Full-Time

Senior Application Security Engineer

 PrizePicks

PrizePicks

501-1,000 employees

Daily fantasy sports with over/under predictions

Compensation Overview

$90k - $180k/yr

+ Annual Bonus

No H1B Sponsorship

Atlanta, GA, USA

Remote

Atlanta preferred; remote within the U.S.

Category
IT & Security (1)
Required Skills
LLM
Kubernetes
Github Actions
Postman
Threat modeling
Docker
Jenkins
Requirements
  • 3+ years of experience in Software Development or Application Security
  • Hands-on experience integrating security tools (SAST, DAST, SCA, Secrets Detection) into automated CI/CD workflows (e.g., GitHub Actions, GitLab CI, Jenkins) and tuning these tools to prevent alert fatigue
  • Deep knowledge of the OWASP Web Security Testing Guide (WSTG) and/or Mobile Application Security Testing Guide (MASTG) and the ability to think like a threat actor
  • Experience conducting Threat Modeling to catch flaws before they are built
  • Familiarity with the OWASP Top 10 for Large Language Models (LLMs) and the ability to advise on guardrails around AI integration
  • Experience supporting an Incident Response process, specifically providing the AppSec perspective to help scope exploits and verify patches mitigate
  • Deep understanding of how web applications work including HTTP headers, JWTs, CORS, and authentication flows and ability to validate them manually when scanners fail
  • Proven ability to define risks in both technical and business terms
  • Proficiency in deploying and tuning SAST, DAST, and SCA tools (e.g., Snyk, CodeQL, Dependabot, Mend, Wiz)
  • Threat Modeling experience performing architectural threat models on products and services
  • Strong experience building and maintaining security workflows in GitHub Actions
  • Working knowledge of Kubernetes and containerized compute services
  • Comfortable using Burp Suite or Postman to manually validate logic flaws
  • 3+ years of professional experience in Software Development or Application Security
Responsibilities
  • Own the Pipeline: Support and optimize application security tooling within our CI/CD pipelines to provide accurate, actionable, and prioritized alerts to devs
  • Be a Security Champion: Act as the primary security partner for Engineering and Product teams, ensuring security is baked in from the design phase through deployment
  • Threat Modeling: Lead collaborative threat modeling exercises to identify architectural risks before code is even written. Partner with penetration testing teams to translate these threats into targeted testing scenarios for high-risk functions
  • Code-Level Remediation: Don’t just tell devs what is wrong—show them how to fix it by performing deep-dive code reviews and providing actionable remediation guidance
  • Secrets Management: Help lead the charge in identifying and removing hard-coded secrets, moving the org toward more secure, automated secret management practices
  • Bug Bounty & Research: Help manage our bug bounty program by triaging submissions, working with researchers, and validating fixes with our engineers
  • Secure AI Integration: Serve as the security consultant for AI/ML initiatives. Partner with engineering to design secure "LLM-backed" features, focusing on prompt injection prevention, data privacy/sanitization, and secure integration of third-party AI APIs
  • Incident Response: Support the team during application-related security incidents, bringing your deep knowledge of code and logic to the table
  • Feature Validation: Perform security assessments on new features to help identify logic flaws that automated scanners might miss. Partner with our penetration testing team on high-risk releases to exchange knowledge and continuously sharpen your offensive security skillset
  • Strategic Communication: Translate technical vulnerabilities into business risk. You’ll be responsible for documenting and presenting findings in a way that is actionable for engineers and understandable for leadership

PrizePicks runs a daily fantasy sports platform where users predict whether selected athletes will perform above or below a set benchmark across 2–5 players. Winnings depend on accuracy, with up to 10x the entry fee, and revenue comes from real-money entry fees. Unlike traditional fantasy that builds full rosters, it focuses on flexible, single-event bets across multiple sports. Its goal is to provide a simple, accessible way for fans to test sports knowledge and win money, within U.S. and Canada regulatory limits.

Company Size

501-1,000

Company Stage

Seed

Total Funding

$2.3M

Headquarters

Atlanta, Georgia

Founded

2015

Simplify Jobs

Simplify's Take

What believers are saying

  • Allwyn's $1.6B acquisition completed January 2026 funds US expansion to 45+ jurisdictions.
  • Los Angeles Dodgers partnership June 2025 adds in-stadium branding and fan promotions.
  • Mike Quigley CMO appointment February 2025 leverages Niantic expertise for engagement.

What critics are saying

  • Florida AG Moody lawsuits reclassify pick'em as illegal betting, forcing revenue-losing free-play pivot.
  • California class actions against PrizePicks as illegal gambling halt operations via Penal Code violations.
  • DraftKings lobbies California, Texas tighten DFS rules, blocking 60% US population markets.

What makes PrizePicks unique

  • PrizePicks offers simplest over/under player predictions against numbers, not users.
  • Largest independent DFS platform covers widest sports breadth in North America.
  • First fantasy operator with iCAP accreditation from National Council on Problem Gambling.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at PrizePicks who can refer or advise you

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

401(k) Company Match

Unlimited Paid Time Off

Paid Sick Leave

Paid Holidays

Flexible Work Hours

Performance Bonus

Company Social Events

Growth & Insights and Company News

Headcount

6 month growth

2%

1 year growth

2%

2 year growth

4%
CZECH NEWS CENTER, a. s.
Apr 2nd, 2026
Allwyn lists 22% of shares on Athens stock exchange after OPAP merger

Allwyn, the international gaming group from Karel Komárek's KKCG empire, has listed on the Athens Stock Exchange following its March merger with Greek firm OPAP. The combined entity, Allwyn AG, is now the world's second-largest publicly traded lottery and gaming group, with approximately 22% of shares in free float. The listing follows KKCG's long-term strategy of building an international lottery platform since acquiring Sazka in 2011. Allwyn now operates across Greece, Austria, Croatia, Italy, the UK and the US. Recent expansions include a $1.6 billion acquisition of 62% of PrizePicks in January and obtaining the UK National Lottery licence in 2022. In 2025, Allwyn reported preliminary net revenues of €4.1 billion, a 4% year-on-year increase, with adjusted EBITDA of €1.58 billion.

iGaming Expert
Mar 4th, 2026
Allwyn abandons $245M Novibet acquisition following Greek regulator objections

Lottery giant Allwyn has abandoned its planned acquisition of a 51% stake in Novibet following objections from the Hellenic Competition Commission. The transaction, valued at €217 million, was first announced in December 2024. Allwyn and Novibet owner Logflex MT Holding Limited terminated the deal after the HCC raised concerns about restricted competition in Greece's online gaming market. Allwyn already controls over 50% of the Greek market through its stake in OPAP, which operates the Pamestoixima and Stoixman brands. Objectors argued Allwyn was seeking to acquire the only competitor capable of competing on equal terms in Greece. Despite the setback, Allwyn continues expanding elsewhere, recently completing a $1.6 billion majority acquisition of PrizePicks in the US and advancing a merger with OPAP.

PR Newswire
Mar 3rd, 2026
PrizePicks partners with Bob Does Sports in exclusive fantasy sports deal

PrizePicks, a North American sports entertainment operator, has announced a multi-platform partnership with Bob Does Sports, the golf and lifestyle brand led by Robby Berger and boasting over 5.5 million followers. The deal marks Berger's return after being an early PrizePicks content partner from 2021 to 2023. PrizePicks will serve as exclusive fantasy sports partner across Bob Does Sports' ecosystem, including social media, podcasts and live events. Bob Does Sports' live-streamed golf challenges will appear on the PrizePicks platform, enabling fan engagement. The partnership will support original programming from Bob HQ, a new content hub opening in Jupiter, Florida. PrizePicks, which operates in over 45 US jurisdictions, recently became the first fantasy sports operator to receive iCAP accreditation from the National Council on Problem Gambling.

GamesHub
Nov 12th, 2025
PrizePicks Acquired by Allwyn for $1.5B

PrizePicks, a fantasy sports specialist, is partnering with Polymarket to integrate event contracts into its app, following a $1.5 billion acquisition by Allwyn. Allwyn has secured the necessary funding for the deal, viewing PrizePicks as a key asset for US expansion. The partnership with Polymarket, a cryptocurrency-based prediction platform, marks PrizePicks' entry into the US predictions market, aiming to enhance user experience and drive innovation.

Pechanga Resort Casino
Oct 28th, 2025
Allwyn's $1.6B PrizePicks Acquisition Plan

Allwyn is acquiring a 62.3% majority stake in PrizePicks for $1.6 billion, marking its entry into the US daily fantasy sports market. The acquisition is financed by a $1.64 billion term loan. PrizePicks' enterprise value is $2.5 billion, potentially rising to $4.15 billion if performance metrics are met over three years. Current CEO Mike Ybarra and his team will continue to lead PrizePicks. The deal is expected to close in Q1 next year, pending conditions.