findGamejobs
All game jobs

Senior Security Research Engineer

PlayStation · Engineering

  • United States, Remote
  • Remote
  • Posted Aug 7, 2026

Why Sony Interactive Entertainment?

Sony Interactive Entertainment isn’t just the Best Place to Play — it’s also the Best Place to Work. Sony Interactive Entertainment (SIE) is the company behind the PlayStation brand. As a subsidiary of Sony Group Corporation, we’re part of a proud legacy of innovation and excellence. SIE is a dynamic technology company, delivering cutting-edge hardware and network services to more than 100 million people and an entertainment leader, home to some of the most beloved and recognizable intellectual properties (IP) in the world. Our role at SIE is to create and nurture the experiences under the PlayStation brand, a name synonymous with entertainment excellence and creativity.

Reporting to the Director of Global Vulnerability Management, you will serve as a Senior Security Research Engineer and technical lead within SIE’s Global Vulnerability Management team. You will lead complex work that advances our Threat Exposure Management capability and supports our transition to a Continuous Threat Exposure Management operating model, while remaining directly engaged in vulnerability research, analysis, security validation, prioritization, and remediation support.

You will partner across Information Security, engineering, technology, and business teams to improve how SIE discovers, prioritizes, validates, and mobilizes action on security risks. You will translate annual TEM goals into defined workstreams, delivery plans, success measures, and repeatable operating practices that improve visibility, decision-making, remediation outcomes, and program scale.

Responsibilities

  • Lead complex Global Vulnerability Management workstreams that advance SIE’s Threat Exposure Management capability and transition toward a Continuous Threat Exposure Management operating model across discovery, prioritization, validation, and mobilization.
  • Translate annual TEM goals into defined delivery plans, milestones, success measures, dependencies, and repeatable operating practices. Monitor progress, identify barriers, and adjust execution to improve outcomes.
  • Lead hands-on vulnerability research and technical analysis to confirm security conditions, eliminate false positives, characterize exploitability and business impact, and provide actionable remediation or mitigation guidance.
  • Improve the discovery and assessment of vulnerabilities across SIE network, cloud, endpoint, application, container, and other technology environments.
  • Develop risk-based prioritization using vulnerability and threat intelligence, exploitation evidence, asset and business context, control effectiveness, and remediation considerations.
  • Lead security validation activities and develop proofs of concept when appropriate to distinguish material risk, evaluate defensive controls, and support informed decisions.
  • Partner with Information Security teams and technology owners to mobilize remediation, clarify ownership, establish effective handoffs, resolve barriers, and measure progress through remediation, mitigation, or accepted disposition.
  • Evolve GVM platforms, integrations, data, analytics, automation, and AI-enabled workflows to improve coverage, data quality, consistency, decision speed, and operational scale.
  • Communicate vulnerability trends, material risks, remediation progress, and program outcomes to technical, operational, and leadership audiences through clear reports and recommendations.
  • Mentor engineers and partner teams, contribute to technical standards and procedures, and improve the quality of vulnerability analysis, validation, documentation, and delivery.
  • Maintain current knowledge of relevant vulnerabilities, exploitation techniques, threat activity, security technologies, and industry practices.
  • Some travel may be required.

Qualifications

  • 8+ years of relevant experience in information security, information technology, systems engineering, or a related field, including substantial experience in vulnerability management, security research, or exposure management.
  • Bachelor’s degree or equivalent in computer science, information security, or a related discipline.
  • Experience leading complex technical workstreams across multiple teams, translating objectives into delivery plans, and achieving measurable outcomes without relying on direct reporting authority.
  • Hands-on experience with vulnerability research, technical analysis, security validation, risk-based prioritization, and remediation or mitigation guidance.
  • Experience assessing vulnerabilities across several technology domains, such as operating systems, networks, cloud services, applications, endpoints, containers, databases, or hybrid infrastructure.
  • Experience with vulnerability discovery, assessment, validation, or exposure-management platforms and their supporting integrations.
  • Knowledge of adversarial tactics, exploitation techniques, threat intelligence, and attack frameworks such as MITRE ATT&CK, with the ability to apply that information to vulnerability prioritization.
  • Experience using scripting, programming, APIs, or automation to improve security analysis and operational workflows. Relevant technologies may include Python, SQL, Bash, PowerShell, JavaScript, or comparable languages.
  • Experience analyzing and contextualizing security data to connect technical findings with asset, service, business, threat, control, and remediation information.
  • Familiarity with software engineering practices such as version control, testing, code review, CI/CD, reusable components, and controlled production releases.
  • Ability to communicate complex security conditions, priorities, tradeoffs, and recommendations clearly to technical, operational, and leadership audiences.
  • Experience mentoring engineers or analysts and influencing technical practices across teams.

Desired qualifications

  • Experience helping evolve a traditional vulnerability-management function toward a TEM or CTEM operating model.
  • Experience with continuous security validation, adversarial exposure validation, exploit research, or proof-of-concept development.
  • Experience securing cloud, container, application, or build-pipeline environments and integrating security capabilities into engineering workflows.
  • Experience with security-data and analytics platforms such as Snowflake, Domo, or comparable technologies.
  • Experience applying automation, advanced analytics, or AI-enabled capabilities to vulnerability analysis, prioritization, validation, or remediation workflows.

At SIE, we consider several factors when setting each role’s base pay range, including the competitive benchmarking data for the market and geographic location.

Please note that the base pay range may vary in line with our hybrid working policy and individual base pay will be determined based on job-related factors which may include knowledge, skills, experience, and location.

In addition, this role is eligible for SIE’s top-tier benefits package that includes medical, dental, vision, matching 401(k), paid time off, wellness program and coveted employee discounts for Sony products. This role also may be eligible for a bonus package. Click here to learn more.

This is a flexible role that can be remote, with varying pay ranges based on geographic location. For example, if you are based out of Seattle, the estimated base pay range for this role is listed below.

$175,500 — $263,300 USD

Please note, Sony Interactive Entertainment conducts background checks at the offer stage for all new employees (which may include criminal background checks for some roles) and will need to process personal information to support these checks.

Please refer to our Candidate Privacy Notice for more information about what personal information we collect, how we use it, who we share it with, and your data protection rights.

Equal Opportunity Statement:

Sony is an Equal Opportunity Employer. All persons will receive consideration for employment without regard to gender (including gender identity, gender expression and gender reassignment), race (including colour, nationality, ethnic or national origin), religion or belief, marital or civil partnership status, disability, age, sexual orientation, pregnancy, maternity or parental status, trade union membership or membership in any other legally protected category.

We strive to create an inclusive environment, empower employees and embrace diversity. We encourage everyone to respond.

Sony Interactive Entertainment is a Fair Chance employer and qualified applicants with arrest and conviction records will be considered for employment.

This listing comes from PlayStation's own job board and is shown as published. Checked Oct 6. Applications go directly to PlayStation.

More roles at PlayStation

  • Senior Cloud Security Engineer

    PlayStationNewPosted today

    Ireland, Dublin

    We are looking for an inspirational and hardworking person to join the Platform Hosting Cloud Security Engineering team at SIE! You'll be joining a team of innovative engineers…

    €88K – €132K

  • Senior Business Analyst, PlayStation Store

    PlayStationNewPosted yesterday

    United States, San Mateo, CA

    You will lead the business analysis workstream for complex commercial initiatives, working with business leaders and subject-matter experts to understand business objectives…

    $147K – $221K

  • Sr. Product Manager, Core Experience

    PlayStationNewPosted yesterday

    United States, San Mateo, CA

    This role is focused on leading core, user-facing and backend system software initiatives which are critical to the success of the PlayStation platform. We are looking for a…

    $169K – $253K

  • United Kingdom, London

    We’re looking for a Organic Growth Specialist to join our Growth Marketing team for an initial 6-12 month period. Please note this role has been assessed as Inside IR35, and…

    Salary not listed

  • Senior Accountant, e-Commerce (Contract)

    PlayStationPosted 3 days ago

    United States, San Mateo, CA

    The consultant will support full-cycle accounting for the online store, from customer orders and inventory movement through revenue, cost of goods sold, accounts receivable, cash…

    Salary not listed

    Contract

All PlayStation jobs

New game jobs, once a week

Follow the newest roles in your feed reader, Slack or Discord. RSS feeds