
// Open Role at Rockstar Games
Join Rockstar Games as an Application Security Engineer, working on world-class entertainment experiences. You'll identify security flaws in complex software designs and contribute to safeguarding our games and players within a highly motivated, inclusive studio.
At Rockstar Games, we create world-class entertainment experiences.
Become part of a team working on some of the most rewarding, large-scale creative projects to be found in any entertainment medium - all within an inclusive, highly-motivated environment where you can learn and collaborate with some of the most talented people in the industry.
Rockstar is on the lookout for a passionate Application Security Engineer who possess a passion for diving into complex software designs to identify security flaws and vulnerabilities.
This is a full-time, permanent and in-office position based in Rockstar’s unique game development studio in the heart of Dundee, Scotland.
3+ years of experience working in a professional, academic or research environment identifying and remediating security bugs/flaws.
Strong knowledge of the principles and techniques for both manual and automated application security assessments of desktop and web applications.
Good knowledge of common web security vulnerabilities (e.g., OWASP Top 10), attack techniques and remediation tactics/strategies.
Good understanding of common low-level vulnerabilities (e.g. use-after-free and buffer overflows)and common mitigations.
Good understanding of networking and web technologies (e.g. WebSockets, HTTPS, TCP/IP, UDP) and security controls relevant to them.
Familiarity with Windows and Linux operating systems fundamentals.
Familiarity with the software development lifecycle (SDLC) and working knowledge of components to secure the SLDC.
Practical experience with client network traffic testing tools and techniques e.g., Burp Suite, Fiddler and Bruno.
Practical experience with thick client testing tools and techniques e.g. Procmon, Strings2, Dependencies.
Proficiency in C#.
Excellent communication skills.
Please note that these are desirable skills and are not required to apply for the position.
Please apply with a CV and cover letter demonstrating how you meet the skills above. If we would like to move forward with your application, a Rockstar recruiter will reach out to you to explain next steps and guide you through the process.
Rockstar is committed to creating a work environment that promotes equal opportunity, dignity and respect. In line with this commitment, Rockstar will provide reasonable accommodations to qualified job applicants with disabilities during the recruitment process in order for such applicants to be considered for the position for which they are applying, as well as to qualified employees to enable them to perform the essential functions of their roles. If you need more information about Rockstar’s reasonable accommodation policies or process, or need to request an accommodation, please notify your recruiter during the interview process.
If you’ve got the right skills for the job, we want to hear from you. We encourage applications from all suitable candidates regardless of age, disability, gender identity, sexual orientation, religion, belief, race, or any other protected category.
#LI-AH
- 3+ years of experience working in a professional, academic or research environment identifying and remediating security bugs/flaws. - Strong knowledge of the principles and techniques for both manual and automated application security assessments of desktop and web applications. - Good knowledge of common web security vulnerabilities (e.g., OWASP Top 10), attack techniques and remediation tactics/strategies. - Good understanding of common low-level vulnerabilities (e.g. use-after-free and buffer overflows)and common mitigations. - Good understanding of networking and web technologies (e.g. WebSockets, HTTPS, TCP/IP, UDP) and security controls relevant to them. - Familiarity with Windows and Linux operating systems fundamentals. - Familiarity with the software development lifecycle (SDLC) and working knowledge of components to secure the SLDC. - Practical experience with client network traffic testing tools and techniques e.g., Burp Suite, Fiddler and Bruno. - Proficiency in C#. - Excellent communication skills.