Senior DevSecOps Engineer
BLOCKCHAINSAbout the role
OUR VISION
In the new and exciting world of the decentralized internet, otherwise known as Web3, it is an individual’s fundamental right to own and control their digital identity. To ensure that the individual is paramount in Web3, we are developing a suite of applications to enable everyone to safely engage, take part, and transact in the emerging, decentralized world of the internet. Our platform centers on Web3 Identity and leverages that identity to provide individuals with secure digital asset storage and recovery, access to decentralized finance, the ability to prove ownership of their creations, and gateways to digital interactions and experiences – all to empower and benefit every Web3 user.
We believe that the decentralized nature of Web3 creates an opportunity for everyone to challenge the digital status quo—to own and control their identity, data, finances, creations, and future. This is the chance to get it right – to rally a movement of individuals so Web3 belongs to everyone, not to trillion-dollar companies. To fulfill this vision, we are seeking dynamic people who want to join us in leading the way to this new world.
WHAT YOU WILL DO
As a key member of the Cyber/IT team with robust interaction across other functions – Product, Engineering and GRC – the DevSecOps Engineer will be critical to the realization of DevSecOps principles and best practices at Blockchains. The key responsibility of the role is to provide leadership in the DevSecOps areas of Vulnerability Scanning, coordination of Remediation Patching, and other daily Security and Compliance efforts in software engineering, builds and deployments. The ideal candidate has tactical skills in development and IT operations experience as well as demonstrable cybersecurity savvy –a security-first mindset – and can analyze issues, articulate solutions, coach/mentor responsibilities for key functional groups, and catalyze action to advance us on our journey to DevSecOps excellence.
- Manage app-sec lifecycle of architecture, tooling, and operations:
- Work productively with Engineering, Product and Cyber/IT teams to accelerate momentum for CI/CD pipeline automation – from tooling and governance (process, procedures, and playbooks) perspectives – and motivate app-sec champions to own and drive adherence to standards. Serve as point of contact for product teams on all such matters.
- Enable and champion constant refinement in DevSecOps practices, including automation of SAST, DAST, IAST, MAST along with threat modeling, code peer reviews, penetration testing, security remediation and security monitoring/incident response enablement.
- Direct experience building and maintaining CI/CD pipelines and automating manual processes, preferably in Gitlab.
- Direct experience implementing and maintaining SAST and DAST tools like Sonarqube Sonar, BlackDuck, Snyk, OWASP ZAP, Rapid7 InsightAppSec.
- Assist in the development, definition and sustainment of security standards and best practices around a zero-trust approach.
- Align cross-functionally on issues and direction, clearly communicated, and mobilize action across teams and per consensus on an action plan to ensure code and operational integrity.
- Responsible for vulnerability management, and core contributor to exception and release management – and driver of applicable reporting across platforms and products.
- Work on cross-functional Cyber/IT, GRC and Engineering projects:
- Identify new tools or innovate on existing provisions, tooling or procedural, to drive new efficiencies and to augment impact of DevSecOps capacity and performance.
- Identify and propose controls for risks, technical or operational, crafting appropriate governance apparatus for review, refinement, and adoption by team(s) upon approval.
- Serve as a coach to enable security champions and raise awareness – in peer-to-peer training, workshops, or less structured initiatives – of DevSecOps principles and practices, and work with team members across functions to drive corresponding tactics.
WHAT YOU WILL NEED TO SUCCEED
To ensure success, you must have a passion for all things IT, Cybersecurity, and DevSecOps with a security first mindset. You are a diligent collaborator who is equally technical, and business minded. You are knowledgeable in taking a risk-based approach to prioritize efforts. You can assist in leading efforts to improve the overall application security program and availability of systems. You can work with numerous cross-functional teams in a fast paced, growing company. Strong verbal and written communication skills. Experience in blockchain technologies would be a plus.
YOUR EDUCATION AND EXPERIENCE
- Bachelor’s degree and relevant work experience
- 10 + years
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s