Senior Software Engineer, Security
About the role
SeatGeek believes live events are powerful experiences that unite humans. With our technological savvy and fan-first attitude we’re simplifying and modernizing the ticketing industry.
SeatGeek is looking for a security engineering professional for our Security team. As a Senior Software Engineer, Security, you’ll be involved in a mix of security engineering, product security, incident response, and a trace of red teaming.
You’ll be involved with critical security initiatives that strengthen our secure-by-default posture across our platform, products, and company. You’ll pair architectural guidance with hands-on engineering — building paved roads, tooling, and automated detection/response that scale. You’ll operate in a fast-paced, collaborative environment, partnering with both engineering and non-engineering teams to reduce risk without slowing builders down. As a senior engineer, you'll own meaningful work end-to-end and help make the secure path the easy path — from cloud and code to laptops, identity, email, and awareness — including the AI tools reshaping how we build.
If this role sounds interesting to you, we encourage you to apply even if your experience doesn’t match every requirement - we value curiosity, collaboration, and a willingness to learn!
What you'll do
- Build and contribute to secure-by-default protections across the stack (cloud, CI/CD, applications, and endpoints) by creating paved roads and guardrails that make the secure path the easy path within your problem space
- Provide practical security guidance on new products and technologies, recommending secure-by-default patterns that fit into existing workflows
- Help secure SeatGeek's use of AI — from LLM-assisted development to AI-powered product features — by building guardrails and reviewing for risks like prompt injection, sensitive-data exposure, and insecure model and tool integrations
- Contribute to design reviews and threat modeling for high-impact features and services; surface risks early and help ensure mitigations are designed in
- Build security tooling that prevents issues at build/deploy time and helps automate detection and response in production
- Improve our detection and incident response capabilities — raise signal quality, tune detections, and implement automated responders that reduce manual toil and time to contain
- Partner with engineering and business teams on cross-functional security work: endpoint and device trust, identity and email protections, security awareness and training, vendor reviews and risk assessments, and supporting compliance efforts (e.g., PCI/SOX)
- Protect SeatGeek from abuse and bots at the edge and app layers through layered defenses and tuning
- Contribute to security incidents and tabletops, including writing incident reviews; help improve runbooks, processes, and stakeholder communications afterward
- Advocate for strong secure coding practices and contribute to a pragmatic, positive security culture across your team and partner teams
What you have
- 3+ years of broad, hands-on experience across multiple security domains, with strong software engineering fundamentals; track record of driving security projects end-to-end (from design through rollout and adoption)
- Proficiency in one or more programming languages (we use Python, Go, and C#); you write production-quality code and perform rigorous reviews for correctness and security
- Experience partnering across product, platform, and business functions to contribute to cross-team security outcomes
- Ability to build scalable, preventative security solutions across domains (platform/cloud, applications, CI/CD, identity and endpoints), favoring reusable guardrails over one-off fixes
- Ability to think like both an attacker and