About the company
Founded in Paris in 2014, LEDGER is a global platform for digital assets and Web3. Ledger is already the world leader in Critical Digital Asset security and utility. With more than 6M devices sold to consumers in 200 countries and 10+ languages, 100+ financial institutions and brands as customers, 20% of the worldās crypto assets are secured, plus services supporting trading, buying, spending, earning, and NFTs. LEDGERās products include: Ledger Stax, Nano S Plus, Nano X hardware wallets, LEDGER Live companion app, [ LEDGER ] Market, the worldās first secure-minting and first-sale distribution platform, and Ledger Enterprise. With its ease of use, LEDGER allows a user to begin investing in digital assets and ultimately, achieve financial freedom in a safe and stress-free environment.
Job Summary
The mission
šCollaborate with the Infrastructure, the engineering and the Donjon teams to integrate security into the delivery plans, ensure early detection and mitigation of security vulnerabilities
šWork closely with the Donjon, the product Security team responsible, to provide automation and tooling for product security evaluation integration in CI/CD pipeline.
šEngage in proactive security practices, including penetration testing, vulnerability assessments, and Infrastructure Security (IaC) code reviews to ensure Ledger's platforms and applications are secure.
šParticipate in the design and implementation of security architectures, from the design to the risk assessment.
šAct as the primary point of contact for any security incidents, ensuring rapid response, mitigation, and post-incident analysis.
šDrive the adoption of DevSecOps culture, best practices, and methodologies across the organization, ensuring continuous security improvement.
What we're looking for
š5+ years of experience in DevSecOps & automation, security assessment, and cloud-native environments. š8+ years of experience on information security šProficiency working in Unix/Linux environments, Git, Python, Terraform, Kubernetes, AWS cloud solutions and architectures, CI/CD tools, configuration management, etc. šHands-on experience with security tooling deployment, monitoring, and incident response. šProven track record of cross-functional work, with the ability to collaborate effectively with various teams and stakeholders. šExcellent presentation and written communication skills. šAbility to work autonomously, deal with ambiguity, and handle high-pressure situations.