Product Security Engineer
Listed on 2025-12-22
-
IT/Tech
Systems Engineer, Cybersecurity
Founded by fans, Crunchyroll delivers the art and culture of anime to a passionate community. We super-serve over 100 million anime and manga fans across 200+ countries and territories, and help them connect with the stories and characters they crave. Whether that experience is online or in‑person, streaming video, theatrical, games, merchandise, events and more, it’s powered by the anime content we all love.
Join our team, and help us shape the future of anime!
About the roleCrunchyroll is growing and changing, presenting unique challenges and opportunities to support millions of anime fans around the world. The Fan Experiences Services & Tools team provides seamless help to our partners and internal stakeholders, ensuring an exceptional experience for all Crunchyroll fans.
Our charter is focused on helping our internal and external teams around the world integrate, test, and deploy the Crunchyroll applications quickly and with the highest levels of quality. We do this with tools and infrastructure that optimize the developer experience. We tie it all together with sophisticated automated testing and productivity solutions designed to support our culture of experimentation, autonomy and ownership.
Our goal is to focus on delivering the best possible anime fan experience.
You will:
Security Strategy & Leadership: Lead, mentor, and grow the Application Security team. Define the long‑term roadmap for Mobile, Desktop, and Game security to proactively mitigate reverse engineering, piracy, and cheating.
Binary Defense Architecture: Oversee the design and implementation of binary protection strategies. Direct the evaluation and integration of anti‑tamper, obfuscation, and RASP solutions (e.g., Promon, Guardsquare) ensuring minimal impact on game FPS, app performance and user experience.
Game Integrity & Anti‑Cheat: Collaborate with game studios to design “server‑authoritative” economies and implement client‑side detections for memory manipulation, touch macros, and modded APKs.
Trust & Identity Management: Architect robust chains of trust for the ecosystem. Manage code signing certificates, secure boot processes, and the integration of hardware‑backed storage (TEE) for sensitive keys.
Vulnerability Research & Validation: Lead internal or external “red team” initiatives using reverse engineering tools (IDA Pro, Frida) to simulate attacks against our apps and games. Validate the effectiveness of binary defenses and attestation checks before release.
Content Protection Engineering: Collaborate with media engineering to harden DRM implementations (Widevine, Fair Play). Ensure secure handling of media keys and enforce output protection (HDCP).
In the role of Staff Product Security Engineer you will report to the Senior Director of Fan Experience Engineering Service & Tools. We are considering applicants for the locations of Dallas, Los Angeles, or San Francisco.
About YouBinary Application Construction: Solid understanding of how applications are constructed, including compilers, linkers, dynamic loaders, ABI interaction, and executable formats (ELF, Mach‑O, PE).
Game Engine & Anti‑Cheat Security: Solid understanding of Unity (IL2
CPP) and Unreal Engine security architectures. Experience designing defenses against game‑specific attacks: memory editors (Game Guardian), speed hacks, wallhacks, and protecting asset integrity (Asset Bundles).
Cryptography & Chain of Trust: Comprehensive experience with cryptographic primitives (hashing, digests) and Public Key Infrastructure (PKI), including managing digital certificates and establishing chains of trust for code signing and secure boot.
Anti‑Tamper & Ecosystem: Proven track record evaluating and implementing commercial shielding (Promon, Guardsquare, Verimatrix) and platform attestation (Google Play Integrity, Apple App Attest) for both apps and games.
Content Protection & DRM: Experience with Google Widevine, Apple Fair Play, and Microsoft Play Ready, including HDCP enforcement and screen recording prevention.
Reverse Engineering & Analysis: Hands‑on experience with tools (IDA Pro, Ghidra, Frida, Il2
Cpp Dumper) to simulate attacks, analyze game logic, and validate the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).