About the company
MoonPay is the worldās leading web3 infrastructure company. We provide end-to-end solutions for payments, enterprise-scale smart contract development, and digital asset management. Many of the worldās most iconic brands rely on MoonPay to power their web3 strategies and ideas.
Job Summary
About the role:
MoonPay is the world's leading web3 infrastructure company, providing end-to-end solutions for payments, enterprise-scale smart contract development, and digital asset management. Many of the world's most iconic brands rely on MoonPay to power their web3 strategies and ideas.
Our Product Security Squad is a dynamic blend of proactive defenders and inquisitive problem-solvers dedicated to fortifying our systems through rigorous security reviews, hands-on penetration testing, and proactive threat modelling. As a Security Automation & Vulnerability Management Engineer, you will focus on embedding security seamlessly into our Software Development Lifecycle (SDLC).
Responsibilities:
šDesign, implement, and manage the integration of security tooling (SAST, DAST, SCA, Secrets Scanning) into our CI/CD pipelines. šDevelop and maintain automation scripts and platforms to streamline security processes and workflows. šOwn and operate the end-to-end vulnerability management lifecycle: identification, triage, prioritization, distribution, tracking, and reporting. šCollaborate closely with engineering teams to ensure timely remediation of identified vulnerabilities and provide guidance on secure coding practices. šDrive the adoption and implementation of the SLSA framework to enhance supply chain security. šContinuously evaluate and improve existing security automation and vulnerability management workflows. šResearch emerging threats and vulnerabilities, translating findings into actionable detection or prevention mechanisms. šDevelop and maintain documentation for security automation tools, processes, and vulnerability management procedures. šAssist in triaging and validating findings from automated scanners, penetration tests, and bug bounty programs. šContribute to security training materials focused on secure development practices. šSupport incident response activities, particularly where automation or vulnerability data can aid investigation and remediation. šChampion and execute the security team's automation strategy for cross-functional needs.
Requirements:
šSolid background in software development with demonstrable experience in languages common in backend or infrastructure development (e.g., Go, Python, Node.js). šStrong passion for cybersecurity with a focus on security automation and vulnerability management. šUnderstanding of security tools like SAST, DAST, SCA, and secrets scanning solutions within a CI/CD environment. šUnderstanding of vulnerability management principles, including prioritization frameworks (e.g., CVSS) and remediation tracking. šFamiliarity with the concepts and goals of the SLSA framework or similar supply chain security initiatives. šStrong analytical and problem-solving skills, with the ability to identify inefficiencies and propose automated solutions. šSelf-motivated, innovative, and able to operate effectively in a remote, fast-paced environment. šDeep understanding of GitHub's functionalities, including advanced features, security settings, and API capabilities. šStrong administrative skills in managing and maintaining GitHub Enterprise environments. šFamiliarity with GitHub Actions for workflow automation and security enforcement.
Nice-to-have: šExperience working in disruptive technology, FinTech, SaaS, or Crypto sectors. šFamiliarity with cloud security principles (AWS, GCP).
If this role isn't the perfect fit, there are plenty of exciting opportunities in blockchain technology, cryptocurrency startups, and remote crypto jobs to explore. Check them on our Jobs Board.




