filler

Application Security Engineer

Lage: Vancouver, BC, Canada

Hinweis

Diese Position ist nicht mehr offen.

Requisition Number: 175674

Position Title: Software Engineer III - Security

External Description:

EA's Secure Product Engineering & Anti-Cheat Response (SPEAR) team ensures that all EA products are developed with security and gameplay integrity as a top priority. We partner with platform development teams and game studios to ensure that our players can enjoy playing games securely and fairly.

Description

We are looking for a Senior Security Engineer to improve the security and gameplay integrity posture of a multi-platform, live service title, and its supporting services. You will report to the Senior Manager of the Verification and Pentest team, and maintain close relationships with SPEAR's Architecture and Design, and Gameplay Integrity Operations teams. Embedded in and working with the game studio, you will focus on the title through multiple iterative stages of product and service design, development and playtesting. The design reviews, threat modelling and security assessments you perform will cover everything from web applications, to network infrastructure, to thick clients and servers. You will help studio partners to make security-focused design and implementation choices. You will find and help to fix security and gameplay integrity issues at scale, protecting our our data, employee data and our players. You understand security principles, hands-on experience of vulnerability assessment, and a passion to learn new technologies, challenge assumptions, and create new solutions.

Responsibilities:

  • Deliver design reviews and static and dynamic assessments on products running on PC, web, mobile and consoles, identifying and driving the remediation of security and gameplay integrity issues.
  • Partner with SPEAR teams on the scoping and delivery of complex and specialist assessments, making best use of SPEAR subject matter expertise.
  • Develop a broad and deep technical understanding of a single EA title, and central service dependencies, using that understanding to guide your reviews and recommendations.
  • Correctly rate the security or gameplay integrity impact of discovered vulnerabilities and articulate remediation steps to product teams.
  • Guide remediation of vulnerabilities by directly engaging studio developers, providing guidance on fixes and preventative security test cases.
  • Partner with SPEAR to translate important industry security and gameplay security trends into applicable recommendations to the studio development team.
  • Develop educational materials to the studio development team, to raise security IQ.

Qualifications:

  • 5+ years of full stack Application Security reviews, including experience with C++, TypeScript and JavaScript.
  • Hands-on experience with security assessment tools and understanding of their applicability and limitations in different assessment scenarios.
  • Experience in 2 or more of the following domains and expertise in at least one: Networking, OS Internals, Cloud Architecture, Web frameworks, or Mobile Architecture
  • Knowledge of best practices and common pitfalls in one or more of: cryptography, authentication mechanisms, authorization controls and DevSecOps
  • Knowledge of multiple of the following exploitation techniques and expertise in at least one: XSS, SQLi, IDOR, MitM, DoS, BOF, or ROP
  • Experience in rating and discussing vulnerabilities according to their CVSS scoring
  • Experience engaging and explaining the importance of security issues and initiate new efforts in mitigating vulnerabilities at-scale
  • Bachelor's degree in Computer Science or Information Security, or equivalent industry experience

#LI-NS1

City:

State:

Community / Marketing Title: Application Security Engineer

Company Profile:

Electronic Arts Inc. ist ein weltweit führender Anbieter interaktiver Unterhaltungssoftware. EA bietet Spiele, Inhalte und Online-Dienste für internetfähige Spielkonsolen, Personalcomputer, Mobiltelefone und Tablets an.

EEOText:

About Electronic Arts

Everything we do is designed to inspire the world to play. Through our cutting-edge games, innovative services, and powerful technologies, we bring worlds with infinite possibilities to millions of players and fans around the globe.

We’re looking for collaborative and inclusive people with diverse perspectives who will enrich our culture and challenge us. We take a holistic approach with our benefits program, focusing on physical, emotional, financial, career, and community wellness to support our people through every chapter of life. We provide comprehensive benefit packages and support for a balanced life with paid time off and new parent leave, plus free games and so much more. Our goal is to provide a safe and respectful workplace that empowers you to thrive in both work and life.

Electronic Arts is an equal opportunity employer. All employment decisions are made without regard to race, color, national origin, ancestry, sex, gender, gender identity or expression, sexual orientation, age, genetic information, religion, disability, medical condition, pregnancy, marital status, family status, veteran status, or any other characteristic protected by law. We will also consider employment qualified applicants with criminal records in accordance with applicable law. EA also makes workplace accommodations for qualified individuals with disabilities as required by applicable law.

Days Open: 33

Can this position be remote?: 0

EEO Employer Verbiage:

EA engagiert sich für Chancengleichheit und Gleichstellung. Alle Personalentscheidungen werden unabhängig von Ethnie, Hautfarbe, Herkunft, Abstammung, Geschlecht, Geschlechtsidentität oder ausgelebtem Geschlecht, sexueller Orientierung, Alter, genetischer Information, Religion, Behinderung, Krankheit, Schwangerschaft, Familienstand oder Veteranenstatus getroffen. EA sorgt außerdem für die durch geltendes Gesetz vorgeschriebenen Anpassungen am Arbeitsplatz für Individuen mit anerkannten Behinderungen.

Click here to view our Data Privacy Policy.

google-site-verification: google7f7a22bb8fdf2c3d.html