Fanatics

Senior Staff Security Engineer

Fanatics$167K — $275K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years in security engineering or related field
  • 6+ years hands-on software engineering experience
  • Expertise in application security, SDLC, and API security
  • Experience securing AI systems and managing AI-specific threats
  • Proficient in AWS security services and implementation
  • Hands-on experience with WAF platforms and rule development
  • Experience with infrastructure as code tools like Terraform or Ansible

Responsibilities

  • Set secure architecture strategy for various environments including cloud and on-premises
  • Lead threat model reviews for complex services and AI systems
  • Define the organization's approach to AI security and model pipelines
  • Contribute production code for security tooling and product features
  • Provide security oversight across multiple product teams and architecture reviews
  • Drive security coding programs supporting version-controlled environments
  • Mentor senior engineers to enhance the security engineering capabilities

Benefits

  • Comprehensive benefits package including health insurance
  • Opportunity for cultural immersion in New York City
  • Participation in a structured onboarding program
  • Access to continuous professional development and training resources
  • Support for relevant certifications and educational growth
Full Job Description
About the Team

As a Senior Staff Security Engineer on the Fanatics Ecosystems Security team, you'll operate across the full breadth of our security domains, spanning application, AI, cloud, identity, and edge security. You'll lead security reviews, deliver impactful tooling in close partnership with engineering teams, and drive security programs with efficiency and scale.
Responsibilities
  • Set the secure architecture strategy across product and enterprise environments, including
    on-premises, cloud, and containerless environments, establishing patterns and guardrails that other
    engineers and security teams build on, with a primary focus on application security and AI/ML
    system security
  • Lead threat model reviews for the most complex services and AI systems, including LLM-integrated
    products, agentic workflows, and model supply chains. (Be an Enabler)
  • Define and evolve the org's approach to AI security, securing model pipelines, data and trust
    boundaries, third-party model integrations, and AI attack surfaces
  • Contribute production code to product features and internal security tooling as a hands-on
    engineering partner
  • Act as the technical escalation point across security domains, including AppSec, cloud, identity,
    CI/CD, and AI, providing efficient security input across multiple product teams and architecture
    reviews simultaneously
  • Drive and scale security coding programs supporting immutable, version-controlled environments
    through infrastructure as code, detection as code, and other engineering security initiatives
  • Mentor senior and staff level engineers, raising the security engineering bar across the organization
  • Represent security in cross-functional and executive level architecture discussions, translating
    technical risk into business impact
  • Participate in an on-call rotation to provide 24/7 support for incident escalations, serving as an
    escalation lead for the most complex incidents
Experience and Skills
  • 12+ years of experience in security engineering or a related field, including 6+ years of hands-on
    software engineering experience
  • Required: Strong proficiency developing and reviewing code in one or more programming
    languages, including Python, Java, or Go
  • Deep expertise in application security, including secure SDLC integration, SAST/DAST/IAST tooling,
    manual code review, and API security.
  • Demonstrated experience securing AI systems, including LLM application security, prompt injection
    defenses, data governance, secure agentic tool use, and emerging AI-specific threats
  • Demonstrated expertise implementing AWS security services and best practices (CloudTrail,
    GuardDuty, CloudWatch, Security Hub) at scale across multi-account environments
  • Hands-on experience managing WAF platforms (Cloudflare, Akamai, Fastly, AWS WAF or equivalent),
    including custom rule development, not just enabling managed rulesets
  • Demonstrated experience leveraging infrastructure as code with tools such as Terraform or Ansible,
    including designing secure module patterns and policy-as-code guardrails
  • Experience with identity management protocols (OAuth, SAML, OpenID Connect) and designing
    identity architecture across multiple business units or products
  • Deep understanding of secure CI/CD pipeline design, able to define what a good release pipeline
    looks like, why each stage exists, and how to harden against supply chain and pipeline compromise
  • Track record of influencing security strategy and roadmap at an organizational level, not just
    executing within a single team
  • Relevant certifications such as OSCP, OSWE, OSCE, or CISSP

Depending on the role, your interview and onboarding experience may include in-person components, such as onsite interviews or Launching into Better: LIVE-a multi-day cultural immersion in New York City for full-time, non-seasonal hires. These sessions are designed to build connection and bring our culture to life, though specific travel and participation requirements will be confirmed based on your role and location. Your recruiter will provide clear guidance at each stage of the process.

For information about our benefits, please visit https://benefitsatfanatics.com/

Ranges will change based on country and state of residence, which are reflected in Geographical Zones defined by Fanatics Betting and Gaming. The range incorporates all of our Geographical Compensation Zones and is subject to change as the Zone associated with the actual offer is confirmed. In addition to the base and bonus, full-time employment, and more. For information about our benefits, please visit https://benefitsatfanatics.com/

Salary Range

$167,000-$275,000 USD

About Fanatics

Fanatics is a leading retailer of licensed sports merchandise. The company was founded in 1995 and has grown to become the largest online retailer of officially licensed sports merchandise in the world. Fanatics offers a wide range of products, including jerseys, hats, and other apparel, as well as collectibles and memorabilia. The company has partnerships with all major sports leagues and teams, as well as with individual athletes. Fanatics is committed to providing a seamless shopping experience for its customers and has invested heavily in technology and logistics to ensure fast and reliable delivery.
Learn more about Fanatics
Size
5,000 employees
Industry
Founded
1995

Similar Jobs

More Jobs at Fanatics

More Information Technology Jobs

Find similar Senior Staff Security Engineer jobs: