Full-Time

Application Security Engineer III

Confirmed live in the last 24 hours

Fanatics

Fanatics

10,001+ employees

Global digital sports platform for fans

No salary listed

Mid, Senior

Hyderabad, Telangana, India

In Person

Category
Cybersecurity
IT & Security
Required Skills
Chef
PHP
Microsoft Azure
Python
JavaScript
Git
Ruby
Java
Gradle
Microservices
C#
AWS
Go
Jenkins
Maven
REST APIs
Objective-C
Development Operations (DevOps)
CircleCI
Splunk
Google Cloud Platform
Requirements
  • Bachelor’s degree in computer science, Information Systems, or equivalent combination of education and experience
  • Certifications in the field of Information Security (at least one of the following: CISSP, CEH, GIAC CPEN, OSCP, OSWE, CWAPT, GWAPT, GWEB)
  • A minimum of 3 to 5 years of experience
  • In-depth knowledge of web and mobile security vulnerabilities, attack vectors and mitigation techniques
  • Experience with multiple programming languages (Java, JavaScript, Go, Python, Ruby, Objective-C, C#, PHP) with hands on level coding experience with at least one scripting and one objected oriented programming language
  • Fluent with security testing with SAST, SCA, DAST, IAST, Fuzz and penetration testing tools
  • Understanding of application security standards such as OWASP ASVS/Top 10 and CWE 25
  • Ability to discover and patch SQLi, XSS, CSRF, SSRF, authentication and authorization flaws, and other web-based security vulnerabilities (OWASP Top 10 and beyond)
  • Knowledge of common authentication technologies including OAuth, SAML, CAs, OTP/TOTP
  • Knowledge of DevSecOps to maintain security in CI/CD pipeline
  • Solid experience with security tools like Semgrep, CheckMarx, VeraCode, BurpSuite, Snyk, Nessus
  • Familiar with tools like Git, Jenkins, CircleCI, Maven, Ant, Gradle, Nexus, SonarQube, Artifactory, Chef, Splunk
  • Experience writing custom rules for static analysis tools
  • Experience with API Security, IaC, Containerization, RASP, IAST
  • Experience with micro services, container deployment and service orchestration
  • Strong knowledge of cryptography, API security, and secret management
  • Ability to clearly and effectively communicate concerns and issues to the management and engineers
  • Experience with Cloud (AWS, Azure, GCP) Security
  • Experience writing tools to automate tasks and integrate systems using scripting languages like Go, Python and REST APIs
  • Experience in delivering and educating development groups in Secure Coding
  • Expertise with common vulnerabilities and attack vectors
  • Experience integrating security tools into developer pipelines
  • DevOps experience managing deployment and configuration
Responsibilities
  • Establish security best processes and practices for our mobile, on-premises and cloud-based platforms.
  • Provide expert knowledge and guidance to the product teams about security vulnerabilities and remediation controls.
  • Support and consult with product and development teams in the area of application security, including threat modeling and Application Security reviews.
  • Implement, continuously develop, and maintain secure Software Security Development Lifecycle processes and software maturity model.
  • Perform threat modeling, secure design, and source code review.
  • Conduct security assessments, security testing and validation of vulnerability scan results.
  • Assist teams in reproducing, triaging, and addressing application security vulnerabilities.
  • Incorporate security tools/tasks to automate product development and deployment.
  • Develop, implement, and automate defensive controls, creating and tuning tools and rules to detect and address malicious activity. Responsible for integration of security controls into SDLC.
  • Establish supply chain security process and ensure 3rd party software meet the standards.
  • Facilitate injection, integration, and compliance for Static Application Security Testing (SAST), Container Security Scanning & Open-Source Security Analysis during development phase.
  • Facilitate injection, integration, and compliance for Dynamic Application Security Testing (DAST)
  • Contribute to triaging, addressing security issues and tracking remediation.
  • Own and manage Secure SDLC tooling.
  • Develop and customize security tools used by security teams and developers.
  • Work closely with development teams to build security directly into their SDLCs.
  • Provide remediation guidance to programmers and management.
  • Support bug bounty program
  • Support the preparation of security releases
  • Mentor and train development teams on secure coding standards and techniques. Develop Secure Coding Program.
  • Constantly innovate at the pace of the adversary using latest techniques.
Desired Qualifications
  • Strong critical thinking and analytical skills
  • Ability to approach problem solving in a constructive and collaborative way that does not require absolute security.
  • The ability to communicate complicated technical issues and risks to programmers, network engineers and managers.
  • Strong leadership, project, and team-building skills
  • Exceptional communication skills with diverse audiences; the ability to be an application security subject matter expert who can explain relevant topics to general audiences.

Fanatics operates a global digital sports platform that caters to sports fans by offering a wide variety of products and services. Its main segments include Fanatics Commerce, where fans can buy licensed sports gear and apparel; Fanatics Collectibles, which allows fans to collect physical and digital trading cards and memorabilia; and Fanatics Betting & Gaming, which is focused on sports betting services. The platform connects with over 100 million sports fans and has partnerships with around 900 sports properties, including major leagues and teams. Fanatics stands out from competitors by providing a comprehensive suite of offerings that enhance the overall fan experience, from merchandise to collectibles and betting. The company's goal is to continuously improve and delight sports fans around the world.

Company Size

10,001+

Company Stage

Growth Equity (Venture Capital)

Total Funding

$5.2B

Headquarters

New York City, New York

Founded

1995

Simplify Jobs

Simplify's Take

What believers are saying

  • Fanatics' valuation rose to $18 billion, tripling in a year.
  • Partnership with Komo Tech enhances fan engagement through immersive games and competitions.
  • Acquisition of PointsBet's US businesses strengthens Fanatics' sports betting market position.

What critics are saying

  • Expansion into sports betting may face regulatory challenges and market saturation.
  • Increased competition from WWE-NFL partnership could divert sales from Fanatics.
  • Komo Tech partnership may not yield expected results if technology fails to resonate.

What makes Fanatics unique

  • Fanatics integrates merchandise, memorabilia, and sports betting into fan festivals.
  • The company collaborates with 2,500 athletes and celebrities, including 200 exclusive athletes.
  • Fanatics offers a comprehensive suite of products for sports fandom, enhancing fan experience.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Work Life Balance - At Fanatics we place our focus on results and empowerment and encourage you to enjoy your time on and OFF the field with our competitive time off policies.

Recognition and Rewards Program - Fanatics values our internal fans too! Our programs are designed to thank and reward Fanatics athletes for their hard work and commitment to winning as a team.

Company Sponsored Events - From breakfast to happy hour and every hour in between – Fanatics employees can enjoy time together at one of our many company events.

Fanatics.com Employee Discount - As an employee you will receive a special discount on all of your favorite sports merchandise and memorabilia.

Give Back - Fanatics cares about the fans around us. We encourage you to partner up with your teammates in giving back and serving the communities where we work and play.

Meet & Greets - You never know who will show up to the office. You might just meet one of your all-time favorite athletes.

Invest in You - Here at Fanatics we want you to accomplish your goals. We offer tuition reimbursement.

Healthy Lifestyle - Fanatics cares about helping and supporting our teams in their busy lifestyles. Through wellness relationships with fitness and weight management partners we are here to support you in whatever your lifestyle goals.

Wellness Coverage - Your health is important to you – and it’s important to us too! We offer a number of benefit plan options for convenience and flexibility.

Financial Security - Through our plans, Fanatics offers you a way to budget for health care expenses that you’d typically pay for out of pocket.

Retirement - The sooner you begin planning for your retirement, the better. Fanatics offers generous plans to help you prepare for the future.

Network of Support - Fanatics understands that sometimes you may need someone in your corner. Through the Life Assistance Program, you and your family have access to support 24 hours a day, 7 days a week.

Fanatics Family First - Afterall we are #OneFanatics. Put your family first with our paid maternity and paternity leave program, or take advantage of our infertility treatment reimbursement program to get the support you need while you try to grow your family.

IDEA - We invite you to join one of our Employee Resource groups, or celebrate and honor what’s most important to you through our IDEA (Inclusion, Diversity, Equality & Advocacy) floating holiday. We recognize diversity helps foster innovation, and people perform better when they can be themselves. Gender Affirmation Treatment reimbursement is available to employees.

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

1%
The Wall Street Journal
Dec 8th, 2024
WSJ News Exclusive | Fanatics Valuation Rises to $18 Billion as It Plans to Expand Sports Offerings

Fanatics raised a new round of funding valuing the online sports-merchandise retailer at $18 billion, people familiar with the matter said, roughly tripling its valuation from a year ago.

Yahoo Sports
Sep 12th, 2024
Fanatics Launching Events Division With Investment From IMG

Fanatics is launching a new events vertical, in partnership with IMG, to capitalize on the company’s growing suite of business ventures, including merchandise, memorabilia, fashion, music, trading cards and sports betting. Starting next year, Fanatics Events will create fan festivals that feature athletes and brands from across the industry, including those in the Fanatics orbit. […]

Fanatics
Sep 12th, 2024
History — Fanatics Inc

What began as a single e-commerce deal in 2002 has grown into a mobile-first, tech and data-fueled consumer brand, built to satisfy global fans who purchase gear in-the-moment when passion is burning highest. Fanatics provides the ultimate shopping experience to sports fans whether buying gear onlin

Business Wire
Sep 12th, 2024
GSI Commerce to Acquire Fanatics, Inc.

GSI Commerce Inc. (Nasdaq: GSIC) today announced that it has signed a definitive agreement to acquire Fanatics, Inc., an online retailer of licensed s