DevOps Engineer
Security Engineer (DevSecOps)
Удалённоfulltime
Откликнуться на сайте работодателяОписание вакансии
Security Engineer (DevSecOps)
Full-time · Hybrid / Remote-friendly
About us
We are a group of regulated fintech and cryptocurrency companies. Security isn’t a feature for us — it’s the foundation the business stands on.
About the role
You will be one of two founding security hires, working alongside a GRC Manager under the CISO: they own the compliance framework and audit calendar; you own the technical engineering and evidence that makes compliance real. This is a hands-on, high-ownership individual-contributor role in an environment governed by PCI DSS Level 1, ISO 27001, SOC 2, and CCSS.
You’ll have direct access to standalone security tooling — scanners, WAF/CDN security rules, cloud security posture tools — and work through a specify → implement → verify loop with DevOps and R&D for anything embedded in infrastructure or application code they own. You define what must change and verify it changed; they implement in their systems. It’s a deliberate model that keeps change control clean in a regulated environment, and it means your requests need to be sharp — which is why we need someone with a real infrastructure background, not just a scanner operator.
What you’ll do
In priority order:
• Be the security–engineering liaison — translate security requirements and audit-driven requests from the CISO into scoped engineering tasks; implement within your own security tooling scope; route infrastructure and code changes to DevOps and R&D as tracked, well-specified requests; verify outcomes and report status proactively.
• Produce technical compliance evidence — cloud config exports, access reviews, network posture, scan results, change records, CI/CD execution logs — audit-ready, on the GRC Manager’s calendar and to their specifications.
• Run offensive security and validation — internal vulnerability scanning; reproduce and validate external pen test findings; verify remediation; challenge false positives with evidence; coordinate ASV scans and pen test cycles technically.
• Own CI/CD security gate outcomes — triage findings from pipeline gates (SAST, dependency/container scanning, SBOM); define checks and pass/fail thresholds; manage and monitor implementation of gate changes by their owners; package outputs as compliance evidence.
• Assess cloud and edge posture — research the cloud and CDN/WAF stack, find and test drift and misconfigurations, prioritize by risk, verify remediation; direct ownership of WAF security rules and posture tooling.
• Run vulnerability management end to end — scanning, triage, prioritization, fix coordination, closure verification.
• Co-build security monitoring — co-implement the detection layer of our agentic, Kubernetes-native monitoring platform with DevOps; contribute and execute detection logic; investigate what it surfaces.
• Support incident response — technical investigation, log analysis, containment under CISO direction.
What you’ll bring
• Solid DevOps / infrastructure foundation: AWS, Kubernetes, CI/CD, infrastructure-as-code, Linux — the specify→verify model only works when the specifier deeply understands the systems.
• Hands-on experience with offensive security tooling — penetration testing tools, red team frameworks, vulnerability scanners (e.g. Nessus, Burp Suite, Metasploit, Nmap, OpenVAS) — able to run scans, validate findings, and reproduce reported vulnerabilities.
• Shell scripting and automation (Bash).
• The communication muscle this role runs on: you can take “the assessor needs proof these controls exist” and come back with the right export, correctly scoped, first time.
• Sound judgment with elevated access and credentials; least-privilege discipline.
Nice to have
• 2+ years in a security-titled seat (security engineering, vulnerability management, AppSec).
• Offensive certifications: OSCP, eJPT, PNPT or equivalent.
• Exposure to audit evidence production (PCI DSS, ISO 27001, SOC 2) — knowing what evidence looks like is a genuine differentiator.
• Python for security automation and tooling.
• Tooling: Trivy, SonarQube, Dependency-Track, GuardDuty, Defender, Cloudflare security.
• SIEM / detection engineering (Microsoft Sentinel).
• Interest in LLM/AI systems and their security.
• Fintech, payments, or crypto background.
Why join
• Founding hire: direct line to the CISO and real influence over the security roadmap — you’re not ticket #4 in a queue.
• Full breadth: offensive work, evidence, cloud posture, detection, incident response — not a narrow slice.
• A modern AI-assisted security stack whose detection layer you’ll co-build from close to the ground up.
• A GRC counterpart who owns the paperwork side of compliance, so your audit involvement stays technical.
Это сохранённая копия объявления, опубликованного в другом месте. Вакансии снимают без предупреждения — перед откликом проверьте сайт работодателя. mentors.coach не является нанимающей стороной.