обновлено 34 минуты назад
Security Engineer (Web3)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Engineer (Web3) (DevSecOps and Cloud Security): Hardening CI/CD pipelines, cloud infrastructure, identity systems, and endpoint security while managing security operations and bug bounty workflows with an accent on hands-on engineering, vulnerability remediation, and protocol security. Focus on threat modeling architectural changes, integrating SAST/DAST and supply-chain controls, investigating incidents, and building tooling for faster vulnerability response.
Location: On-site in Cayman, Denver, or New York; daily in-office work is required
Company
Product-focused engineering organization working across infrastructure, protocol, and platform security.
What you will do
- Own daily security operations, including monitoring, alerting, triage, incident investigation, and response.
- Manage endpoint security detections and incidents through an EDR platform.
- Lead identity lifecycle processes, including onboarding, offboarding, access provisioning, key rotation, and deprovisioning.
- Own the ImmuneFi bug bounty program, triage submissions, reproduce issues, and coordinate vulnerability remediation.
- Audit and harden CI/CD pipelines, dependency security, secrets management, supply-chain integrity, build provenance, and SAST/DAST integration.
- Review cloud environments and architectural changes, implement security tooling, and manage external security vendors.
Requirements
- 5–8+ years of experience in software and security engineering, including DevSecOps or security operations.
- Strong software engineering fundamentals and the ability to write production code.
- Hands-on experience hardening CI/CD pipelines such as GitHub Actions or CircleCI.
- Experience securing cloud infrastructure using AWS, GCP, or an equivalent platform.
- Proficiency with endpoint security tooling such as CrowdStrike or an equivalent EDR.
- Experience owning identity and access management workflows and communicating security risks to technical and non-technical stakeholders.
Nice to have
- Previous experience as a software engineer before specializing in security.
- Experience with a DeFi protocol, crypto exchange, or blockchain infrastructure company.
- CTF or security competition experience.
- Contributions to open-source security tooling.
Culture & Benefits
- Hands-on, builder-first security role embedded directly in the engineering organization.
- Close collaboration with infrastructure, protocol, and platform teams.
- Opportunity to shape security standards across the software development lifecycle.
- Responsibility for evaluating and onboarding security tooling as the threat landscape evolves.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Security Consultant (Cloud Security)
5 дней назад
Security Engineer (AI)
61 000 - 76 000€
2 дня назад
Staff Security Engineer (Fintech)
160 000 - 195 000$
2 дня назад
Security Engineering Manager (Cybersecurity)
170 000 - 200 000$
4 дня назад
Security Engineer (AI)
61 000 - 76 000€
Twilio
6 дней назад