Назад
Company hidden
обновлено 34 минуты назад

Security Engineer (Web3)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer (Web3) (DevSecOps and Cloud Security): Hardening CI/CD pipelines, cloud infrastructure, identity systems, and endpoint security while managing security operations and bug bounty workflows with an accent on hands-on engineering, vulnerability remediation, and protocol security. Focus on threat modeling architectural changes, integrating SAST/DAST and supply-chain controls, investigating incidents, and building tooling for faster vulnerability response.

Location: On-site in Cayman, Denver, or New York; daily in-office work is required

Company

Product-focused engineering organization working across infrastructure, protocol, and platform security.

What you will do

  • Own daily security operations, including monitoring, alerting, triage, incident investigation, and response.
  • Manage endpoint security detections and incidents through an EDR platform.
  • Lead identity lifecycle processes, including onboarding, offboarding, access provisioning, key rotation, and deprovisioning.
  • Own the ImmuneFi bug bounty program, triage submissions, reproduce issues, and coordinate vulnerability remediation.
  • Audit and harden CI/CD pipelines, dependency security, secrets management, supply-chain integrity, build provenance, and SAST/DAST integration.
  • Review cloud environments and architectural changes, implement security tooling, and manage external security vendors.

Requirements

  • 5–8+ years of experience in software and security engineering, including DevSecOps or security operations.
  • Strong software engineering fundamentals and the ability to write production code.
  • Hands-on experience hardening CI/CD pipelines such as GitHub Actions or CircleCI.
  • Experience securing cloud infrastructure using AWS, GCP, or an equivalent platform.
  • Proficiency with endpoint security tooling such as CrowdStrike or an equivalent EDR.
  • Experience owning identity and access management workflows and communicating security risks to technical and non-technical stakeholders.

Nice to have

  • Previous experience as a software engineer before specializing in security.
  • Experience with a DeFi protocol, crypto exchange, or blockchain infrastructure company.
  • CTF or security competition experience.
  • Contributions to open-source security tooling.

Culture & Benefits

  • Hands-on, builder-first security role embedded directly in the engineering organization.
  • Close collaboration with infrastructure, protocol, and platform teams.
  • Opportunity to shape security standards across the software development lifecycle.
  • Responsibility for evaluating and onboarding security tooling as the threat landscape evolves.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →