Pipeline
Browse Jobs
Sign inSign up
Pipeline
Browse jobsSign inContactTermsPrivacyCookiesPreferences
Logos provided by Logo.dev

© 2026 Pipeline. All rights reserved.

  1. Home
  2. Jobs
  3. IT
  4. Senior AppSec Engineer
PrizePicks logo

PrizePicks

Senior AppSec Engineer at PrizePicks

Atlanta, GA preferred, RemoteFull-timeRemoteITPosted about 1 month ago
Apply with Pipeline→

About the Role

<div class="content-intro"><p><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">At PrizePicks, we are the fastest-growing sports company in North America, as recognized by Inc. 5000. As the leading platform for Daily Fantasy Sports, we cover a diverse range of sports leagues, including the NFL, NBA, and Esports titles like League of Legends and Counter-Strike. Our team of over 550 employees thrives in an inclusive culture that values individuals from diverse backgrounds, regardless of their level of sports fandom. Ready to reimagine the DFS industry together?&nbsp;</span></p></div><h1><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 18pt;"><strong>What you’ll do:</strong></span></h1> <ul> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Own the Pipeline:</strong> Support and optimize application security tooling (SAST, SCA, Secrets Detection) within our CI/CD pipelines to provide accurate, actionable, and prioritized alerts to devs.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Be a Security Champion:</strong> Act as the primary security partner for Engineering and Product teams, ensuring security is baked in from the design phase through deployment.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Threat Modeling:</strong> Lead collaborative threat modeling exercises to identify architectural risks before code is even written. Partner with penetration testing teams to translate these threats into targeted testing scenarios for high-risk functions.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Code-Level Remediation:</strong> Don’t just tell devs <em>what</em> is wrong—show them <em>how</em> to fix it by performing deep-dive code reviews and providing actionable remediation guidance.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Secrets Management:</strong> Help lead the charge in identifying and removing hard-coded secrets, moving the org toward more secure, automated secret management practices.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Bug Bounty &amp; Research:</strong> Help manage our bug bounty program by triaging submissions, working with researchers, and validating fixes with our engineers.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Secure AI Integration:</strong> Serve as the security consultant for AI/ML initiatives. Partner with engineering to design secure "LLM-backed" features, focusing on prompt injection prevention, data privacy/sanitization, and secure integration of third-party AI APIs.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Incident Response:</strong> Support the team during application-related security incidents, bringing your deep knowledge of code and logic to the table.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Feature Validation:</strong> Perform security assessments on new features to help identify logic flaws that automated scanners might miss. Partner with our penetration testing team on high-risk releases to exchange knowledge and continuously sharpen your offensive security skillset.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Strategic Communication: </strong>Translate technical vulnerabilities into business risk. You’ll be responsible for documenting and presenting findings in a way that is actionable for engineers and understandable for leadership.</span></li> </ul> <h1><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 18pt;"><strong>What you have:</strong></span></h1> <ul> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">3+ years of experience in software development, mobile development, or application security. You are comfortable reading unfamiliar code and can speak Developer fluently.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">​​CI/CD Pipeline Expertise: Hands-on experience integrating security tools (SAST, DAST, SCA, Secrets Detection) into automated workflows (e.g., GitHub Actions, GitLab CI, Jenkins). You know how to tune these tools to prevent alert fatigue.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">Deep knowledge of the OWASP Web Security Testing Guide (WSTG) and/or Mobile Application Security Testing Guide (MASTG) and the ability to think like a threat actor.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">Experience conducting Threat Modeling to catch flaws before they are built.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">Familiarity with the OWASP Top 10 for LLMs. You understand the unique risks of integrating AI into a production stack and can advise on how to build guardrails around model inputs and outputs.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">Experience supporting an Incident Response (IR) process, specifically providing the AppSec perspective to help scope an exploit and verify if a patch truly mitigates it.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">A deep understanding of how web applications work. You know your way around HTTP headers, JWTs, CORS, and auth flows, and you can validate them manually when the scanners fail.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">Proven ability to define risks in both technical and business terms.</span></li> </ul> <p><span style="font-family: tahoma, arial, helvetica, sans-serif;"><strong><span style="font-size: 14pt;">Technical must haves:</span></strong></span></p> <ul> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>3+ years</strong> of professional experience in <strong>Software Development</strong> or <strong>Application Security</strong>.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>AppSec Tooling:</strong> Proven proficiency in deploying and tuning SAST, DAST, and SCA (e.g., Snyk, CodeQL, Dependabot, Mend, Wiz).</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Threat Modeling:</strong> Experience performing architectural threat models on products and services.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>CI/CD Automation:</strong> Strong experience building and maintaining security workflows in <strong>GitHub Actions</strong>.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Cloud Native:</strong> Working knowledge of Kubernetes and containerized compute services.</span></li> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>Security Testing: </strong>Comfortable using Burp Suite or Postman to manually validate logic flaws.</span></li> </ul> <h1><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 18pt;"><strong>Where you’ll live:</strong></span></h1> <ul> <li style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">While we prefer candidates based in Atlanta, we are open to qualified applicants from anywhere in the U.S. and are willing to consider remote candidates. #LI-Remote&nbsp;</span></li> </ul> <h1><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 18pt;"><strong>Working at PrizePicks:</strong></span></h1> <p><span style="font-size: 12pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif;">The typical salary range for this position is $90,000 to $180,000. At PrizePicks, we consider your role, level, and where you'll be working when determining our salary ranges. The compensation info you see on our job postings gives you an idea of the starting pay range for the position. Your actual pay within that range will depend on your specific work location, as well as your skills, experience, and education. Your </span><span style="font-family: tahoma, arial, helvetica, sans-serif;">recruiter will be happy to chat more about the specific pay range for your location and how we arrived at it during the hiring process.&nbsp;</span></span></p> <p><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">This application period will remain open for 30 days. We’re committed to finding the best candidate, so this date may be adjusted, and any changes will be reflected in this posting.&nbsp;</span></p> <p><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">Date Posted:&nbsp; 3/26/26</span></p> <p><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;">Re posted: 5/1/26</span></p><div class="content-conclusion"><h1><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 18pt;">Benefits you’ll receive:</span></h1> <p><span style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;">In addition to your great compensation package, full-time employees will be eligible for the following perks:&nbsp;</span></p> <ul> <li style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;">Company-subsidized medical, dental, &amp; vision plans&nbsp;</span></li> <li style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;">401(k) plan with company match</span></li> <li style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;">Annual bonus</span></li> <li style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-family: tahoma, arial, helvetica, sans-serif;">Flexible PTO to encourage a healthy work/life balance (2 weeks STRONGLY encouraged!)</span></li> <li style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;">Generous paid leave programs, including 16-week paid parental leave and disability benefits</span></li> <li style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;">Workplace flexibility and modern work schedules focused on getting the job done, not hours clocked</span></li> <li style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;">Company-wide in-person events and team outings</span></li> <li style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;">Lifestyle enhancement program</span></li> <li style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;">Company equipment provided (Windows &amp; Mac options)</span></li> <li style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: tahoma, arial, helvetica, sans-serif;">Annual performance reviews with opportunities for growth and career development</span></li> </ul> <p><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 12pt;"><strong>You must be authorized to work for any employer in the U.S.&nbsp; We are unable to sponsor or take over sponsorship of an employment Visa at this time.&nbsp;</strong></span></p> <p><span style="font-family: tahoma, arial, helvetica, sans-serif; font-size: 10pt;"><em><span style="font-weight: 400;">PrizePicks is an Equal Opportunity Employer.&nbsp; All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.</span></em></span></p></div>

Related Roles

  • Market Intelligence Intern - Fall 2026

    PrizePicks

    Atlanta, Georgia, United States
  • Associate Product Manager, Payments

    PrizePicks

    Atlanta, Georgia, United States
  • Product Manager

    PrizePicks

    Atlanta, Georgia, United States
  • Lead Researcher, Brand Performance & Cultural Insights

    PrizePicks

    Atlanta, GA preferred, RemoteRemote
  • Game Operations Manager

    PrizePicks

    Atlanta, GA preferred, RemoteRemote
  • Game Operations - Trading Analyst

    PrizePicks

    Atlanta, GA preferred, RemoteRemote