Browse All Jobs
Job Description
PENN Entertainment is seeking an Application Security Engineer to join their Application Security team. The successful candidate will collaborate with various teams, including release and change management, SRE, Engineering, and compliance, to secure software systems, applications, and code. This role involves designing and implementing security measures, maintaining knowledge of OWASP top 10 and MITRE top 25 CWE, and developing standards for security tooling. Responsibilities:
  • Collaborate with release and change management, SRE, Engineering, and compliance teams
  • Work with security/internal/external/state auditors to demonstrate compliance
  • Maintain a working knowledge of OWASP top 10 and MITRE top 25 CWE
  • Develop standards for security tooling focused on the application layer (SAST, DAST, SCA, MAST, RASP)
  • Build/implement secure artifact workflows in the SDLC to ensure governance and compliance standards are being met
  • Create technical approaches to implementing Application Security control technologies
  • Contribute to PENN Interactive’s Application Security program to support our continued growth
  • Define and report on security metrics, their delivery, and improvements
  • Work with service teams to conduct threat models of PENN Interactive’s internal and customer facing applications
  • Assist service teams in understanding and remediating security findings (code bashing)
Requirements:
  • 2+ years of Application Security or DevSecOps experience
  • Experience working with GCP or AWS
  • Experience with software supply chain security (SBOMs, Artifact Signing, Attestations)
  • Programming experience in Python or Go
  • Experience with implementing security tooling in CI/CD
  • Experience supporting RESTful APIs and securing containerized workloads (GKE, EKS)
  • Experience working in regulated environments (PCI-DSS, SOC 2, etc)
What PENN Entertainment Offers:
  • Competitive compensation package
  • Comprehensive Benefits package
  • Fun, relaxed work environment
  • Education and conference reimbursements
  • Opportunities for career progression and mentoring others
Apply Manually