Join Lido as a SecOps Engineer to integrate security into development processes and manage incidents in a fully remote environment.
Posted by employer 3 months ago
First seen on Joblaze 1 week ago
Last verified on the company career page 1 day ago
Skills & Technologies
Not disclosed in this posting: compensation, seniority, years of experience, visa sponsorship.
Benefits
Joblaze summary
The SecOps Engineer at Lido plays a crucial role in integrating security into the development lifecycle, focusing on incident management and vulnerability assessments. Key skills include technical security evaluations, programming in languages like Python and Golang, and effective communication to bridge gaps between technical and non-technical teams. This position is ideal for someone with a solid background in security practices, particularly those familiar with blockchain and DevOps environments. Lido emphasizes a collaborative approach, ensuring security is a fundamental aspect of its operations.
Joblaze insights
Quick facts
From the original posting
The SecOps contributor workstream is responsible for helping the DAO to integrate security into development processes, managing incidents, and collaborating with teams. This role develops response plans, conducts assessments, and ensures effective communication of security practices. Essential skills include technical security assessments, programming, and strong communication abilities, with blockchain and DevOps experience being advantageous.
Develop secure systems to protect Lido Protocol, DAO, applications, contributors, partners, and stakers.
Define processes, systems, and applications to make attacks difficult to execute and easy to detect.
Embed security practices and tools within the development pipeline.
Develop and maintain incident response plans and playbooks.
Perform regular vulnerability assessments and penetration testing.
Lead or participate in incident response activities, including investigation, containment, eradication, and recovery.
Monitor security alerts and incidents to identify and respond to threats promptly.
Collaborate with development and operations teams to ensure security is incorporated from design to deployment and maintenance.
Provide training and support on security tools and techniques, emphasizing soft skills like communication, negotiation, and influence.
Experience with technical security assessments, code audits, design reviews, and vulnerability research.
Proficiency in programming languages (Python, Golang, JavaScript, Bash).
Experience with security tools and technologies (SIEM, IDS/IPS, vulnerability scanners, automated security testing).
Excellent communication skills to articulate security concepts to technical and non-technical stakeholders.
Strong problem-solving abilities for security investigations and risk assessments.
English level: B2+
Experience with blockchain technologies, Ethereum-based networks, web3 bug hunting, and contract analysis.
Familiarity with DevOps practices and tools (Docker, Kubernetes, GitHub Actions, Git, Ansible, Terraform).
Experience with supply chain attacks analysis and prevention.
Focus on improving real-world security, not compliance.
Contribute from anywhere in the world.
Competitive compensation level.
Flexible schedule.
Compensation for education, including language & professional growth courses.
Equipment & co-working reimbursement program.