Security Engineer - Product Security - Blockdaemon San Francisco, California, United States Bookmark Share Print 183 0 0

Listing Description

Blockdaemon is looking for a talented Security Engineer who is excited to help scale one of the largest decentralized blockchain infrastructure platforms in the world. You'll work closely with the technology organization to evaluate the design and implementation of our product offerings, help create innovative security solutions for our products, and educate our teams on secure application development and emerging threats. In addition, you will solve ambitious technical problems on the forefront of application security with a transparent and open minded team


 


Position Overview:



  • Operationalizing SAST and DAST integrations into our build and deploy pipelines

  • Contributing security-focused feedback to engineers during all phases of the development lifecycle

  • Performing technical security assessments on our web applications, native clients, internal services, and partner applications

  • Seeking out opportunities to automate processes when appropriate

  • Communicating risks to engineering staff through training and technical demonstration of vulnerabilities and secure design patterns

  • Maintaining and creating secure development practices and programs for our engineering teams and external developers

  • Acting as an ambassador for security within Blockdaemon

  • Identifying emerging classes of vulnerabilities and developing solutions for them before they’re a problem


 


Required Experience:



  • Bachelor’s degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience

  • 5+ years experience in security testing of web applications and native apps

  • Deep understanding of web application architecture and design principles

  • Strong written and verbal communication skills and ability to communicate with empathy when delivering constructive feedback regarding security matters to engineers and product designers

  • Experience with manual secure code review in languages such as: Golang, JavaScript, Java, Python, Ruby, PHP

  • Familiarity with common web application testing tools for DAST, SAST, and IAST analysis such as Burp Suite, Checkmarx, Veracode

  • Knowledge of authentication mechanisms like SAML, OAuth, etc.

  • Knowledge of common security flaws and resolution as published by OWASP, SANS, etc.

  • Knowledge of how to test code and applications across various platforms (iOS, Mac, Linux, Windows, Android, etc) for security and quality

  • Ability to see patterns, commonalities and investigate complex issues

  • Organizational skills to bring together and record detailed and accurate information about bugs and systemic issues

  • Experience with GCP is a plus

  • Current or former security training or certifications such as SANS GWAPT or similar is a plus

  • Though this is not primarily a development role, some background in software engineering in a collaborative and dynamic environment is a plus


 


#LI-Remote


 


Listing Details

  • Citizenship: Not Provided
  • Incentives: Not Provided

 

  • Education: Not Provided
  • Travel: Not Provided
  • Telework: Not Provided



About Us

NinjaJobs is a community-run job platform developed by information security professionals. Our unique approach of focusing strictly on cybersecurity positions allows us to personalize the user experience.

Our Contacts

1765 Greensboro Station Pl.
Suite 900
Tysons Corner Va 22102

(703) 594-7765