Senior Security Engineer (Web3)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Security Engineer (Web3/Infrastructure): Securing cloud, network, and infrastructure-as-code for institutional-grade blockchain investment products with an accent on IaC guardrails, identity design, and runtime posture. Focus on implementing policy-as-code, executing offensive infrastructure testing, and securing the CI/CD supply chain.
Location: Remote (US)
Company
provides institutional-grade, blockchain-enabled investment products and services, specializing in the tokenization of real-world assets like US Treasuries.
What you will do
- Own and manage cloud security posture across AWS and GCP, focusing on IAM, network segmentation, and encryption.
- Design and enforce IaC guardrails using policy-as-code and CI gates to ensure secure defaults.
- Lead identity and access design across cloud and developer platforms to maintain a least-privilege environment.
- Conduct focused offensive testing, including cloud red-team scenarios and CI/CD supply-chain attack paths.
- Develop and implement a secrets management strategy to eliminate long-lived credentials.
- Mentor engineers on threat modeling and secure-by-default infrastructure patterns.
Requirements
- Must be authorized to work in the United States without sponsorship.
- 3-5+ years of experience in security engineering with a deep focus on cloud and infrastructure.
- Strong IaC skills with experience writing and refactoring Terraform at scale.
- Hands-on production experience with AWS, GCP, or Azure.
- Proficiency in scripting with Python or Go.
- Working knowledge of Kubernetes security, including RBAC and workload identity.
Nice to have
- Experience defending crypto, fintech, or other high-target environments.
- Experience with CI/CD security.
- Familiarity with the interaction between on-chain operations and off-chain infrastructure.
Culture & Benefits
- Competitive compensation including salary, future token rights, and/or equity.
- Comprehensive benefits package (medical, vision, and dental).
- Flexible vacation policy (PTO).
- Remote-first culture with a high-caliber team from companies like Goldman Sachs, Google, and Meta.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →