ValueLabs is hiring for Lead Security Engineer. Below is the Job Description.
About the Role
As the Security Lead Engineer, you will be a hands‑on security engineer who builds and implements security controls, tooling, and automation across applications, cloud infrastructure, APIs, and blockchain-integrated platforms — not just an auditor who finds problems and hands them off. This role combines offensive security testing with production‑grade engineering: you'll write code, ship security tooling, implement fixes directly into infrastructure and pipelines, and own outcomes end‑to‑end. Deep expertise in application security, cloud security, secure development, and software engineering is required.
Responsibilities
Build and Own Offensive Security Tooling
- Design, build, and maintain internal security tooling (scanners, custom scripts, automated test harnesses) rather than relying solely on off‑the‑shelf DAST/SAST products.
- Conduct hands‑on penetration testing against web apps, APIs, mobile apps, cloud infrastructure, and containers — and implement the fixes, not just report findings.
- Write proof‑of‑concept exploits and custom detection rules for vulnerability classes specific to the platform.
Implement Cloud and Infrastructure Security Controls
- Write and maintain Terraform (or equivalent IaC) modules that enforce secure‑by‑default configurations — not just audit existing IaC for misconfigurations.
- Build and deploy CSPM policy‑as‑code and Kubernetes security policies (OPA/Gatekeeper, network policies, admission controllers) directly into the environment.
- Own remediation of cloud misconfigurations by shipping infrastructure changes, not just filing tickets.
- Build and maintain automated security gates in CI/CD (SAST/DAST/dependency scanning, secrets detection) as code — own the pipeline configuration, not just “support” it.
- Write custom integrations/plugins where off‑the‑shelf tools don't fit the stack.
- Partner with engineering to embed security checks that block bad merges automatically, reducing manual review load.
Security Monitoring and Detection Engineering
- Build detection rules and SIEM integrations — write the queries, correlation rules, and alerting logic, not just “support” monitoring.
- Automate triage and response workflows for common alert classes.
Smart Contract and Financial Logic Security
- Perform hands‑on review of smart contracts and financial logic (reward spoofing, withdrawal validation, transaction integrity) and write test suites that catch these classes of bugs before external audit.
- Contribute directly to fixes in collaboration with blockchain engineering, not just flag issues.
Vulnerability Remediation Engineering
- Triage and prioritize findings, then implement or pair on fixes with dev teams rather than handing off remediation guidance alone.
- Validate fixes through re‑testing and automated regression tests that prevent recurrence.
Qualifications
Must‑Have
- 10+ years in cybersecurity with strong hands‑on offensive security and software engineering experience (not audit/GRC‑only background).
- 2+ years Product Security; 2+ years DevSecOps with direct ownership of CI/CD security pipeline code; 2+ years AWS Cloud Security with hands‑on IaC authorship (Terraform).
- Proven track record of shipping security tooling or automation into production, not just performing assessments.
- Deep OWASP Top 10 / API Security Top 10 knowledge, applied through both testing and secure code review.
- Experience writing Kubernetes security policy as code (OPA/Gatekeeper, admission controllers), not just assessing K8s configs.
- Strong Secure SDLC background with the ability to pair directly with engineers on fixes.
Nice‑to‑Have
- FinTech/digital asset platform experience with financial fraud attack vectors.
- OSCP, OSCE, GXPN, or GPEN certifications.