1 day ago
Base Salary
$202k - $236k/yr
Responsibilities
- Design integrity architecture for large-scale synchronous tournaments, including server-authoritative scoring, verifiable outcomes, tamper-evident result pipelines, and fairness controls.
- Detect and prevent score injection, result forgery, replay attacks, clock or latency manipulation, multi-accounting, collusion, account sharing, and Sybil attacks.
- Build mobile anti-cheat protections for bots, automation, input replay, memory manipulation, code injection, modified clients, rooted or jailbroken devices, and emulators.
- Implement and operate device attestation, device fingerprinting, mobile application hardening, and runtime application self-protection capabilities.
- Develop reusable server-side controls for API, WebSocket, session, transaction, authorization, rate-limiting, and server-authoritative validation risks.
- Build systems to detect account takeover, payment and payout fraud, chargeback abuse, account farming, promotion abuse, and virtual-asset laundering.
- Create telemetry pipelines, detection rules, dashboards, behavioral analytics, security services, automation, and internal tooling for large-scale events.
- Conduct threat modeling, penetration testing, secure code reviews, security assessments, mobile reverse engineering, and security research.
- Lead technical response to live cheating, fraud, exploitation, and DDoS incidents, including disqualification decisions, response playbooks, and post-incident improvements.
- Partner with gameplay, platform, mobile, data, fraud, security, finance, legal, communications, and player-support teams.
Requirements
- At least 6 years of experience in game security, application security, anti-cheat engineering, fraud prevention, or mobile security.
- Strong software-development skills in Python or TypeScript, including backend services, detection tools, or automation.
- Deep understanding of API security, authentication and authorization, session management, and applied cryptography.
- Hands-on experience with iOS or Android security, application hardening, attestation, root or jailbreak detection, or mobile application reverse engineering.
- Understanding of server-authoritative game design and common cheating and abuse techniques.
- Working knowledge of at least one major cloud provider, such as AWS, GCP, or Azure, and distributed real-time architectures.
- Preferred experience with Frida, objection, Ghidra, jadx, Hopper, mobile instrumentation, reverse-engineering tools, and mobile RASP or hardening products.
- Preferred experience securing tournaments, leaderboards, sweepstakes, skill-gaming, real-money gaming, or other prize-bearing competitions, including geo-eligibility, age gating, and KYC requirements.
- Preferred knowledge of payment fraud, chargebacks, virtual currencies, marketplace abuse, SIEM platforms, streaming telemetry pipelines, and large-scale behavioral analytics.
- Preferred experience applying statistics or ML to anomaly detection, assessing WebSocket or UDP protocols, and contributing to security research, bug bounties, CTFs, conferences, or open source.
Benefits
- Base salary of $202,000–$236,000 plus equity and benefits.
- Medical coverage through Blue Cross Blue Shield, dental and vision coverage, and company-paid life insurance.
- Company contributions to Health Savings Accounts and a 401(k) plan with Safe Harbor company matching.
- Flexible vacation policy and paid company holidays.
- Company-provided technology package.
- Relocation assistance where applicable, including travel and company-provided housing for the first 90 days.
- The role is located in New York, the Bay Area, Chicago, or Greenville.