer
Electronic Arts Inc.는 세계를 선도하는 인터랙티브 엔터테인먼트 소프트웨어 기업입니다. EA는 인터넷 콘솔, 개인용 컴퓨터, 휴대전화, 태블릿용 게임과 콘텐츠 및 온라인 서비스를 제공합니다.
EEOText: About EA We exist to inspire the world to play. Through innovative technology and immersive storytelling, we deliver new ways of experiencing worlds of interactive entertainment for our millions of players worldwide. Our strength lies in the diversity of our people, combining creativity, innovation and passion. We fully champion inclusive culture, and provide opportunities for growing, learning, and leading that allows for the most impactful and rewarding work of our teams’ careers. We put our people first, and we make sure they’re taken care of both in and out of the office. As we reflect on our learnings and successes from remote work, we aim to provide dynamic, collaborative and flexible work environments for our teams. Our employees connect through our Employee Resource Groups, which are actively involved in driving business decisions every step of the way. But our support doesn’t end at the workplace—we also encourage a balanced lifestyle with paid time off and new parent leave, free video games, fitness reimbursement and more. Our goal is to provide a safe, respectful and inspiring workplace for all of our employees. Through our diversity, equity, inclusion and social responsibility programs, we’re doing the work to give everyone the space to be their full selves while giving back to our community. We’re looking for problem-solvers, game-changers, innovators, dreamers, doers—people that are ready to move the needle and build on our success. As our industry accelerates, we aren’t just keeping up—we’re staying ahead of the game. Electronic Arts is an equal opportunity employer. All employment decisions are made without regard to race, color, national origin, ancestry, sex, gender, gender identity or expression, sexual orientation, age, genetic information, religion, disability, medical condition, pregnancy, marital status, family status, veteran status, or any other characteristic protected by law. Electronic Arts also makes workplace accommodations for qualified individuals with disabilities as required by applicable law.
Date Opened: 2022-09-14 13:34:31.373
EEO Employer Verbiage:
EA는 균등한 기회의 제공을 실천합니다. 모든 채용은 인종, 피부색, 출신 국가, 혈통, 생물학적/사회적 성별, 성 정체성 또는 표현, 성적 성향, 나이, 유전 정보, 종교, 장애 여부, 질병 유무, 임신 여부, 혼인 상태, 가족 상황, 군 복무 여부 등의 요인을 고려하지 않고 결정됩니다. EA는 관련 법률에서 명시하는 대로 업무 공간에 장애가 있는 입사 지원자 또는 예정자를 위한 시설을 마련해두고 있습니다.