Hard Rock Digital
Hard Rock Digital

Principal Product Security Engineer

This job is no longer available and isn't accepting applications.

TLDR

Own the full arc of product security from code to production, setting priorities and driving outcomes across an end-to-end program.

What are we building?

Hard Rock Digital is a team focused on becoming the best online sportsbook, casino, and social gaming company in the world. We’re building a team that resonates passion for learning, operating, and building new products and technologies for millions of consumers. We care about each customer interaction, experience, behavior, and insight and strive to ensure we’re always acting authentically.

Rooted in the kindred spirits of Hard Rock and the Seminole Tribe of Florida, Hard Rock Digital taps a brand known the world over as the leader in gaming, entertainment, and hospitality. We’re taking that foundation of success and bringing it to the digital space - ready to join us?

What's the Position?

We're looking for a Principal Product Security Engineer to own the security of Hard Rock Bet — our sportsbook and casino — from the first line of code to production: how we design and build secure software, and how we find, prioritize, and close vulnerabilities once they exist. Full-lifecycle ownership, not a narrow slice of the pipeline — real autonomy, real accountability for outcomes.

You'll be one of three Principal Engineers — Product Security, Identity, and Cloud & Network Security — hired as direct reports to our VP Security / CISO, inside a 16-person security organization. It's a highly regulated, highly targeted business — player data, real-money transactions, wagering integrity — your work directly protects players and our license to operate.

If you like owning a problem end to end and making the secure path the fast path to production, this role is built for you.

What You'll Do

Secure SDLC & DevSecOps

  • Embed automated checks across our cloud (GitHub Actions) and on-prem product pipelines — GitHub Advanced Security (SAST/SCA) and Wiz Code for application, dependency, and container scanning

  • Define secure-by-default patterns, paved-road guardrails, and standards for secure coding, code review, and dependency hygiene — so teams ship quickly and safely

  • Serve as the application authority for our Zero Trust program, aligned to NIST SP 800-207 and the CISA Zero Trust Maturity Model (Applications & Workloads pillar)

Threat Modeling & Secure Design

  • Partner with product and engineering on security reviews for new features and payment integrations — running threat modeling (e.g., STRIDE) early in design and turning output into concrete, prioritized work

Vulnerability Management (End to End)

  • Own the product and application vulnerability lifecycle — one program spanning code, dependency, container, pen-test, and bug-bounty findings, from discovery through remediation

  • Prioritize by real-world risk and drive remediation against risk-based SLAs; engineering owns the fixes, you own the program and the escalation paths that shrink time to remediate

  • Report program health with metrics leadership can act on, and provide evidence for compliance obligations (PCI DSS, GLI, ISO 27001, SOC 2)

  • Where this role ends: our Principal Cloud & Network Security Engineer owns cloud misconfiguration and runtime posture; you own the application layer — code, dependencies, and containers — on one shared prioritization model

Application & API Security

  • Defend our applications and APIs against the OWASP Top 10 and API abuse, partner on payment security across our payment gateways, and team with our Principal Cloud & Network Security Engineer — who owns our Cloudflare edge defenses (WAF, Bot Management) — on bot and abuse resilience

  • Own the application security of player-facing account flows — registration, authentication, session management, recovery — partnering with our Principal Identity Engineer on CIAM architecture and with SecOps and Fraud on account-takeover resilience

Testing & External Assurance

  • Coordinate penetration testing with external partners and drive findings to closure

  • Mature our existing coordinated-disclosure program into a full bug-bounty capability

  • This is a big charter by design — year one is about sequencing, not doing it all at once. You'll set priorities with the CISO; with GitHub Advanced Security, Wiz, and Cloudflare already live, you're building a program, not standing up scanners from zero.

Requirements

What are we looking for?

  • 10+ years in application or product security — or equivalent practical experience

  • Deep expertise across the AppSec toolchain: SAST, SCA, and secure code review

  • Strong command of the vulnerability management lifecycle: triage, prioritization, remediation tracking, metrics

  • Hands-on threat modeling and secure-design partnership with engineering teams

  • Working knowledge of a modern programming language and how real applications are built and deployed

  • Experience with CI/CD pipelines and cloud-native application security (our products run primarily on AWS)

  • Excellent communication — you turn a finding into a clear, prioritized ask

  • Fluency with AI — you lead with it, reaching for AI tools daily to work faster and sharper; hands-on experience applying AI to security or engineering work is a must

You don't need to tick every box. If you're deep in AppSec but still building the vulnerability-management program muscle — or the reverse — we want to hear from you.

Bonus Points

  • Experience in a regulated industry (gaming, financial services, healthcare) — especially payments/PCI DSS or gaming standards (GLI-19, GLI-33)

  • Experience running or maturing a bug-bounty or responsible-disclosure program

  • DAST or API security testing experience — you'll help decide where it fits our stack

  • Relevant certifications (e.g., OSCP, GWAPT, CSSLP, CISSP)

Who You Are

  • An end-to-end owner — as comfortable in a design review as chasing a CVE to closure

  • A developer's ally — you make secure the easy choice rather than the slow one

  • Fiercely focused — detail-oriented about risk, pragmatic about what to fix first

  • Deeply curious — you dig past the obvious answer and keep learning as the attack surface shifts

  • Customer obsessed — motivated by protecting real players and real money at scale

Why This Role Is Different

You'll own the full arc of product security — not filing findings for someone else to prioritize while another team chases remediation. You set priorities, see the consequences of your own calls, and build a program that fits how our engineering teams actually work — reporting directly to our VP Security / CISO. A principal seat, not a function buried three layers down.

This is one of three Principal openings reporting to our VP Security / CISO: Identity (who and what gets access), Cloud & Network Security (where workloads run and how traffic moves), and Product Security (the code and its vulnerabilities). Apply to the one that sounds like your Tuesday.

What’s in it for you?

We offer our employees more than just competitive compensation. Our team benefits include:

  • Competitive pay and benefits

  • Flexible vacation allowance

  • A hybrid / remote working environment

  • Startup culture backed by a secure, global brand

Roster of Uniques

We care deeply about every interaction our customers have with us, and trust and empower our staff to own and drive their experience. Our vision for our business and customers is built on fostering a diverse and inclusive work environment where regardless of background or beliefs you feel able to be authentic and bring all your talent into play. We want to celebrate you being you (we are an equal opportunity employer).

Benefits

Flexible Work Hours

Flexible vacation allowance

Startup culture

Startup culture backed by a secure, global brand

Paid Time Off

Flexible vacation allowance

Remote-Friendly

A hybrid / remote working environment

Hard Rock Digital is building an online sportsbook, casino, and social gaming platform that caters to millions of consumers. With a foundation rooted in the renowned Hard Rock brand and the Seminole Tribe of Florida, we are focused on creating innovative products and maximizing authentic customer experiences in the digital gaming space.

View company profile
No longer accepting applications

This job is no longer available