Senior Red Team Operator (Web3)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Red Team Operator (Web3): Planning and executing full-scope adversary emulation across cloud, application, and crypto infrastructure with an accent on container security, CI/CD pipelines, and detection-evasion. Focus on building automated offensive tooling, partnering with blue teams for mitigation, and securing complex blockchain systems.
Location: Remote-first with offices in Toronto, New York, London, and Singapore. Open to candidates in Canada and the US, with global remote flexibility for other regions.
Salary: $165,000 – $180,000 USD/CAD
Company
is a leading provider of blockchain infrastructure and staking solutions, powering the decentralized future for institutional clients.
What you will do
- Plan and execute red team engagements, pentests, and ad-hoc assessments across cloud, web, and application layers.
- Apply attacker tactics, techniques, and procedures safely, including detection-evasion work.
- Partner with stakeholders and blue teams to communicate findings and recommend practical mitigations.
- Build and improve red team tooling, scripts, and infrastructure to reduce manual effort.
- Mentor blue team members and lead cross-team exercises like purple teaming.
- Support incident response with offensive security expertise and contribute to post-incident planning.
Requirements
- Strong understanding of cloud platforms, CI/CD pipelines, and supply chain security.
- Demonstrated use of AI tools to accelerate offensive work with sound judgment.
- Offensive expertise in container orchestration, specifically Docker and Kubernetes.
- Experience performing API, web application, and source code security assessments.
- Strong written and verbal communication skills for technical and executive audiences.
- Ability to build automations that chain red team tooling together.
Nice to have
- Industry certifications such as OSCP, OSCE, OSWE, GPEN, or GXPN.
- Experience with GitHub and GitHub Actions.
- Programming proficiency in Go, Rust, or Ruby.
- Understanding of security risks specific to blockchain and crypto.
Culture & Benefits
- 100% remote-first environment with optional office access.
- 4 weeks of PTO plus 1 week of flex days starting from day one.
- Extended company-paid health benefits and parental leave.
- Home office stipend and monthly Wi-Fi reimbursement.
- Yearly Learning & Development budget and stock options.
- Annual on-site company gatherings and retreats.
Hiring process
- Initial recruiter call to discuss the role and company.
- Organized interview process typically lasting 2–4 weeks.
- Thorough identity verification and background checks required.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →