обновлено 16 дней назад
Principal Security Engineer, Detection & Response (Blockchain, Cloud Security & AI)
110 000 - 170 000€
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Security Engineer, Detection & Response (Blockchain, Cloud Security & AI): Building detection coverage and incident response capabilities across blockchain and custody environments, AWS/EKS infrastructure, and internal AI tooling with an accent on crypto-native threats, cloud attacks, and AI-specific risks. Focus on leading incident response, developing SIEM/SOAR and detections-as-code capabilities, and defending against smart contract abuse, container exploitation, and agentic workflow threats.
Location: Ireland; remote work
Base pay range: €110,000–€170,000 per year
Company
builds digital asset, payment, stablecoin, and programmable blockchain infrastructure for global financial innovation.
What you will do
- Lead detection and response projects across blockchain, custody, cloud, endpoint, and AI environments.
- Build coverage for on-chain anomalies, wallet abuse, custody-vault interactions, smart contract exploitation, and protocol-level attacks.
- Develop AWS and EKS detections for IAM compromise, identity federation abuse, lateral movement, runtime exploitation, and configuration drift.
- Detect AI-related risks including shadow AI, unauthorized integrations, agentic workflows, MCP/tool abuse, and AI-driven credential exposure.
- Advance AI use in SOC triage, enrichment, and analyst-acceleration workflows while maintaining SIEM and SOAR platforms.
- Lead incident investigations, provide security guidance, and participate in threat modeling, vulnerability scanning, audits, and custom tool development.
Requirements
- 10+ years of experience in detection, response, or security engineering.
- 3+ years of experience commanding security incidents, particularly incidents involving engineering teams.
- Deep AWS security experience covering IAM, identity federation, KMS, EKS, container attack patterns, runtime exploitation, and CSPM tooling.
- Working knowledge of blockchain and crypto-native threats, including custody attacks, wallet abuse, on-chain monitoring, protocol risks, and smart contract exploitation.
- Hands-on experience with AI tooling and organizational AI risks, plus extensive knowledge of SIEM, case management, SOAR, and Detections As Code.
- Programming experience in Python, Golang, or similar languages, with knowledge of macOS operating systems, file systems, and memory.
Nice to have
- Experience with GCP or OCI.
- Direct experience defending blockchain, custody, or DeFi infrastructure.
- Exposure to insider risk.
Culture & Benefits
- Flexible remote work environment focused on integrity, future-oriented thinking, collaboration, mindfulness, and excellence.
- On-call duty mainly during working hours, with occasional nighttime and weekend incident support.
- On-call shifts occur approximately every third week, with occasional weekend coverage.
- Cross-functional collaboration in a rapidly changing security environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →