обновлено 48 минут назад
Engineering Lead (Web3 Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Engineering Lead (Web3 Security): Owning security across Somnia’s L1 infrastructure, applications, policies, incident response, and multisig key management with an accent on infrastructure hardening, application and supply-chain security, and cryptographic protection of critical assets. Focus on designing signing and treasury operations, building incident-response capability, securing validator and node operations, and coordinating audits and red-team exercises.
Location: Remote; based in a UK-friendly timezone (+/- 4 hours)
Company
is a Web3 product company developing a high-performance Layer 1 blockchain for real-time, autonomous, decentralized applications with native AI inference.
What you will do
- Own the security posture of L1 infrastructure, including validators, RPC, signing services, hosts, networks, pipelines, and monitoring.
- Define and implement access control, secrets management, secure SDLC, change management, and compliance-readiness standards.
- Drive application and supply-chain security through secure-by-default patterns, dependency scanning, build-pipeline security, and high-priority security reviews.
- Design and operate multisig governance, signing ceremonies, and key lifecycles for treasury, upgrades, and privileged operations.
- Build incident-response capabilities covering detection, triage, containment, forensics, postmortems, and tabletop exercises.
- Lead threat modeling, red-team exercises, external audits, bug bounties, and secure collaboration with infrastructure and L1 teams.
Requirements
- Extensive security engineering experience with deep infrastructure security and SecOps expertise at scale.
- Hands-on experience securing production systems with Linux internals, networking, containers, Kubernetes, and infrastructure as code.
- Experience defining and implementing security policies adopted by engineering organizations.
- Deep expertise in key management, signing workflows, HSMs, secrets management, and key generation, rotation, and recovery.
- Strong incident-response leadership skills, including detection, containment, forensics, and postmortems.
- Cryptography fundamentals applied to blockchain and key management, plus genuine interest in crypto and on-chain systems.
Nice to have
- Experience securing blockchain L1/L2 nodes and validator infrastructure.
- Production experience with multisig governance, treasury operations, EVM, smart contract security, and DeFi attack surfaces.
- Experience coordinating audits, bug bounties, responsible disclosure, red teaming, offensive security, or detection engineering.
- Experience with high-throughput or low-latency systems where security must preserve performance.
Culture & Benefits
- Remote work with a global team and a UK-friendly working-time overlap.
- Ownership and autonomy in a lean, outcome-oriented engineering organization.
- Agentic tooling is used to accelerate engineering, security testing, fixes, and feature delivery.
- Competitive compensation with token incentives.
- Technology choices include TypeScript, C++, Go, and Solidity.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →