Application Security Engineer
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, Systems Engineer, Security Manager
Overview
Flo Sports leads the way in delivering world-class digital streaming for millions of fans, families, and athletes in underserved sports. Our digital platform unites casual and dedicated spectators alike, offering thrilling live events from around the world with interactive features, real-time analytics, and powerful broadcast technology. As the essential destination for niche sports content, we deliver everything from breaking news and expert commentary to feature films, documentaries, and multi-episodic series.
We've revolutionized the global sports media industry by building a diverse team—technologists and wrestlers, creators and cheerleading experts, designers and hockey enthusiasts, communicators and motor sport fanatics, producers and sports fans—all united by our passion to serve underrepresented sports communities. We're creating the ultimate destination for our sports, and we're looking for people like you to join us!
THE ROLE:
At Flo Sports, we believe security should accelerate engineering, not slow it down. We're building an Application Security function that partners closely with our developers to ship secure code faster. This isn't about blocking deployments or creating friction—it's about enabling engineers to build with confidence.
As an Application Security Engineer, you'll be the bridge between our Security, SRE, and Engineering teams. You'll work hands-on with developers to identify vulnerabilities, integrate security tooling into our CI/CD pipelines, and help engineers understand and fix security issues before they reach production. You'll have a real impact on how we secure our platform for millions of streaming viewers.
This role is ideal for someone early in their App Sec career who has strong technical fundamentals, genuine curiosity about security, and the communication skills to partner effectively with developers. If you've been a developer who got interested in security, or a security practitioner who loves to code, you'll fit right in.
ResponsibilitiesPartner with Engineering on Security
- Work directly with development teams to triage, explain, and remediate security findings
- Conduct lightweight security reviews of code changes, architecture decisions, and new features
- Be a trusted resource that engineers actually want to consult—not a blocker they work around
Integrate Security into CI/CD
- Manage and optimize our security tooling: AWS Security Hub, Git Hub security features, and Aikido
- Build and maintain automated security checks in our deployment pipelines
- Reduce noise by tuning tools to surface real risks, not false positives
Drive Vulnerability Management
- Own the vulnerability lifecycle from discovery through remediation
- Prioritize findings based on actual risk to the business, not just CVSS scores
- Track metrics and report on security posture to leadership
Build Security Knowledge Across Engineering
- Create practical secure coding guidelines that developers will actually use
- Run lightweight training sessions and lunch-and-learns on common vulnerability patterns
- Document security patterns and anti-patterns specific to our stack
Grow Our App Sec Practice
- Help establish application security processes as we scale
- Contribute to security architecture decisions for new products and features
- Stay current on emerging threats and bring relevant insights to the team
Skills and Abilities
Technical Foundation
- 2+ years of experience in software engineering, Dev Ops, or security
- Solid understanding of web application security fundamentals (OWASP Top 10, common vulnerability classes)
- Hands-on experience with at least one programming language (Python, JavaScript/Node.js, Go, or similar)
- Familiarity with CI/CD pipelines and modern development workflows (Git Hub Actions, Helm, etc.)
Security Knowledge
- Understanding of secure coding practices and common vulnerability patterns
- Experience with or strong interest in security tools (SAST, DAST, SCA, or cloud security)
- Familiarity with AWS security services (Security Hub, IAM, Guard Duty) is a plus
- Knowledge of container security and Kubernetes is a plus
Mindset & Communication
- Genuine curiosity about security—you enjoy understanding how things break
- Stro…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).