About the company
Finoa is a regulated crypto asset platform for institutional investors co-founded in 2018 by Christopher May and Henrik Gebbing. The company came to life through the shared aspiration to make institutional interactions with crypto assets simple and secure, and is backed by prominent investors, including Balderton Capital, Coparion, Maven11, Signature Ventures, and Venture Stars. Finoa has since then grown into a truly international company, powered by a diverse team and serving high-profile clients from around the world. Reference clients include renowned venture capital firms, crypto hedge funds, corporates, Web3 companies, and high-net-worth individuals. If you want to join one of Europeās most exciting crypto start-ups, be part of the next wave of innovation disrupting finance, and grow together with us, then this is your chance to apply. Finoa is an equal opportunity employer devoted to diversity and inclusion in the workplace. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, or disability status.
Job Summary
In this role, you will:
šIntegrate SCA, SAST, and DAST tools into CI/CD pipelines to ensure secure software development. šImplement Zero-Trust security principles across infrastructure, ensuring robust access controls and identity management. šDesign and deploy secure and scalable secrets management solutions to protect sensitive data. šDevelop comprehensive threat models for all services, identifying and mitigating potential risks. šConduct frequent penetration testing of internal applications and services to identify vulnerabilities proactively. šEstablish unified vulnerability management pipelines, integrating and standardizing security data from multiple sources. šEnsure compliance with industry security standards, including SOC 2, ISO 27001, and NIST frameworks. šCollaborate with development and operations teams to advocate for security best practices and secure coding principles. šAutomate security-related tasks, leveraging scripting and security orchestration techniques. šResearch and implement emerging security technologies, particularly in blockchain and cryptographic security.
What you need to be successful:
šExperience in deploying and managing SAST, DAST, and SCA tooling within CI/CD environments. šStrong knowledge of secure coding practices, threat modeling, and cryptography. šExpertise in blockchain security and application security methodologies. šHands-on experience with AWS security best practices and cloud-native security solutions. šProven track record in vulnerability assessments, penetration testing, security monitoring, and incident response. šFamiliarity with key management solutions and Privileged Access Management (PAM) systems. šExperience working with HSMs (Hardware Security Modules) or other secure computational technologies.
The future of finance is here ā whether youāre interested in blockchain, cryptocurrency, or remote web3 jobs, thereās a perfect role waiting for you.