This job post is closed and the position is probably filled. Please do not apply. Work for ShapeShift and want to re-open this job? Use the edit link in the email when you posted the job!
๐ค Closed by robot after apply link errored w/ code 404 3 years ago
\nPOSITION OVERVIEW\n\nShapeShift is seeking a Senior Software Security Engineer to help identify risks and mitigate them for this growing organization. The Software Security Engineer will be scanning, researching, hacking, and advising developers on security, in addition to altering source code to resolve security vulnerabilities. The ideal candidate will possess a keen understanding of how tweaking one parameter can vastly change the security outcomes of an information system. This position offers a unique opportunity to think with a black hat but wear a white hat for an exciting cryptocurrency startup.\n\nThis is a full-time, exempt position that reports directly to the CISO.\n\nYour desire to make a real impact on an organization and the world grows by the day. The ideal candidate will be open to daily changes in workflow and protocol (and force us to improve workflows). As a start-up in an evolving space, there are new challenges that require new solutions every day.\n\nGOALS OF POSITION\n\n\n* Stay abreast with daily CVE announcements and 0-day vulnerabilities\n\n* Provide strong software engineering experience to ShapeShift’s Security team.\n\n* Work with Site Reliability Engineers and IT administrators to mitigate any vulnerabilities found with ShapeShift's systems.\n\n* Provide security guidance and advice to software engineers on best practices for storing, securing, and accessing secrets in their application development. \n\n* Participate in architecture design discussions for ShapeShift's upcoming feature enhancements and new products/services, ensuring best practices in security are followed in each phase of development, and ensuring security risks are understood and mitigated in the design choices.\n\n* Execute and automate approved penetration tests, vulnerability scans, and related intelligence gathering about the existing security posture of development and production systems.\n\n* Manage internal TLS Certificate Authority, issuing and revoking internal server and client certificates where necessary.\n\n* Collect and organize security-related metrics for reporting to ShapeShift’s CISO.\n\n* Maintain ShapeShift's existing Information Security Policy, ensuring it is up-to-date with ShapeShift's requirements. \n\n* Providing security training to all new staff, and security refreshers to existing staff.\n\n* Oversee the provisioning of cryptographic keys and security hardware for new staff.\n\n* Can research, understand, and implement security enhancements to ShapeShift systems independently, and communicate changes to management in a timely fashion.\n\n\n\n\nSUCCESS METRICS OF POSITION\n\n\n* Concerns and risks are brought to the attention of the CISO in a timely manner\n\n* Staff receive your assessments and recommendations on improving/maintaining security in a timely manner\n\n* Staff are able to rely on you to educate them on security and answer their questions\n\n* Ability to contribute security enhancements to ShapeShift’s codebase.\n\n* Senior Security Engineer is able to meet deadlines independently\n\n\n\n\nWHAT YOU BRING TO THE TABLE\n\n\n* "Jack of All Trades" mindset, knowledgeable in many areas\n\n* "Geek to English translator" - ability to train/teach security concepts to non-security staff in easy-to-understand language\n\n* Strong "Google-fu" - ability to quickly find and learn concepts that aren't already known\n\n* Knowledge and experience that can be relied upon by others in the Security department\n\n* Ability to be flexible while working in a dynamic startup environment\n\n* Desire to make the world a better and safer place\n\n\n\n\nREQUIRED EDUCATION & EXPERIENCE\n\n\n* 7+ years of full-stack engineering experience or equivalent \n\n* Strong competency with Javascript and/or TypeScript\n\n* Strong competency with modern software development tools (git, jira, IDEs)\n\n* Experience performing source code review\n\n* Experience resolving application level vulnerabilities\n\n* Experience working with GPG / PGP\n\n* Experience with TLS, cryptographic certificates and PKI\n\n* Experience performing vulnerability scanning (i.e. Metasploit, Nessus, or similar)\n\n* Securing and administering services/daemons according to best practices\n\n* Experience working with Linux and open source technologies\n\n* At least 4 years experience in a security-focused role\n\n\n\n\nPREFERRED EDUCATION & EXPERIENCE\n\n\n* Experience securing cloud-based service providers, such as DigitalOcean, Azure, and AWS\n\n* Experience with deployment automation tools such as CircleCI, Terraform, etc.\n\n* Experience with penetration testing\n\n* Experience with charting, graphing, and presenting data visually\n\n* Experience working with cryptocurrencies and blockchains\n\n* Familiarity with Agile Development Methodologies \n\n* Familiarity with hardware and firmware security \n\n* Security certifications such as: CISSP, CISA, OSCP, Pentest+, Security+ would be an asset\n\n* Experience with Open Source Software\n\n\n \n\n#Salary and compensation\n
No salary data published by company so we estimated salary based on similar jobs related to InfoSec, Senior, Engineer, Developer, Digital Nomad, English, JavaScript, Education and Linux jobs that are similar:\n\n
$60,000 — $120,000/year\n
\n\n#Benefits\n
๐ฐ 401(k)\n\n๐ Distributed team\n\nโฐ Async\n\n๐ค Vision insurance\n\n๐ฆท Dental insurance\n\n๐ Medical insurance\n\n๐ Unlimited vacation\n\n๐ Paid time off\n\n๐ 4 day workweek\n\n๐ฐ 401k matching\n\n๐ Company retreats\n\n๐ฌ Coworking budget\n\n๐ Learning budget\n\n๐ช Free gym membership\n\n๐ง Mental wellness budget\n\n๐ฅ Home office budget\n\n๐ฅง Pay in crypto\n\n๐ฅธ Pseudonymous\n\n๐ฐ Profit sharing\n\n๐ฐ Equity compensation\n\nโฌ๏ธ No whiteboard interview\n\n๐ No monitoring system\n\n๐ซ No politics at work\n\n๐ We hire old (and young)\n\n
# How do you apply?\n\nThis job post has been closed by the poster, which means they probably have enough applicants now. Please do not apply.