Skip to main content
Unity

Senior Application Security Engineer

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Enterprise
DKK 702.2k–DKK 1053.4k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior application security engineer with 5+ years' AppSec experience for large-scale systems. Must be hands-on in secure code review, threat modeling, SAST/DAST/SCA and cloud security (GCP/AWS/Azure). Role works with engineering teams across US and EMEA.

Core skills

Threat modelingApplication securitySecure code review

Required skills

Secure design reviewsManual code reviewSASTDASTSCAPenetration testingVulnerability managementCloud security (GCP, AWS, or Azure)AuthenticationAuthorizationCryptographySecure architecture patternsAI-assisted code review / AI tooling

Optional skills

Experience in gaming industryExperience in ad techExperience in technology industry

Required languages

English Professional

What you'll do

  • Lead threat modeling, secure design reviews, and penetration testing for Unity products and services, from the engine and editor to cloud services, APIs, and internal platforms.
  • Perform deep code review and manual testing on high-risk systems, using AI-assisted review processes and covering areas automated tooling cannot fully reach.
  • Build and operate security automation.
  • Use and extend AI-assisted tooling for continuous code review, finding triage, and automated penetration testing, and step in where human judgment is required.
  • Secure Unity's AI and agentic systems; assess AI-native products, LLM integrations, and agent workflows for the risks specific to them.
  • Partner with engineering teams to drive remediation, turning recurring findings into guardrails, secure defaults, and paved paths.
  • Investigate and respond to application security incidents, including root cause analysis and durable corrective action.
  • Contribute to Unity's secure development lifecycle and to compliance work.

What they require

  • 5+ years in application security, with a track record on complex, large-scale systems.
  • Strong command of secure coding and common vulnerability classes (OWASP Top 10 and beyond).
  • Hands-on secure development experience across several languages.
  • Practical penetration testing, security assessment, and vulnerability management experience with standard tooling (SAST, DAST, SCA, and manual techniques).
  • Experience with Cloud security (GCP, AWS, or Azure).
  • Working knowledge of authentication, authorization, cryptography, and secure architecture patterns.
  • Clear technical communication for both engineers and non-technical partners across regions.

Benefits

  • Comprehensive health, life, and disability insurance
  • Commute subsidy
  • Employee stock ownership
  • Competitive retirement/pension plans
  • Generous vacation and personal days
  • Support for new parents through leave and family-care programs
  • Office food snacks
  • Mental Health and Wellbeing programs and support
  • Employee Resource Groups
  • Global Employee Assistance Program
  • Training and development programs
  • Volunteering and donation matching program

Unity [NYSE: U] is the world’s leading game engine, powering play for more than 3 billion consumers each month. Unity enables teams across industries like automotive, manufacturing, and healthcare to design, simulate, and collaborate in 3D.

GamingEnterpriseunity.com
DKK 702.2k–DKK 1053.4k/yr