Application Security and Infrastructure Protection Administrator
Summary
Lead application security and infrastructure protection at VENU+, embedding security into the SDLC and DevSecOps pipelines while managing vulnerability remediation, incident response, compliance, and risk across cloud, web, mobile, API, and SaaS platforms that power the company's entertainment, gaming, and venue technology products.
At VENU+, work feels like play — but with purpose.
As the global leader in creating unforgettable guest experiences, we combine entertainment, gaming, souvenirs, mobility, and storage solutions to bring more excitement, engagement, and convenience to the world’s top destinations. From ScooterPals® Fur-Wheelers and claw machines to photo capture, arcade games, and smart lockers, our creative programs help venues operate more efficiently, elevate guest satisfaction, and increase revenue — all with ease. Guided by collaboration, innovation, and a passion for excellence, we empower our team members to grow, contribute, and make a meaningful impact.
If you’re seeking a career that’s dynamic, rewarding, and full of opportunity, you’ll find it at VENU+.
At VENU+, we believe great work deserves meaningful rewards. Our benefits are designed to support your health, financial security, and overall well-being — so you can thrive both personally and professionally:
Benefits Available to Qualifying Full-Time and Part-Time Employees:
-
Flexible Time Off – Paid time off that allows you to take the time off you need, along with paid holidays.
-
Health & Wellness Coverage – Comprehensive medical, dental, and vision plans.
-
Retirement Planning – 401(k) plan with 50% company match on the first 6% contributed, including Roth options
-
And more!!
Grow your career with great benefits—and even better people!
Job Summary:
The Application Security Administrator is a hands-on individual contributor responsible for administering security controls that protect VENU+ applications, cloud platforms, infrastructure, data, and user access. This role partners with software development, IT operations, vendors, and business stakeholders to identify vulnerabilities, strengthen system configurations, support secure software delivery, maintain audit readiness, and respond to security events. The position has no direct reports and serves as a technical security resource across the technology lifecycle.
Key Responsibilities:
- Administer and monitor application, cloud, infrastructure, identity, endpoint, and data-protection security controls.
- Perform and coordinate vulnerability scanning, secure-configuration reviews, risk validation, remediation tracking, and closure verification across applications and infrastructure.
- Support application security testing through SAST, DAST, software composition analysis, dependency scanning, API testing, penetration-test coordination, and manual validation as appropriate.
- Partner with developers and technical teams to integrate security into requirements, design reviews, code-review practices, CI/CD pipelines, release processes, and production support.
- Review security findings, eliminate false positives, assign risk-based priorities, document recommended fixes, and verify remediation before closure.
- Apply and maintain security baselines using recognized practices such as OWASP, CIS Controls and Benchmarks, NIST guidance, and vendor hardening standards.
- Support identity and access administration, including role-based access, least privilege, privileged access, multifactor authentication, access reviews, and timely provisioning or deprovisioning.
- Monitor security alerts, logs, dashboards, and system health; investigate suspicious activity and participate in incident response, containment, recovery, root-cause analysis, and corrective-action tracking.
- Assist with cloud and SaaS security, patching, certificates, encryption, secrets protection, backup validation, recovery readiness, and remediation of unsupported or end-of-life technology.
- Maintain security procedures, runbooks, system and asset records, audit evidence, third-party risk documentation, exception records, metrics, status updates, and practical security guidance for technical and business teams.