Tournament & Competition Integrity
Design the integrity architecture for large-scale synchronous competitions: server-authoritative scoring, verifiable game outcomes, and tamper-evident result pipelines.
Detect and prevent score injection, result forgery, replay attacks, and clock/latency manipulation in real-time brackets.
Build defenses against multi-accounting, collusion, account sharing, and Sybil attacks on qualification and elimination rounds.
Define fairness controls for prize-bearing events, including anomaly review workflows before payouts are released.
Mobile Game Security & Anti-Cheat
Design client-side and server-side controls to detect bots, automation, input replay, memory manipulation, code injection, and modified or repackaged app clients.
Implement and operate device attestation (Apple App Attest / DeviceCheck, Google Play Integrity), root/jailbreak detection, emulator detection, and device fingerprinting.
Evaluate and integrate commercial mobile app-hardening / RASP and anti-cheat capabilities where appropriate.
Server-Side Integrity
Partner with gameplay engineers to make server-authoritative validation the default for critical game logic, scoring, and transactions.
Review APIs, WebSocket services, and real-time protocols for tampering, replay, authorization, and abuse risks.
Develop reusable security controls for rate limiting, session integrity, and transaction validation.
Fraud & Abuse Prevention
Build systems to detect account takeover, payment and payout fraud, chargeback abuse, account farming, promotion abuse, and virtual-asset laundering.
Protect prize disbursement: eligibility verification, geo/age restrictions on prize competitions, and coordination with KYC and payments teams on winner payouts.
Collaborate with fraud, finance, legal, data, and player-support teams to investigate coordinated abuse and reduce losses.
Translate abuse patterns into durable product controls and detection logic.
Telemetry & Detection Engineering
Develop security services, automation, and internal tooling (Python and/or TypeScript).
Build telemetry pipelines, detection rules, dashboards, and behavioral analytics for cheating, botting, fraud, and coordinated abuse — designed for extreme spikes (a million concurrent players in a minutes-long event).
Improve alert fidelity and maintain measurable coverage across player, application, and infrastructure signals.
Security Assessment & Incident Response
Conduct threat modeling, penetration testing, secure code reviews, and security assessments of mobile clients, APIs, and backend services.
Research emerging cheat tooling, mobile-tampering techniques, and gray-market services targeting prize competitions.
Triage and lead technical response to active exploits, cheating campaigns, fraud, and DDoS during live events, including real-time decisions on disqualification and event integrity.
Create response playbooks and drive post-incident improvements with Engineering, Legal, Communications, and Player Support.