About this role
SeatGeek believes live events are powerful experiences that unite humans. With our technological savvy and fan-first attitude we’re simplifying and modernizing the ticketing industry.
SeatGeek is looking for a security engineering professional for our Security team. As a Senior Software Engineer, Security, you’ll be involved in a mix of security engineering, product security, incident response, and a trace of red teaming.
You’ll be involved with critical security initiatives that strengthen our secure-by-default posture across our platform, products, and company. You’ll pair architectural guidance with hands-on engineering — building paved roads, tooling, and automated detection/response that scale. You’ll operate in a fast-paced, collaborative environment, partnering with both engineering and non-engineering teams to reduce risk without slowing builders down. As a senior engineer, you'll own meaningful work end-to-end and help make the secure path the easy path — from cloud and code to laptops, identity, email, and awareness — including the AI tools reshaping how we build.
If this role sounds interesting to you, we encourage you to apply even if your experience doesn’t match every requirement - we value curiosity, collaboration, and a willingness to learn!
What you'll do
• Build and contribute to secure-by-default protections across the stack (cloud, CI/CD, applications, and endpoints) by creating paved roads and guardrails that make the secure path the easy path within your problem space
• Provide practical security guidance on new products and technologies, recommending secure-by-default patterns that fit into existing workflows
• Help secure SeatGeek's use of AI — from LLM-assisted development to AI-powered product features — by building guardrails and reviewing for risks like prompt injection, sensitive-data exposure, and insecure model and tool integrations
• Contribute to design reviews and threat modeling for high-impact features and services; surface risks early and help ensure mitigations are designed in
• Build security tooling that prevents issues at build/deploy time and helps automate detection and response in production
• Improve our detection and incident response capabilities — raise signal quality, tune detections, and implement automated responders that reduce manual toil and time to contain
• Partner with engineering and business teams on cross-functional security work: endpoint and device trust, identity and email protections, security awareness and training, vendor reviews and risk assessments, and supporting compliance efforts (e.g., PCI/SOX)
• Protect SeatGeek from abuse and bots at the edge and app layers through layered defenses and tuning
• Contribute to security incidents and tabletops, including writing incident reviews; help improve runbooks, processes, and stakeholder communications afterward
• Advocate for strong secure coding practices and contribute to a pragmatic, positive security culture across