Quick Summary
About Us
Chess.com is a leading global gaming site and the #1 platform for playing, learning, and enjoying chess. Our team of over 600 fully remote professionals across 60+ countries is dedicated to serving the global chess community. We support 250M+ chess players worldwide with top-tier products, content, and tools.
We are a passionate tech, gaming, and content company committed to the game. We value our mission-driven, flat, life-celebrating, and non-corporate culture.
About The Role
The Security Engineer is crucial for protecting our technology infrastructure and enhancing the security posture of our gaming platform. This role focuses on proactively identifying, assessing, and mitigating security vulnerabilities. You will serve as a trusted security advisor to engineering teams, directly impacting our ability to safeguard user data, maintain platform integrity, and embed secure development practices throughout the product development lifecycle.
This position is vital for building and maintaining robust security defenses within a fast-paced, remote-first technology environment, integrating security expertise into daily engineering operations and strategic decision-making.
What You'll Do
- Lead the vulnerability management program, including triaging, reproducing, and assessing security vulnerabilities from Bug Bounty programs, and collaborating with engineering teams for prioritization and remediation.
- Conduct comprehensive threat modeling with engineering teams to analyze solutions, ensure designs meet security industry standards, and identify potential attack vectors.
- Manage security incident response by reviewing penetration testing results and SIEM reports, translating technical findings into actionable remediation tasks, and tracking resolution.
- Optimize security infrastructure by applying updates to Web Application Firewalls (WAF) and other security systems, aligning configurations with current threats and organizational needs.
- Drive security tool evaluation and implementation, researching, recommending, and leading procurement processes for security software solutions.
- Provide security consultation and guidance as a subject matter expert to development teams, integrating security best practices into the software development lifecycle and architectural decisions.
- Maintain security awareness and documentation by communicating updates, progress reports, and recommendations to stakeholders, and keeping security policies and procedures current.
Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent professional experience.
- Minimum 3+ years of professional experience specifically in web application security.
- Demonstrated expertise with security testing tools such as Burp Suite or similar web request analysis and tampering tools.
- Strong written communication skills in English, capable of clearly explaining technical security concepts to diverse audiences.
- Experience working effectively in fully distributed/remote team environments.
- Proven ability to collaborate cross-functionally with engineering and development teams.
Preferred Skills and Qualifications
- Previous hands-on experience managing or participating in Bug Bounty programs.
- Programming experience in PHP or JavaScript.
- Experience with penetration testing methodologies and tools.
- Knowledge of SIEM platforms and security monitoring systems.
- Familiarity with Web Application Firewall (WAF) configuration and management.
- Understanding of secure software development lifecycle (SDLC) practices.
- Experience with Jira or similar project management and issue tracking systems.
- Strong sense of ownership and accountability in a flat organizational structure.
- Passion for continuous learning and staying current with evolving security threats and technologies.
About the Opportunity
- This is a full-time opportunity.
- We are 100% remote (work from anywhere!).
- This role is open to candidates who can work in [region/timezone].
Learn more about us:

