Senior Security Engineer, Software
Job description
About the role
The Scopely Explore division is actively seeking a technical expert to safeguard the integrity and security of our gaming ecosystem, which includes globally recognized titles such as Pokémon GO, Monster Hunter Now, and Pikmin Bloom. You will take ownership of designing and implementing protective measures across our software development lifecycle, build infrastructure, and application layer to ensure a safe and engaging experience for our millions of players worldwide. This role requires a deep understanding of how security controls interact with complex software delivery pipelines and live services. You will be responsible for evolving the security posture of the engineering organization rather than simply responding to isolated incidents. The ideal candidate thrives in a fast-paced, product-driven environment where technical excellence directly enables business success. You will partner closely with product managers, engineers, and operations teams to embed security seamlessly into their workflows. This position is critical for maintaining the trust of our player community and protecting sensitive data at scale.
Key facts
What you'll do
- Develop and maintain AI-driven or agentic workflows to automate routine security operations, reducing manual overhead and improving response times.
- Conduct security audits and design reviews for applications and platform components to identify architectural weaknesses before deployment.
- Advise product and operations teams on security best practices, translating complex concepts into actionable guidance for cross-functional partners.
- Build internal tooling to improve developer efficiency and security coverage, enabling teams to self-serve secure configurations and checks.
- Lead efforts in application scanning, fuzzing, and security architecture to uncover vulnerabilities in code and third-party components.
- Harden CI/CD pipelines, container environments, and in-house libraries to ensure that deployment processes are resilient against tampering and misconfiguration.
- Manage third-party library assessments and vulnerability remediation, tracking risks across the software supply chain and driving mitigation strategies.
- Promote secure coding standards across engineering teams, ensuring alignment with industry frameworks and regulatory expectations.
- Participate in red-team exercises and coordinate with external penetration testers to validate the effectiveness of existing defenses.
- Collaborate with site reliability and infrastructure teams to ensure that security controls are performant, observable, and integrated into production environments.
- Analyze security telemetry and incident data to derive insights and prioritize initiatives that reduce future risk exposure.
- Mentor junior engineers and developers on secure development practices, fostering a culture of security ownership across the organization.
- Evaluate emerging threats relevant to gaming platforms and recommend controls that mitigate novel attack vectors.
- Act as a subject matter expert for Scopely Explore initiatives, representing security in planning sessions and roadmap discussions.
Requirements
- Bachelors degree in Computer Science or a related field, providing a foundational understanding of systems, networking, and secure design principles.
- 5+ years of experience in a global organization with cloud-centric infrastructure, preferably GCP, demonstrating familiarity with large-scale operational environments.
- Proficiency in using AI tools such as Claude, Codex, OpenCode, or Gemini, including knowledge of RAG and MCP, to enhance productivity and automate complex tasks.
- Ability to build scalable automation and agentic workflows that can operate reliably in production environments without constant supervision.
- Experience hardening distributed web services and cloud architectures, including the implementation of zero-trust networking and secure service communication.
- Strong programming skills in Go or Java, enabling you to review code, develop security tools, and integrate security into engineering projects.
- Deep understanding of modern vulnerability classes and exploitation patterns, including injection flaws, broken authentication, and insecure deserialization.
- Excellent communication skills for working with distributed teams, ensuring that security requirements and findings are clearly articulated to diverse stakeholders.
Nice to have
- Background in red-team operations or mitigation tracking, with experience emulating adversary techniques and managing remediation efforts.
- Familiarity with build systems, artifact repositories, or large-scale infrastructure, providing insight into how software is built, stored, and deployed.
- Experience delivering privacy-focused solutions, aligning security designs with data protection regulations and user expectations.
- History with security champion programs or code quality management, demonstrating a commitment to improving engineering practices.
- Experience in a customer-centric engineering environment, where decisions are influenced by the needs and safety of end users.
- Research or practical experience in AI security and safety, addressing risks associated with automated systems and model behavior.
Practical notes
- Scopely will never ask for payment or financial details during the hiring process.
- Verify that all recruitment communications originate from an email address ending in @scopely.com.
- If you suspect fraudulent activity, contact recruiting@scopely.com.
This role is based in Zurich, Switzerland, and requires the ability to work onsite in the local region on a full-time basis. Candidates must be legally authorized to work in Switzerland without requiring company sponsorship for a visa or work permit. The position demands consistent availability during standard business hours to collaborate effectively with global teams and respond to security incidents in a timely manner. Travel may be required occasionally to meet with engineering and security partners at offices or to conduct assessments on-site. No additional travel-related expenses or relocation support commitments are specified at this time. Applications must be submitted through official Scopely career channels, and only candidates who closely match the outlined qualifications will be contacted for further consideration.