Why this grade This listing scored 63/100, which is a C. It lost the most ground on pay transparency. See the breakdown
- Description depth 20 / 20 How much the posting actually says about the work, measured in characters of real text.
- Remote clarity 15 / 15 Whether "remote" means anywhere, or is quietly restricted to one country.
- Freshness 12 / 15 How recently it was posted. Older postings are likelier to be filled or abandoned.
- Corroboration 10 / 10 Whether more than one source carries this listing.
- Role specificity 6 / 10 Whether the listing is tagged well enough to tell what the role actually is.
- Pay transparency 0 / 25 A published salary range, worth more than any other single factor because it is what a candidate cannot find out without applying.
Every figure above is arithmetic over the posting itself — its salary field, its text, its age, its tags and how many sources carry it. How the grades work →
This listing does not state a salary
$112k – $155k
That is the middle half of what comparable roles paid on this board over the last 90 days — 50 listings that did publish a figure, median $136k. It is not this employer's offer, and we have no idea what they pay. It is only what the rest of the market advertised.
php javascript
About Us
Chess.com is one of the largest gaming sites in the world and the #1 platform for playing, learning, and enjoying chess.
We are a team of 600+ fully remote people in 60+ countries working hard to serve the global chess community. We are here to support 250M+ chess players worldwide with the best possible product, content, and tools to serve the community!
We are a tech company. A gaming company. A content company. And we do it all with passion and commitment to the game. Above all we prize our mission-driven, flat, life-celebrating, no-corporate culture, and we look forward to meeting you and learning more about what you can bring to the team.
About The Role
The Security Engineer plays a critical role in protecting our technology infrastructure and maintaining the security posture of our gaming platform. This position exists to proactively identify, assess, and mitigate security vulnerabilities while serving as a trusted security advisor to engineering teams across the organization. The role directly impacts our ability to safeguard user data, maintain platform integrity, and ensure secure development practices are embedded throughout our product development lifecycle.
This position is essential for building and maintaining robust security defenses in a fast-paced, remote-first technology environment where security expertise must be seamlessly integrated into daily engineering operations and strategic decision-making processes.
What you'll do
- Lead vulnerability management program by triaging, reproducing, and assessing security vulnerabilities submitted through Bug Bounty programs, working directly with engineering teams to prioritize and remediate discovered security gaps
- Conduct comprehensive threat modeling by collaborating with engineering teams to analyze proposed solutions, ensuring designs meet security industry standards and identifying potential attack vectors before implementation
- Manage security incident response by reviewing penetration testing results and SIEM reports, translating technical findings into actionable remediation tasks, and tracking resolution progress through completion
- Optimize security infrastructure by applying updates to Web Application Firewalls (WAF) and other security systems, ensuring configurations align with current threat landscape and organizational needs
- Drive security tool evaluation and implementation by researching, evaluating, and recommending security software solutions, attending vendor demonstrations, and leading procurement processes from requirements gathering through deployment
- Provide security consultation and guidance by serving as subject matter expert to development teams, ensuring security best practices are integrated into software development lifecycle and architectural decisions
- Maintain security awareness and documentation by communicating security updates, progress reports, and recommendations to stakeholders through established channels and maintaining current security policies and procedures
Qualifications
- Bachelor's degree in Computer Science, Information Security, or related technical field, or equivalent professional experience
- Minimum 3+ years of professional experience specifically in web application security
- Demonstrated expertise with security testing tools such as Burp Suite or equivalent web request analysis and tampering tools
- Strong written communication skills in English with ability to clearly explain technical security concepts to diverse audiences
- Experience working effectively in fully distributed/remote team environments
- Proven ability to collaborate cross-functionally with engineering and development teams
Preferred Skills and Qualifications
- Previous hands-on experience managing or participating in Bug Bounty programs
- Programming experience in PHP or JavaScript
- Experience with penetration testing methodologies and tools
- Knowledge of SIEM platforms and security monitoring systems
- Familiarity with Web Application Firewall (WAF) configuration and management
- Understanding of secure software development lifecycle (SDLC) practices
- Experience with Jira or similar project management and issue tracking systems
- Strong sense of ownership and accountability in a flat organizational structure
- Passion for continuous learning and staying current with evolving security threats and technologies
About the Opportunity
- This is a full-time opportunity
- We are 100% remote (work from anywhere!)
---
You can learn more about us here:
Apply for this role Opens ats.rippling.com — verified as the employer's own application page
Quick question · anonymous · one tap
Would you apply to this job?
Answer to see what other job seekers said.
Keep looking
Similar remote roles, still open
-
C
6h ago
Werkstudent (m/w/d) Schwachstellenmanagement: Von der SBOM zur Entscheidung
Langlauf Security Automation GmbH Lippstadt
-
C
22h ago
Senior Security Engineer, Identity and Access Management
HackerOne Netherlands, UK, USA
- D 19h ago
- C 1d ago
See every "Security Engineer" role →
Get new “Security Engineer” roles by email
One email a day with what is new in "Security Engineer". Nothing new, no email.
We confirm the address first, and every mail carries an unsubscribe link. Alerts are ours, not a third party's.
Your turn · no account needed
Help the next applicant
You may know something about this listing that we cannot see from here. One tap. No account needed. Signed-in reports earn points once the evidence agrees with you.
I know what it pays
Sign in with Google to earn points for reports — 100 confirmed points buy a week of Early Access.
Where this listing came from
- 15 Sep 2026 Company ATS employer ATS first sighting
- 01 Oct 2026 Real Work From Anywhere also listed, 16 days later
Seen on 2 boards over 24 days. The employer edited the description 1× since we first recorded it.