Назад
Company hidden
1 день назад

Product Security Engineer (Crypto)

Формат работы
remote (Global)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Product Security Engineer (Crypto): Building secure applications, cloud infrastructure, APIs, and development workflows with an accent on application security, cloud security, and Secure SDLC automation. Focus on threat modeling, securing Kubernetes and microservices, integrating security checks into CI/CD pipelines, and solving complex vulnerabilities across web and mobile platforms.

Location: Worldwide; remote or hybrid with flexible hours across international teams

Company

hirify.global operates a crypto-focused product platform with distributed international teams.

What you will do

  • Review application architectures and new product features, conduct threat modeling, and perform security design reviews.
  • Identify and help remediate vulnerabilities across backend services, REST APIs, microservices, web platforms, and mobile applications.
  • Build and improve Secure SDLC practices, security automation, and developer security workflows.
  • Deploy and maintain SAST, DAST, dependency scanning, container scanning, and secret detection in CI/CD pipelines.
  • Secure cloud infrastructure and Kubernetes environments, including IAM, secrets management, networking, and infrastructure hardening.
  • Partner with Platform, DevOps, and software engineering teams while supporting penetration testing activities and technical security decisions.

Requirements

  • 4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering.
  • Strong software engineering background with experience securing backend systems, REST APIs, and microservices.
  • Experience with AWS, GCP, or Azure, plus Kubernetes, Docker, networking, and infrastructure security.
  • Hands-on experience with Secure SDLC, security automation, SAST, DAST, dependency scanning, and secrets management.
  • Knowledge of OWASP Top 10, common attack vectors, and secure coding practices; mobile application security experience is required.
  • Fluent English required. Experience in fintech, crypto, payments, or blockchain and offensive security or penetration testing experience are required.

Nice to have

  • Security certifications.

Culture & Benefits

  • Remote or hybrid work with flexible hours across international teams.
  • Up to 20 vacation days, 8 company holidays, and 5 personal days per year.
  • Up to 100% coverage for professional courses, conferences, and English learning.
  • Structured performance reviews and team recognition programs.
  • International team retreats, including stays in company apartments in Cyprus.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →