Staff Product Security Engineer
at Crunchyroll, LLC
Los Angeles, United States
About Crunchyroll
Founded by fans, Crunchyroll delivers the art and culture of anime to a passionate community. We super-serve over 100 million anime and manga fans across 200+ countries and territories, and help them connect with the stories and characters they crave. Whether that experience is online or in-person, streaming video, theatrical, games, merchandise, events and more, it’s powered by the anime content we all love.
Join our team, and help us shape the future of anime!
About the role
Crunchyroll is growing and changing, presenting unique challenges and opportunities to support millions of anime fans around the world. The Fan Experiences Services & Tools team provides seamless help to our partners and internal stakeholders, ensuring an exceptional experience for all Crunchyroll fans.
Our charter is focused on helping our internal and external teams around the world integrate, test, and deploy the Crunchyroll applications quickly and with the highest levels of quality. We do this with tools and infrastructure that optimize the developer experience. We tie it all together with sophisticated automated testing and productivity solutions designed to support our culture of experimentation, autonomy and ownership. Our goal is to focus on delivering the best possible anime fan experience.
You will:
-
Security Strategy & Leadership: Lead, mentor, and grow the Application Security team. Define the long-term roadmap for Mobile, Desktop, and Game security to proactively mitigate reverse engineering, piracy, and cheating.
-
Binary Defense Architecture: Oversee the design and implementation of binary protection strategies. Direct the evaluation and integration of anti-tamper, obfuscation, and RASP solutions (e.g., Promon, Guardsquare) ensuring minimal impact on game FPS, app performance and user experience.
-
Game Integrity & Anti-Cheat: Collaborate with game studios to design "server-authoritative" economies and implement client-side detections for memory manipulation, touch macros, and modded APKs.
-
Trust & Identity Management: Architect robust chains of trust for the ecosystem. Manage code signing certificates, secure boot processes, and the integration of hardware-backed storage (TEE) for sensitive keys.
-
Vulnerability Research & Validation: Lead internal or external "red team" initiatives using reverse engineering tools (IDA Pro, Frida) to simulate attacks against our apps and games. Validate the effectiveness of binary defenses and attestation checks before release.
-
Content Protection Engineering: Collaborate with media engineering to harden DRM implementations (Widevine, FairPlay). Ensure secure handling of media keys and enforce output protection (HDCP).
In the role of Staff Product Security Engineer, you will report to the Senior Director of Fan Experience Engineering Service & Tools. We are considering applicants for the location of Dallas, Los Angeles, or San Francisco.
About You
We get excited about candidates, like you, because you have...
-
Binary Application Construction: Solid understanding of how applications are constructed, including compilers, linkers, dynamic loaders, ABI interaction, and executable formats (ELF, Mach-O, PE).
-
Game Engine & Anti-Cheat Security: Solid understanding of Unity (IL2CPP) and Unreal Engine security architectures. Experience designing defenses against game-specific attacks: memory editors (GameGuardian), speed hacks, wallhacks, and protecting asset integrity (AssetBundles).
-
Cryptography & Chain of Trust: Comprehensive experience with cryptographic primitives (hashing, digests) and Public Key Infrastructure (PKI), including managing digital certificates and establishing chains of trust for code signing and secure boot.
-
Anti-Tamper & Ecosystem: Proven track record evaluating and implementing commercial shielding (Promon, Guardsquare, Verimatrix) and platform attestation (Google Play Integrity, Apple App Attest) for both apps and games.
-
Content Protection & DRM: Experience with Google Widevine, Apple FairPlay, and Microsoft PlayReady, including HDCP enforcement and screen recording prevention.
-
Reverse Engineering & Analysis: Hands-on experience with tools (IDA Pro, Ghidra, Frida, Il2CppDumper) to simulate attacks, analyze game logic, and validate the resilience of binary protections.
-
TBD: Mobile Security Standards: Relevant certifications OWASP MASVS and the OWASP Mobile Top 10, with the ability to map these standards to engineering roadmaps.
-
Web & Network Security: Experience securing web standards within application contexts, including HTTPS/TLS, cookie security (Secure, HttpOnly, SameSite), local storage, and Content Security Policy (CSP).
-
Hybrid App & WebView Security: Expert handling of WebView bridges (WKWebView), ensuring secure data exchange between native and web contexts.
-
Hardware-Backed Security: Experience utilizing TEEs (Secure Enclave, TrustZone, TPM) for secure key storage, cryptographic operations, and offline license management.
-
DevSecOps & Supply Chain: Experience automating security (SAST/DAST) within CI/CD pipelines and managing third-party SDK risks (supply chain attacks).
About the Team
The Fan Experiences Engineering team at Crunchyroll plays a pivotal role in enhancing and expanding our users' experiences. We collaborate extensively with a diverse network of device, payment, and gaming partners to broaden the reach of Crunchyroll's offerings. Our primary objective is to drive growth, open up new acquisition channels, and optimize both the scope and quality of our services. Situated at the crossroads of technology and business, we are dedicated to continually enabling experiences that delights our fans.
Why you will love working at Crunchyroll
In addition to getting to work with fun, passionate and inspired colleagues, you will also enjoy the following benefits and perks:
- Receive a great compensation package including salary plus performance bonus earning potential, paid annually.
- Flexible time off policies allowing you to take the time you need to be your whole self.
- Generous medical, dental, vision, STD, LTD, and life insurance
- Health Saving Account HSA program
- Health care and dependent care FSA
- 401(k) plan, with employer match
- Employer paid commuter benefit
- Support program for new parents
- Pet insurance and some of our offices are pet friendly!
#LifeAtCrunchyroll #LI-Hybrid
About our Values
We want to be everything for someone rather than something for everyone and we do this by living and modeling our values in all that we do. We value
-
Courage. We believe that when we overcome fear, we enable our best selves.
-
Curiosity. We are curious, which is the gateway to empathy, inclusion, and understanding.
- Kaizen. We have a growth mindset committed to constant forward progress.
-
Service. We serve our community with humility, enabling joy and belonging for others.
Our commitment to diversity and inclusion
Our mission of helping people belong reflects our commitment to diversity & inclusion. It's just the way we do business.
We are an equal opportunity employer and value diversity at Crunchyroll. Pursuant to applicable law, we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Crunchyroll, LLC is an independently operated joint venture between US-based Sony Pictures Entertainment, and Japan's Aniplex, a subsidiary of Sony Music Entertainment (Japan) Inc., both subsidiaries of Tokyo-based Sony Group Corporation.
Questions about Crunchyroll’s hiring process? Please check out our Hiring FAQs: https://help.crunchyroll.com/hc/en-us/articles/360040471712-Crunchyroll-Hiring-FAQs
Please refer to our Candidate Privacy Policy for more information about how we process your personal information, and your data protection rights: https://tbcdn.talentbrew.com/company/22978/v1_0/docs/spe-jobs-privacy-policy-update-for-crpa-dec-21-22.pdf
Please beware of recent scams to online job seekers. Those applying to our job openings will only be contacted directly from @crunchyroll.com email account.
