Create New Account
Sign up to continue searching for suitable jobs in Web 3.0

OR
Terms of Use
Already have an account?

Log In to Your Account
Log in to continue searching for suitable jobs in Web 3.0

OR
Don’t have an account?
MoonPay
Senior Security Engineer - Automation
atĀ MoonPay
about 2 hours ago | 8 views | Be the first one to apply

Senior Security Engineer - Automation

Full-time
Hybrid, United States

About the company

MoonPay is the world’s leading web3 infrastructure company. We provide end-to-end solutions for payments, enterprise-scale smart contract development, and digital asset management. Many of the world’s most iconic brands rely on MoonPay to power their web3 strategies and ideas.

Job Summary

About the role:

MoonPay is the world's leading web3 infrastructure company, providing end-to-end solutions for payments, enterprise-scale smart contract development, and digital asset management. Many of the world's most iconic brands rely on MoonPay to power their web3 strategies and ideas.

Our Product Security Squad is a dynamic blend of proactive defenders and inquisitive problem-solvers dedicated to fortifying our systems through rigorous security reviews, hands-on penetration testing, and proactive threat modelling. As a Security Automation & Vulnerability Management Engineer, you will focus on embedding security seamlessly into our Software Development Lifecycle (SDLC).

Responsibilities:

šŸ“Design, implement, and manage the integration of security tooling (SAST, DAST, SCA, Secrets Scanning) into our CI/CD pipelines. šŸ“Develop and maintain automation scripts and platforms to streamline security processes and workflows. šŸ“Own and operate the end-to-end vulnerability management lifecycle: identification, triage, prioritization, distribution, tracking, and reporting. šŸ“Collaborate closely with engineering teams to ensure timely remediation of identified vulnerabilities and provide guidance on secure coding practices. šŸ“Drive the adoption and implementation of the SLSA framework to enhance supply chain security. šŸ“Continuously evaluate and improve existing security automation and vulnerability management workflows. šŸ“Research emerging threats and vulnerabilities, translating findings into actionable detection or prevention mechanisms. šŸ“Develop and maintain documentation for security automation tools, processes, and vulnerability management procedures. šŸ“Assist in triaging and validating findings from automated scanners, penetration tests, and bug bounty programs. šŸ“Contribute to security training materials focused on secure development practices. šŸ“Support incident response activities, particularly where automation or vulnerability data can aid investigation and remediation. šŸ“Champion and execute the security team's automation strategy for cross-functional needs.

Requirements:

šŸ“Solid background in software development with demonstrable experience in languages common in backend or infrastructure development (e.g., Go, Python, Node.js). šŸ“Strong passion for cybersecurity with a focus on security automation and vulnerability management. šŸ“Understanding of security tools like SAST, DAST, SCA, and secrets scanning solutions within a CI/CD environment. šŸ“Understanding of vulnerability management principles, including prioritization frameworks (e.g., CVSS) and remediation tracking. šŸ“Familiarity with the concepts and goals of the SLSA framework or similar supply chain security initiatives. šŸ“Strong analytical and problem-solving skills, with the ability to identify inefficiencies and propose automated solutions. šŸ“Self-motivated, innovative, and able to operate effectively in a remote, fast-paced environment. šŸ“Deep understanding of GitHub's functionalities, including advanced features, security settings, and API capabilities. šŸ“Strong administrative skills in managing and maintaining GitHub Enterprise environments. šŸ“Familiarity with GitHub Actions for workflow automation and security enforcement.

Nice-to-have: šŸ“Experience working in disruptive technology, FinTech, SaaS, or Crypto sectors. šŸ“Familiarity with cloud security principles (AWS, GCP).

If this role isn't the perfect fit, there are plenty of exciting opportunities in blockchain technology, cryptocurrency startups, and remote crypto jobs to explore. Check them on our Jobs Board.

Similar jobs

about 2 hours ago | 5 views | Be the first one to apply
Full-time
Onsite, India
about 2 hours ago | 8 views | Be the first one to apply
Full-time
Remote, New York, Hybrid
about 2 hours ago | 6 views | Be the first one to apply
Full-time
Hybrid, Remote, New York
3 days ago | 38 views | Be the first one to apply
Full-time
United States, Hybrid
3 days ago | 46 views | Be the first one to apply