Job FunctionsImplementing and managing security tools within CI/CD pipelinesSecuring cloud environments with a focus on IAM, secrets management, and workload protectionProviding expert opinions to inform decisions and assist in evaluating, selecting, and implementing security tools and frameworks
Job Requirements5 years of professional experience as a DevSecOps engineerProven experience in securing AWS-based setups and Kubernetes clustersHands-on experience with security tools (e.g., OWASP ZAP, Nessus, Qualys)Familiarity with SIEM and other security platformsKnowledge of relevant regulatory standards (e.g., GDPR, SOC 2, ISO/IEC 27001)
SkillsProven experience in securing AWS-based setups and Kubernetes clustersHands-on experience with security tools (e.g., OWASP ZAP, Nessus, Qualys)Familiarity with SIEM and other security platformsKnowledge of relevant regulatory standards (e.g., GDPR, SOC 2, ISO/IEC 27001)Strong understanding of how PKI works, as well as SSL and TLS protocolsProven experience in securing AWS-based setups and Kubernetes clustersHands-on experience with security tools (e.g., OWASP ZAP, Nessus, Qualys)Familiarity with SIEM and other security platforms
As a Senior DevSecOps Engineer you will bridge our infrastructure and security teams, taking ownership of security-focused initiatives and helping us provide around-the-clock support as part of our on-call rotation.
Candidate Profile
- Background in Computer Science or related field
- 5 years of professional experience as a DevSecOps engineer
- Proven experience in securing AWS-based setups and Kubernetes clusters
- Proven experience with CI/CD pipelines, automation, and TerraForm
- Strong understanding of how PKI works, as well as SSL and TLS protocols
- Hands-on experience with security tools (e.g., OWASP ZAP, Nessus, Qualys)
- Familiarity with SIEM and other security platforms
- Knowledge of relevant regulatory standards (e.g., GDPR, SOC 2, ISO/IEC 27001)
Nice to Have
- Security certifications such as CISSP, CCSP, GCSA, CDP, OSCP, CEH, or GIAC
- Cloud security certifications like AWS Certified Security Specialty
Responsibilities
- Implement and manage security tools within our CI/CD pipelines, including DAST, SAST, and container scanning solutions.
- Secure our cloud environments with a focus on IAM, secrets management, and workload protection
- Provide expert opinions to inform decisions and assist in evaluating, selecting, and implementing security tools and frameworks (SIEM, CNAPP, SSPM, SOAR, XDR).
- Participate in the existing on-call rotation to maintain 24/7 coverage
- Work closely with team members across APAC, Europe, and North America to ensure seamless integration of security practices
- Detect, mitigate, and respond to security incidents, utilizing log analysis tools and contributing to incident post-mortems
- Ensure our systems comply with relevant regulatory standards
Compensation & Perks
- Competitive compensation package (commensurate to experience) + performance and referral bonuses
- 100% remote and flexible working hours
- Work from anywhere in the world
- Generous paid time off, including maternity/paternity leave
- Retirement/pension plan
- Equity
- Rent your own desk in a co-working space or work from anywhere at any time
- Free gym membership or any virtual alternative of your choice
- Learn about the hottest and newest products and trends in the crypto space before they appear on any news outlets
- Join quarterly all-expenses-paid retreats in exotic/exclusive locations with the team
Life at Quantstamp
Quantstamp is a smart contract security company that is developing the Quantstamp protocol and automated security tools, and conducts manual audits. The Quantstamp protocol aims to enhance smart contract security and the reputation of projects that create smart contracts by producing openly accessible scan reports.
Thrive Here & What We Value* 1. Competitive compensation package (commensurate to experience) + performance and referral bonuses.* 2. Remote and flexible working hours; work from anywhere in the world.* 3. Generous paid time off, including maternity/paternity leave.* 4. Retirement/pension plan.* 5. Option for Equity.* 6. Rent your own desk or work remotely at any time.* 7. Free gym membership or virtual alternatives.* 9. Quarterly all-expenses-paid retreats in exotic locations with team.* 10. All-inclusive benefits for employees.