Security / DevSecOps Engineer (Blockchain-Fintech)
About the Role Security is foundational architecture at our company. We're looking for a DevSecOps engineer who lives at the intersection of blockchain security and cloud infrastructure, and can embed security thinking into every stage of our development pipeline.
Responsibilities
Design and maintain CI/CD pipelines with integrated SAST, DAST, and SCA tooling
Conduct threat modeling, vulnerability assessments, and smart contract security reviews
Build automated security controls across AWS/GCP infrastructure (IAM, secrets management, network policies)
Monitor for incidents, anomalies, and on-chain threats; develop response playbooks
Own container and Kubernetes security hardening
Partner with engineering on secure-by-default coding practices
Ensure compliance with SOC 2, GDPR, and applicable financial security frameworks
Requirements
4+ years in security engineering or DevSecOps, with at least 1 year in a blockchain/Web3 context
Hands-on experience with smart contract auditing tools (Slither, MythX, Echidna) or willingness to ramp quickly
Proficiency in Python, Go, or Solidity for scripting and tooling
Strong command of cloud security (AWS or GCP preferred), Docker, Kubernetes
Experience with Gnosis Safe, multi-sig wallet infrastructure, and key management systems is a major plus
Certifications (CISSP, CEH, AWS Security Specialty) are nice to have, not required
Compensation: $160K–$200K base + equity