DevOps Security Engineer

Decentralized Masters

Barcelona

Presencial

EUR 70.000 - 100.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Competitive salary
Performance-based incentives
Direct exposure to founders
Team offsites
Remote work flexibility

Descripción de la vacante

Decentralized Masters is looking for a security-focused software engineer to own the security posture of their platform managing significant digital assets. The ideal candidate will have extensive experience in security and quality assurance, with a strong background in fullstack development and cloud infrastructure like AWS. The role offers competitive compensation, remote work flexibility, and direct exposure to the company's founders. Join a high-impact team as they advance digital security in the Web3 space.

Formación

  • 5+ years in software engineering with hands-on security and QA experience.
  • Experience with frontend (React) and backend (Node.js, Python, Go).
  • Hands-on penetration testing and vulnerability assessment experience.

Responsabilidades

  • Own security posture across all products.
  • Conduct penetration testing, vulnerability assessments aligned with OWASP standards.
  • Build and maintain incident response playbooks.

Conocimientos

Security and QA experience
Fullstack development
Penetration testing
AWS expertise
Communication skills

Herramientas

Terraform
Docker
Kubernetes
Burp Suite

Descripción del empleo

About Legacy

Legacy is an easy-to-use, non-custodial Web3 wallet designed to protect digital assets through beneficiary protection and seamless DeFi access. Users can swap across chains, earn yield in one click, and safeguard wealth for the next generation.

About the Software Division

We are building a portfolio of software products inside the Decentralized Masters ecosystem, including:

  • Legacy Wallet - a non-custodial Web3 wallet with beneficiary protection and seamless DeFi access
  • Trading Bot - automated crypto execution tools for serious investors
  • Future fintech and investor infrastructure tools

We are now building the retention and lifecycle engine that will power long‑term recurring revenue across all products.

About The Role

You will be the single person responsible for the security of a platform that tracks hundreds of millions in digital assets. That is the job. Everything else is secondary.

We need someone who breaks things for a living. Someone who looks at a login page and sees six attack vectors. Someone who reads a pull request and catches the injection vulnerability that two senior developers missed. Someone who lies awake thinking about the phishing campaign that hasn’t been invented yet. If that sounds exhausting, this is not your role. If that sounds like Tuesday, keep reading.

Your primary responsibilities are security and quality assurance. You own penetration testing, vulnerability assessments, threat modeling, automated test frameworks, and CI quality gates across every product we ship. You also own infrastructure: AWS, CI/CD pipelines, monitoring, and incident response. And because we are a small, senior team, you will write production code when security and QA responsibilities are covered. You are not a consultant or a checkbox auditor. You are an engineer who ships, and whose code happens to make everything else harder to break.

The ideal candidate has spent time at major product‑driven fintech and crypto companies where a single security failure can destroy user trust overnight.

Security (Primary)
  • Own the security posture across all products: Legacy, Trading Bot, and future platforms. If something gets breached, it is your problem. If nothing gets breached, it is because of your work
  • Conduct regular penetration testing, vulnerability assessments, and threat modeling aligned with OWASP standards and methodologies
  • Ensure full coverage of the OWASP Top 10 in application security testing, code reviews, and deployment checks
  • Perform security‑focused code reviews across frontend, backend, and infrastructure code, catching what standard code reviews miss
  • Implement and manage secrets management (Vault, AWS Secrets Manager, or KMS), access controls, and least‑privilege policies
  • Build and maintain incident response playbooks. When something breaks, you lead the response, run the post‑mortem, and ship the fix
  • Stay ahead of Web3 and crypto‑specific attack vectors: phishing campaigns, wallet exploits, API key compromises, supply chain attacks, and social engineering
  • Manage and coordinate external security audits and penetration tests from third‑party firms
Quality Assurance & Testing (Primary)
  • Design and implement test strategies across all products: unit tests, integration tests, end‑to‑end tests, API tests, and regression suites
  • Build and maintain automated testing frameworks and CI quality gates that prevent broken code from reaching production
  • Define and track quality metrics: test coverage, flakiness rate, regression detection latency, and bug escape rate
  • Write and execute security test cases: authentication flows, authorization controls, input validation, API abuse scenarios, and edge cases around financial data
  • Perform both white‑box and black‑box testing, leveraging full codebase access to catch issues that surface‑level QA would miss
  • Test across the full stack: frontend UI, backend APIs, database queries, third‑party integrations, and on‑chain interactions
Infrastructure & DevOps (Foundation)
  • Maintain and improve cloud infrastructure on AWS using Infrastructure as Code (Terraform or CloudFormation)
  • Own CI/CD pipelines (GitHub Actions preferred): automated testing, security scanning, linting, and deployment
  • Harden infrastructure: network security, IAM policies, container security, and environment isolation
  • Build logging, monitoring, and alerting across all services (CloudWatch, Prometheus, Grafana, or equivalent)
  • Ensure audit trails for user actions, system changes, and access events
  • Manage production reliability, incident response, and cost optimization
Fullstack Development (When the fortress is secure)
  • Contribute production code across frontend and backend, bringing a security‑first mindset to every feature you build
  • Build features, fix bugs, and ship improvements alongside the engineering team
  • Every line you write should make the product better and harder to break: input validation, error handling, authentication, and data protection by default
  • Participate in architecture discussions and code reviews, advocating for testability, reliability, and security in every decision
Requirements
Required
  • 5+ years in software engineering roles with meaningful, hands‑on security and QA experience. We will verify this. If your security experience is theoretical, this is not the right fit
  • Fullstack development experience: you can build and ship features across frontend (React or equivalent) and backend (Node.js, Python, Go, or equivalent)
  • Hands‑on penetration testing and vulnerability assessment experience across web applications, APIs, and cloud infrastructure
  • Strong working knowledge of OWASP standards, including the OWASP Top 10, OWASP Testing Guide, and OWASP secure coding practices
  • Experience building automated test frameworks and integrating testing into CI/CD pipelines
  • AWS expertise (EC2, ECS/EKS, Lambda, VPC, IAM, S3, RDS, CloudFront, WAF)
  • Infrastructure as Code experience (Terraform, CloudFormation, or Pulumi)
  • Container technologies: Docker and Kubernetes in production environments
  • Scripting and automation proficiency in Bash and Python
  • Experience with secrets management tools (HashiCorp Vault, AWS Secrets Manager, or similar)
  • Familiarity with security and testing tools (Burp Suite, OWASP ZAP, Selenium, Cypress, Jest, Postman, or equivalent)
  • Strong communication skills: you can explain security risks and quality tradeoffs clearly to non‑technical stakeholders
Nice‑to‑Have
  • Security certifications: OSCP, CISSP, CompTIA Security+, AWS Security Specialty, or equivalent
  • Experience at a crypto, DeFi, Web3, or fintech product company (Coinbase, Phantom, Stripe, Casa, MetaMask, Zerion, Ramp, or similar)
  • Familiarity with Web3‑specific security concerns: wallet security, key management, on‑chain monitoring, phishing mitigation
  • SDET background or experience in a hybrid development‑and‑testing role
  • Experience testing financial systems: payment flows, ledger integrity, double‑spend prevention, or transaction monitoring
  • Experience implementing zero‑trust architectures
  • Bug bounty participation, CVE publications, or contributions to open‑source security tooling
Benefits
What We Offer
  • Competitive salary + performance‑based incentives tied to retention & LTV improvement
  • Direct exposure to founders
  • Team Offsites
  • Remote work
  • High ownership, high‑impact role
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Associate Security Engineer
Associate Security Engineer

Spendesk • Barcelona

Híbrido
EUR 40.000 - 70.000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care
+2
Product Security Engineer
Product Security Engineer

Gomining • España

Híbrido
EUR 65.000 - 90.000
Professional development
Flexible work arrangement
Paid time off
+2
Senior Application Security Engineer
Senior Application Security Engineer

LeoVegas Group • Málaga

Híbrido
EUR 70.000 - 100.000
Hybrid work policy
Workation benefits
Wellness contribution
+7
Technical Team Lead, Contract
Technical Team Lead, Contract

Xcelirate • Barcelona

A distancia
EUR 145.000
Competitive salary with retention bonus
Top-notch workstation
Global co-working access
+2
Security Engineer — Mobile RASP
Security Engineer — Mobile RASP

Ditto • España

Presencial
EUR 70.000 - 110.000
Security Engineer
Security Engineer

Wizeline • Barcelona

Presencial
EUR 90.000 - 130.000
High-Impact Environment
Professional Development
Flexible Culture
+3
Senior DevOps / Platform Engineer
Senior DevOps / Platform Engineer

OpenVPN Inc. • España

Presencial
EUR 90.000 - 130.000
Competitive pay rates
Fully remote work environments
Self-managed time off
Lead Application Security Engineer
Lead Application Security Engineer

Remofirst • España

Presencial
USD 140.000 - 190.000
Parental leave
Wellbeing stipend
Remote-first, always
Senior Security Engineer
Senior Security Engineer

Auctane • Barcelona

Presencial
EUR 75.000 - 83.000
Private health insurance
Annual salary review
Training budget up to €2000/year
+2
Senior Security Engineer
Senior Security Engineer

Auctane • Sevilla

Presencial
EUR 75.000 - 83.000
Private health insurance
26 days holiday per year
Annual salary review
+2