About the company
Interested in working on cutting-edge blockchain technology and creating equitable access to the global financial system? Since 2014, the mission-driven team at the Stellar Development Foundation (SDF) has helped fuel the tremendous growth of the Stellar blockchain network, an open-source platform that operates at high-scale today. Developers and companies around the world build on it, and the SDF team is expanding to support the rapidly growing and changing Stellar ecosystem. The launch of Soroban, the new smart contracts platform designed to work well with Stellar, brings a wealth of opportunity for innovation. When you join SDF as a Community Manager, you will be a part of a team thatās leveraging that opportunity to increase developer participation in order to bootstrap the ecosystem of tools, protocols, dapps, and educational resources necessary for Soroban to succeed.
Job Summary
In this role you will:
šLead efforts to improve our security vulnerability management programs both proactively (audits, etc) and reactively (bug bounties, etc) šEstablish a security framework (processes, training, etc) with engineering teams to incorporate security during all phases of application development lifecycle. šBuild a strong "security minded" community for the long term. Expanding our security framework to the broader community as to help secure the Stellar Ecosystem. šIdentify gaps in tools and automation in the Stellar Ecosystem, and help close those gaps by leveraging all SDF resources available (legal, business partnerships, grants, or developed in house).
You have:
š8+ years of experience on a SecOps, AppSec team and/or Software development team. šStrong understanding of security libraries and common security flaws. šHands on development experience with various languages. Being able to understand and work with a new language is a plus. šA strong track record working in a collaborative environment šExperience consulting with external vendors šExperience with MITRE, NIST, OWASP frameworks šExperience with common security / pen testing tools, nmap, Burp Suite šExperience with automated security scanners: Nessus, Qualys, Synk šA strong understanding of OSI protocols such as TCP/IP, UDP, HTTP, HTTPS šA good understanding of Cloud Infrastructure access controls and best practices. šA good understanding of Linux šExperience performing security testing using fuzzing techniques