Job Search and Career Advice Platform

Aktiviere Job-Benachrichtigungen per E-Mail!

Senior Security Engineer

Grvt

Remote

EUR 70.000 - 90.000

Vollzeit

Heute
Sei unter den ersten Bewerbenden

Erstelle in nur wenigen Minuten einen maßgeschneiderten Lebenslauf

Überzeuge Recruiter und verdiene mehr Geld. Mehr erfahren

Zusammenfassung

A technology-focused organization in Germany is seeking a highly skilled security engineer to enhance the reliability and security of their platform. This role involves leading security assurance activities and collaborating across teams to ensure platform integrity. Ideal candidates will have extensive experience in application security, proficiency in Python, and knowledge of cloud infrastructures. Familiarity with security frameworks and certifications is a plus. Join a forward-thinking team dedicated to maintaining high-security standards.

Qualifikationen

  • 5+ years of experience in Information Security, particularly in application security.
  • Deep understanding of OWASP Top 10 for web application security.
  • Experience building security engineering tools using Python.

Aufgaben

  • Lead security assurance activities including penetration testing and architecture reviews.
  • Collaborate with Ops and QA Engineers as the primary security expert.
  • Build internal tooling for security visibility and incident response.

Kenntnisse

Information Security background
Web application security knowledge
Python proficiency
Proficiency in security testing tools
Threat modeling experience
Smart contract auditing experience
Cloud infrastructure experience

Tools

SonarQube
Checkmarx
OWASP ZAP
Burp Suite
Jobbeschreibung
Key Responsibilities:
  • DevSecOps (cloud infrastructure, incident response, platform stability)
  • Test Engineering (end-to-end testing, regression pipelines, feature assurance)
  • Security Engineering (penetration testing, security advisory, security governance)

The organization has the mandate of ensuring the end-to-end reliability of the GRVT platform, protecting our product's reliability, correctness, and security.

This role is positioned within the Security vertical but works cross-functionally with the entire organization.

  • Lead technical assurance activities across projects, including penetration testing, purple teaming, threat modeling, and architecture reviews—ensuring both new and existing systems maintain a high security baseline.
  • Serve as the primary security expert within the SRE team, collaborating closely with Ops and QA Engineers and wider teams to design practical, high-impact controls that enhance platform security without compromising delivery velocity.
  • Build automation and internal tooling for security visibility, posture monitoring, and enforcement (e.g., secret scanning, anomaly detection, automated test harnesses).
  • Monitor, triage, and lead response efforts for security incidents, coordinating across SRE and wider engineering teams.
  • Establish and maintain security policies and controls aligned with both engineering best practices and regulatory obligations.
  • Educate and empower developers and engineers with actionable guidance, secure coding practices, and feedback cycles—reducing the likelihood of vulnerabilities during development.
Experience & Skills Requirements:
  • Strong Information Security (InfoSec) background (5 years+), with proven experience in application security across both traditional web stacks and blockchain-based systems.
  • Expert knowledge of web application security, including deep familiarity with the OWASP Top 10, to assess and defend GRVT’s off-chain services against common web-based threats.
  • Python proficiency — experience building security engineering tools such as automated API security testers, custom static analyzers, or CI/CD-integrated scanners for secrets, misconfigurations, and insecure patterns.
  • Proficiency in security testing tools, such as SAST (e.g., SonarQube, Checkmarx, GoSec) and DAST (e.g., OWASP ZAP, Burp Suite).
  • Demonstrated ability to quickly understand and analyze unfamiliar codebases, enabling effective secure code review across diverse systems—including web services, infrastructure components, and smart contracts.
  • Experience conducting threat modelling exercises, or a strong grasp of threat modeling methodologies to evaluate project risk at the design and implementation levels.
  • Smart contract auditing experience, with familiarity in identifying common vulnerabilities in decentralized applications and blockchain systems.
  • Bug bounty programs experience, either as a seasoned researcher or by managing an organization’s program.
  • Experience with cloud infrastructure (e.g., AWS, GCP). Understanding of container security and DevSecOps principles, with practical experience integrating security into CI/CD pipelines.
Bonus Points:
  • Familiarity with IT security frameworks such as SOC 2 and ISO 27001, and how to align technical controls to compliance objectives.
  • Holds or actively pursues professional certifications such as OSCP, OSWE, CISSP, CDP, or CTMP.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
eine PDF-, DOC-, DOCX-, ODT- oder PAGES-Datei bis zu 5 MB per Drag & Drop ablegen.