waypointjobs

Chess.com

Security Engineer

Remote — Worldwide (see timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

About Us

Chess.com is one of the largest gaming sites in the world and the #1 platform for playing, learning, and enjoying chess.

We are a team of 600+ fully remote people in 60+ countries working hard to serve the global chess community. We are here to support 250M+ chess players worldwide with the best possible product, content, and tools to serve the community!

We are a tech company. A gaming company. A content company. And we do it all with passion and commitment to the game. Above all we prize our mission-driven, flat, life-celebrating, no-corporate culture, and we look forward to meeting you and learning more about what you can bring to the team.

About The Role

The Security Engineer plays a critical role in protecting our technology infrastructure and maintaining the security posture of our gaming platform. This position exists to proactively identify, assess, and mitigate security vulnerabilities while serving as a trusted security advisor to engineering teams across the organization. The role directly impacts our ability to safeguard user data, maintain platform integrity, and ensure secure development practices are embedded throughout our product development lifecycle.

This position is essential for building and maintaining robust security defenses in a fast-paced, remote-first technology environment where security expertise must be seamlessly integrated into daily engineering operations and strategic decision-making processes.

What you'll do

Lead vulnerability management program by triaging, reproducing, and assessing security vulnerabilities submitted through Bug Bounty programs, working directly with engineering teams to prioritize and remediate discovered security gaps

Conduct comprehensive threat modeling by collaborating with engineering teams to analyze proposed solutions, ensuring designs meet security industry standards and identifying potential attack vectors before implementation

Manage security incident response by reviewing penetration testing results and SIEM reports, translating technical findings into actionable remediation tasks, and tracking resolution progress through completion

Optimize security infrastructure by applying updates to Web Application Firewalls (WAF) and other security systems, ensuring configurations align with current threat landscape and organizational needs

Drive security tool evaluation and implementation by researching, evaluating, and recommending security software solutions, attending vendor demonstrations, and leading procurement processes from requirements gathering through deployment

Provide security consultation and guidance by serving as subject matter expert to development teams, ensuring security best practices are integrated into software development lifecycle and architectural decisions

Maintain security awareness and documentation by communicating security updates, progress reports, and recommendations to stakeholders through established channels and maintaining current security policies and procedures

Qualifications

Bachelor's degree in Computer Science, Information Security, or related technical field, or equivalent professional experience

Minimum 3+ years of professional experience specifically in web application security

Demonstrated expertise with security testing tools such as Burp Suite or equivalent web request analysis and tampering tools

Strong written communication skills in English with ability to clearly explain technical security concepts to diverse audiences

Experience working effectively in fully distributed/remote team environments

Proven ability to collaborate cross-functionally with engineering and development teams

Preferred Skills and Qualifications

Previous hands-on experience managing or participating in Bug Bounty programs

Programming experience in PHP or JavaScript

Experience with penetration testing methodologies and tools

Knowledge of SIEM platforms and security monitoring systems

Familiarity with Web Application Firewall (WAF) configuration and management

Understanding of secure software development lifecycle (SDLC) practices

Experience with Jira or similar project management and issue tracking systems

Strong sense of ownership and accountability in a flat organizational structure

Passion for continuous learning and staying current with evolving security threats and technologies

About the Opportunity

This is a full-time opportunity

We are 100% remote (work from anywhere!)

---

You can learn more about us here:

Originally posted on Himalayas

Who can apply

The source lists worldwide eligibility. Accepted UTC offsets: UTC-11, UTC-10, UTC-9.5, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC-4, UTC-3.5, UTC-3, UTC-2, UTC-1, UTC+0, UTC+1, UTC+2, UTC+3, UTC+3.5, UTC+4, UTC+4.5, UTC+5, UTC+5.5, UTC+5.75, UTC+6, UTC+6.5, UTC+7, UTC+8, UTC+8.75, UTC+9, UTC+9.5, UTC+10, UTC+10.5, UTC+11, UTC+12, UTC+12.75, UTC+13, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job