SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Fanatics is a leading global digital sports platform serving over 100 million sports fans worldwide. The company operates across three main pillars: Fanatics Commerce (licensed fan gear and merchandise), Fanatics Collectibles (physical and digital trading cards and memorabilia), and Fanatics Betting & Gaming (sportsbook and iGaming platform). With partnerships spanning 900 sports properties, 2,500 athletes and celebrities, and 2,000+ retail locations, Fanatics is reshaping how fans engage with sports.
As a Senior Staff Security Engineer on the Fanatics Ecosystems Security team, you will operate across the full breadth of security domains—application, AI, cloud, identity, and edge security. This is a hands-on technical leadership role where you'll set secure architecture strategy, lead threat modeling for complex services and AI systems, and drive security programs at organizational scale.
Key responsibilities include: establishing secure architecture patterns and guardrails across product and enterprise environments (on-premises, cloud, containerless); leading threat model reviews for complex services, LLM-integrated products, agentic workflows, and model supply chains; defining and evolving the organization's AI security approach; contributing production code to product features and internal security tooling; serving as technical escalation point across AppSec, cloud, identity, CI/CD, and AI domains; driving and scaling security coding programs through infrastructure-as-code and detection-as-code initiatives; mentoring senior and staff-level engineers; representing security in cross-functional and executive architecture discussions; and participating in on-call rotation for incident escalations.
You'll need 12+ years of security engineering experience with 6+ years of hands-on software engineering. Required skills include strong proficiency in Python, Java, or Go; deep application security expertise (secure SDLC, SAST/DAST/IAST, manual code review, API security); demonstrated experience securing AI systems (LLM application security, prompt injection defenses, data governance, agentic tool use); AWS security services expertise at scale; hands-on WAF platform management (Cloudflare, Akamai, Fastly, AWS WAF); infrastructure-as-code experience (Terraform, Ansible); identity management protocol expertise (OAuth, SAML, OpenID Connect); and deep understanding of secure CI/CD pipeline design. A track record of influencing security strategy at organizational level is essential.