Customer EDD Risk Analyst

The Compliance Team ❤️

As a Customer Risk Analyst,  you’ll join our team at MoonPay to support the Financial Intelligence Unit (FIU) in ensuring that the business in the US operates in accordance with all legal and regulatory requirements and all Group standards relating to anti-money laundering and counter terrorism financing (AML). This role will be responsible for performing holistic due diligence reviews in support of the Bank’s BSA/AML Know Your Customer (KYC) policies and procedures. The BSA/AML EDD program is designed to review higher-risk customers and their activity closely at account opening and periodically thereafter.

The ideal candidate is a highly motivated, inquisitive individual with a background in AML/BSA, able to work independently and as a part of the team, can analyze, assess financial activity/documentation to evaluate potential risk of certain customer types. We are currently looking for candidates in Poland.  

What you’ll do 👀

  • Timely completion of EDD Onboarding customer reviews 
  • Timely completion of periodic/high risk customer EDD reviews and escalation of potential concerns to the appropriate group.
  • Managing the EDD and other exception queues
  • Resolve escalations by Customer Operations Team or other parties
  • Liaising with with e-KYC vendor when needed
  • Conduct research using available systems and proprietary tools to identify relevant Know Your Customer (KYC) information.
  • Support Managers and Team Leaders in conducting complex customer or partner reviews.
  • Serve as a backup for any FIU Analyst related functions and contribute to additional assignments/projects as assigned by Management
  • Assist with training and job shadowing for new team members
  • Keep up-to-date with industry news and developments both in BSA/AML and KYC, as well as in the cryptocurrency and blockchain space

You should apply if âś…

  • A passion for harnessing the power of digital currency and blockchain technology and services built on top of it.
  • 3+ years experience at a financial institution, ideally in FinTech and/or MSBs.
  • Strong ability to analyze data and identify potential red flags
  • Detail oriented, analytical, and critical thinking skills
  • Proven track record of interpreting large amounts of complex information and extracting facts objectively
  • Ability and passion to learn and adapt quickly, as the crypto space are constantly evolving
  • Strong written and verbal communication skills and attention to detail
  • Ability to effectively balance multiple priorities and learn new tools quickly
  • Outstanding interpersonal skills and ability to develop strong working relationships

You should apply if âś…

  • Ability to assess risk as well as advise management of risk(s)
  • Strong analytical, problem-solving, and critical thinking skills.
  • Able to work well independently or as part of a team.
  • Customer oriented in your approach.
  • An innovative and creative mind looking to suggest new solutions to old problems.
  • Strong organizational and analytical skills with great attention to detail.
  • Excellent written and verbal communication skills in English. Additional languages will be considered an asset.
  • First-rate decision making skills, bias for action and sound judgment.
  • Ability to maintain a strong operational focus with the capacity to manage time sensitive workflows across competing priorities.
  • B.A./B.S. degree; or equivalent work experience or research experience a plus.
  • ACAMS / ACFCS or ICA accreditation

Bonus points:

  • Crypto-specific investigative work experience, and knowledge of blockchain analysis across various crypto products
  • Experience with blockchain analytics software (e.g. Chainalysis, TRM Labs, CipherTrace)
  • Crypto compliance certifications (CCI, CTCE, CCFC, Reactor, KYT)

Research has shown that women are less likely than men to apply for this role if they do not have solid experience in 100% of these areas. Please know that this list is indicative and that we would still love to hear from you even if you feel you are only a 75% match. Skills can be learnt, diversity cannot.

We promote a diverse and inclusive culture at MoonPay.

Logistics đź› 

Unfortunately, we are unable to offer visas of any kind at this time!

Our interview process takes place on Zoom and tends to consist of the following stages:

Hiring Manager Screen (20-30 minutes)

Compliance screen (20-30 minutes)

Culture Screen (20-30 minutes)

Final interview (20-30 minutes)

Please let us know if you require any accommodations for the interview process, and we’ll do our best to provide assistance

Listed in: , , , , , , , , , , , , .

FP&A Analyst (OPEX)

The opportunity ✔️

You will be joining as an early leader on a growing team. In this role, you will own the OPEX financial planning and reporting processes and the company’s financial model for annual planning, rolling forecasts, and long range planning. This is a highly visible role within the organization and requires someone who can work in ambiguity and is a problem solver to help develop and shape our business and financial strategy.

What you’ll do 👀 

  • Lead the monthly, quarterly, and annual FP&A processes, including management reporting, variance analysis, Budgeting, and forecast scenario planning for OPEX.
  • Partner with departments/cost center owners to help them understand and manage their expenses and provide a consolidated view to the executive team on business performance.
  • Develop dashboards to track key performance indicators and monitor business performance. Provide management with insights into drivers of expenses, as well as risks and opportunities. 
  • Create and maintain the company wide workforce planning model. Work with departmental heads to forecast their headcount needs and the financial impacts to the business.
  • Understand our fraud related expenses by working with the data team to identify, manage and mitigate any future risks.
  • Partner with the IT team to understand vendor and software related expenses and identify opportunities for cost savings.
  • Partner with the Accounting team to ensure accounting principles and guidelines are accurately reflected in planning and forecast processes and deliverables. 

You should apply if ✅ 

  • Experience in FP&A, Finance, Accounting, or Business Partnering. OPEX experience is a plus.
  •  Undergraduate degree in business, economics, finance, or another quantitative field. MBA, CFA or CPA is a plus.
  • Experience working in but not limited to FinTech, investment banking, management consulting, or at a fast-growing startup.
  • Proven track record to work independently and manage day to day projects. 
  • Understanding of financial and non-financial KPIs 
  • A well-rounded top performer, with a combination of analytical and interpersonal skills; execution-oriented and attention to timelines. 
  • Superb analytical/quantitative and communication skills and strong executive presence. 
  • Proven ability to collaborate and build relationships at all levels of the organization. 
  • Build complex financial models and present in a clear and compelling manner to a non-finance audience. 
  • Strong proficiency in Excel/ Google sheets is a must. 
  • Passion for cryptocurrency, blockchain technology and financial markets

Listed in: , , , , , , .

Back-end/Node.js Developer

About the Role:

We are seeking an experienced, Russian-speaking Node.JS Developer to join our team. As a Back-End Developer, you will be responsible for coding, debugging, and collaborating with front-end developers to develop functional and sustainable web applications. You will work closely with a team of designers and developers to ensure the successful delivery of high-quality code.

Tasks and Responsibilities:

  • Participate in the overall application lifecycle, from conception to deployment.
  • Focus primarily on coding and debugging tasks to ensure the smooth functioning of back-end systems.
  • Collaborate effectively with front-end developers to integrate user-facing elements with server-side logic.
  • Define and communicate technical and design requirements to the development team.
  • Foster a collaborative and supportive environment.
  • Develop high-quality code that adheres to industry best practices and can be utilized in future projects.
  • Build functional and sustainable web applications, ensuring clean and efficient code.
  • Troubleshoot and debug applications to promptly identify and resolve issues.
  • Stay updated with emerging technologies and industry trends.
  • Employ cutting-edge technologies to improve application functionality and efficiency.

The Ideal Candidate – Who You Are and Requirements:

  • Must be a fluent Russian speaker.
  • B1+ level of English.
  • Living in Cyprus is a big advantage.
  • Willingness to relocate to Cyprus, if not currently residing there, is a big advantage.
  • Minimum of 5 years of experience as a Back-End Developer.
  • In-depth understanding of server-side web applications and API development.
  • Minimum of 5 years of experience with JavaScript.
  • Familiarity with front-end technologies such as HTML and CSS.
  • Familiarity with Node.JS and Moleculer.
  • Familiarity with blockchain technology is an advantage.
  • Possesses critical thinking and problem-solving skills.
  • Strong team player who can collaborate effectively within a multidisciplinary team.
  • Good organizational and time-management skills.
  • Excellent interpersonal and communication skills.
  • A Bachelor’s degree in Computer Science or a similar relevant field is a big advantage.

Benefits:

True to the motto “Take care of your employees, and they’ll take care of your business”, you’ll find many benefits in working with us. For example:

  • Work remotely from anywhere in the world, with the option to work from our beautifully designed, beach-front office in the vibrant city of Limassol, Cyprus.
  • Assistance with Visa and housing search in the event of relocation.
  • Fresh coffee, food, and drinks are served at the office.
  • Company events and celebrations.
  • A fast-paced, challenging, and unique business sector.
  • Flat company and international work environment.
  • Excellent opportunities for advancement within a growing organization.
  • Possibility of international transfers and relocation mid-career.
  • Competitive pay and compensation in the form of Tokens – you grow with the company.
  • At Magic Square, you’ll be empowered to work on things you’re passionate about. You’ll be given autonomy. Your ideas will matter!

If you’re still hesitating because you don’t think you’re a 100% fit for the job, apply anyway and we’ll have a chat! You may have more potential than you think. We look forward to getting to know you!

Listed in: , , , , .

Intern (Undergraduate)

The Role

We’re looking to bring on an intern that will work on various initiatives across different verticals during your internship, giving you a wide range of experiences. Examples of projects include:

  1. Conduct product research and help drive the Alchemy product team to decisions through data-driven approaches.
  2. Create tutorials and content for our different channels of distribution for our new products and upcoming product releases.
  3. Explore different growth strategies for Alchemy focused on growing our key core metrics.
  4. Social media management and marketing work for our existing products and community engagement.
  5. Research cutting-edge verticals such as Zero Knowledge, MEV, Transaction Infrastructure, and Security and present your findings to the wider organization.

You’ll get full responsibility and ownership of your projects. You’ll work closely with the marketing, product, design, sales, ventures, and growth teams to drive your project and ideas forward.

What We’re Looking For:

  • Rising undergraduate juniors or seniors.
  • Major or minor in computer science.
  • Ability to think creatively and solve unique problems for multi-faceted organizations.
  • Have been closely following the web3 space for a while and must understand recent developments, trends, and teams.
  • Able to understand and explain technical concepts in an easy-to-understand way.
  • Has to be extremely confident paired with a strong analytical horsepower that can research and ideate on.
  • Has worked at a startup before or has a passion for helping startups succeed and thrive.
  • Readiness to switch projects at a moment’s notice

Listed in: , , , , , , , , , , , , , .

Analyst, Security Compliance

At Coinbase, our mission is to, and we couldn’t do this without hiring the best people. We’re a group of hard-working overachievers who are deeply focused on building the future of finance and Web3 for our users across the globe, whether they’re trading, storing, staking or using crypto. Know those people who always lead the group project? That’s us.

There are a few things we look for across all hires we make at Coinbase, regardless of role or team. First, we look for candidates who will thrive in a like ours, where we default to trust, embrace feedback, and disrupt ourselves. Second, we expect all employees to commit to our to our work. Finally, we seek people who are excited to learn about and live crypto, because those are the folks who enjoy the intense moments in our sprint and recharge work culture. We’re a remote-first company looking to hire the absolute best talent all over the world.

Ready to #LiveCrypto? Who you are:

  • You’ve got positive energy. You’re optimistic about the future and determined to get there. 
  • You’re never tired of learning. You want to be a pro in bleeding edge tech like DeFi, NFTs, DAOs, and Web 3.0. 
  • You appreciate direct communication. You’re both an active communicator and an eager listener – because let’s face it, you can’t have one without the other. You’re cool with candid feedback and see every setback as an opportunity to grow.
  • You can pivot on the fly. Crypto is constantly evolving, so our priorities do, too. What you worked on last month may not be what you work on today, and that excites you. You’re not looking for a boring job.
  • You have a “can do” attitude. Our teams create high-quality work on quick timelines. Owning a problem doesn’t scare you, but rather empowers you to take 100% responsibility for achieving our mission.
  • You want to be part of a winning team. We’re stronger together, and you’re a person who embraces being pushed out of your comfort zone.

Coinbase is looking for a Security Compliance Analyst to support risk and compliance efforts in designing, evaluating, implementing, and improving IT Security controls across various workstreams; including Internal Controls Financial Reporting/Sarbanes Oxley (ICFR/SOX), Service Organization Controls Reports (SOC Reports), National Institute of Standards and Technology (NIST), International Standards Organization (ISO), among others – for our Institutional products line.

What you’ll be doing (ie. job duties):

  • Work cross functionally with Security, IT, Infrastructure, Product, Engineering, Data, Internal Audit, Finance, and other teams to advise on security best practices and provide guidance on IT Risk and controls (including ICFR/SOX, SOC1/SOC 2, ISO, and NIST controls as well as financial services regulatory reporting requirements)
  • Build relationships with a broad range of Coinbase employees at various levels to accomplish program objectives, educate them on their roles and responsibilities, and further Coinbase’s Security goals
  • Assist in SOC 1, SOC 2, and regulatory requirement gap assessments for Institutional services, track remediation efforts to completion, and facilitate audits with external auditors
  • Conduct design and implementation testing over security controls, identify and analyze process gaps, develop remediation recommendations, and track to completion
  • Work closely with internal and external auditors to educate them and achieve compliance over technology control environment
  • Communicate progress, escalations, and issue resolutions to management and team stakeholders
  • Collaborate with Legal and Security to update company security policies to reflect Institutional requirements
  • Coordinate with Engineering partners to learn about services that support our digital asset transactions and document their processes
  • Create procedural documentation, including training materials or process documentation

What we look for in you (ie. job requirements):

  • 4+ years of security/IT compliance or equivalent experience
  • Hands-on experience with implementing, reviewing or auditing security frameworks such as SOC 1, SOC 2, ICFR/SOX, NIST and/or ISO27001
  • Prior experience working closely with auditors and/or external regulators
  • Experience with compliance initiatives from start to finish
  • Outstanding written and spoken communication skills
  • Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with light supervision
  • Ability to multitask, prioritize work, and meet deadlines in a fast paced environment
  • Focus on precision and accuracy, and the drive to clarify ambiguity

Nice to haves:

  • BA or BS in a technical field or equivalent experience
  • Prior experience at a Big 4 or consulting experience in Cybersecurity preferred
  • Security certifications e.g. CISA, CISSP, CISM or other relevant certifications
  • Experience mapping common controls across multiple frameworks in a GRC tool 
  • Financial services or financial regulatory experience

Job #: P51263

Pay Transparency Notice:  Depending on your work location, the target annual salary for this position can range from $131,325 to $154,500 + target bonus + target equity + benefits (including medical, dental, vision and 401(k)).

Commitment to Equal Opportunity

Coinbase is committed to diversity in its workforce and is proud to be an Equal Opportunity Employer.  All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law.  For US applicants, you may view ,  and  notices by clicking on their corresponding links.  Additionally, Coinbase participates in the  in certain locations, as required by law. 

Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to accommodations[at]coinbase.com and let us know the nature of your request and your contact information.  For quick access to screen reading technology compatible with this site a free compatible screen reader .

Global Data Privacy Notice for Job Candidates and Applicants

Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available . By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined    

Listed in: , , , , , , , , , , , , , .

Institutional Sales, North America

Who You Are:

This is a unique opportunity to join a team that’s fast-growing and a leading innovator in the digital currency financial ecosystem. The candidate will work closely with the heads of business development and institutional sales to develop Galaxy’s product suite for corporates and drive revenue growth with North American institutions.

What You’ll Do:

  • Work with senior leadership to develop go-to-market strategy and tactics for delivering Galaxy’s crypto product suite to North American institutions
  • Ideate around Galaxy’s corporate product offering as we look to educate and deliver institutional grade cryptocurrency solutions
  • Work independently to lead cross-functional partnership initiatives, working with product, finance, comms, compliance, legal and marketing
  • Own all elements of the customer life cycle: scoping of opportunities, identifying potential customers, framing of value, negotiating documentation, optimizing our customer experience
  • Maintain healthy and productive client relationships, resolving business, policy and technical issues
  • Understand regional market and crypto-specific market microstructure
  • Provide leadership in growing our corporate sales team and coverage plan

What We’re Looking For:

  • Strong understanding of financial markets and products, preferably derivatives
  • Experience developing and leading customer relationships at senior / C-suite levels
  • Knowledge of the region
  • A solutions orientated mindset
  • Crypto experience is preferred
  • Bachelors degree

Bonus Points:

  • You enjoy and excel at working cross functionally to deliver commercial results
  • You have shown the ability to build and manage relationships with product and business leaders, internally and externally 
  • You have great strategic instincts and can exercise good judgment with imperfect information
  • You’ve demonstrated success in negotiating a broad set of different types
  • You have great interpersonal and communications skills
  • You’re intellectually curious and think in a structured way
  • Experience in business development, product or growth a plus

What We Offer:

  • Competitive base salary, bonus, and equity compensation
  • Flexible Time Off (paid)
  • 3% 401(k) company contribution
  • Company-paid health and protective benefits for employees, partners, and other dependents
  • Generous paid Parental Leave
  • Free virtual coaching and counseling sessions through Ginger
  • Opportunities to learn about the Crypto industry
  • Free daily snacks in-office
  • Smart, entrepreneurial, and fun colleagues
  • Employee Resource Groups

*Benefits may vary depending on location.

Apply now and join us on our mission to engineer a new economic paradigm.

Listed in: , , , , , , , , , , .

Senior Field Marketing Manager

Vibrant storytellers and Chainalysis evangelists, our Marketing team leverages cutting-edge research, real customer success stories and the infinite possibilities in-between to drive expansion around the world. We’re the connectors and facilitators for key-players in the cryptocurrency industry.

The Field Marketing Manager will partner with our regional sales leader to build and execute the complete demand generation plan for LATAM. This person will collaborate with our global marketing team and manage product launches, events, and demand generation campaigns across this emerging region. We measure success by pipeline development, lead generation, and sales success. 

In one year you’ll know you were successful if…

  • The LATAM team has achieved customer acquisition and sales bookings targets
  • You’ve developed a localized demand generation strategy that reliably builds and accelerates pipeline
  • You understand the cryptocurrency ecosystem, our customers, and can develop local market messaging
  • You’ve developed a partnership with regional leadership and worked collaboratively with the rest of the product and field marketing teams
  • You understand what activities are meaningful to the business and can appropriately prioritize requests from sales and other stakeholders
  • You’ve orchestrated an impactful annual marketing program in budget, supporting a fast-growing sales team by making data-driven decisions to prioritize the most impactful campaigns 

A background like this helps: 

  • Led LATAM marketing for a technology company
  • Have experience in targeting and engaging  public sector agencies (federal law enforcement, state and local, defense or financial regulatory agencies) and private sector companies (traditional finance instructions, crypto companies, fintechs)
  • You have experience with cryptocurrency or blockchain technology  
  • You’re masterful at managing competing deadlines, measuring and drawing insights from KPI’s, and have an exceptional attention to detail

#LI-DP1 #LI-Remote

Listed in: , , , , , , , , , .

Benefits Manager

The People Team at Chainalysis is dedicated to enabling growth, building an inclusive environment, and providing the benefits and perks that help our employees balance work, life, and happiness. Our job is to make sure Chainalysis has the right talent and framework in place to grow both quickly and thoughtfully. 

The Benefits Manager is really great at analyzing benefits data to create visibility to the People team, and broader leadership team on the value, utilization and costs of the benefits and perks Chainalysis offers, including pensions, insurances, education reimbursement, paid time off, parental leave, and other programs.

In one year you’ll know you were successful if…

On Strategy 

  • You’ve reviewed and analyzed complex data on benefit plan utilization, costs and trends and made recommendations for enhancements, cost savings, or potential changes. 
  • Evaluated best practices, market competitiveness and employer/employee value against Chainalysis’s business priorities and values
  • Supported the growth of Chainalysis into additional locations, through both EoR and legal entity structures, by analyzing appropriate benefits offerings, obtaining price quotes, and making recommendations to People leadership.
  • Collaborated with key stakeholders to understand local benefit requirements and external market competitiveness of our benefits programs globally.
  • Managed vendor relationships around renewals, pricing, and reporting, and coordinated with People Operations to ensure SLA standards are met.
  • Partnered with the People Operations, Finance, and Legal teams to implement new benefit programs and vendors.
  • Driven and executed on cross-functional projects from planning through to implementation.

On Compliance

  • You’ve analyzed new and changed global/local laws for compliance and performed ad-hoc reviews to ensure best practice process deployment for the programs are managed
  • Kept abreast of updated or new benefit-related laws, regulations, guidelines and policies, and recommend changes to Chainalysis offerings, processes, or reporting to maintain compliance

On Communication

  • You’ve strategically developed and delivered global benefits training and communication for leaders and employees, in partnership with People Operations, Learning and Development, and HRBP teams
  • Coordinated with other team members and external vendors on benefit communications

A background like this helps: 

  • You’ve led and driven benefit programs in multinational organizations that operate with a mix of legal entities and HR.
  • You’ve worked with benefits programs in some of our fast growing locations: Canada, United Kingdom, Singapore, Korea, Spain, and the United Arab Emirates.
  • Have advanced knowledge in benefits plan design and ability to research as needed.
  • Know the ropes around regulatory compliance in benefits programs and the ability to scale processes in a high-growth environment.
  • Strong analytical skills with proficiency in GoogleSheets/Excel.
  • Love to collaborate with teams in a dynamic and global environment.
  • Display strong problem-solving skills with the ability to build relationships with various leaders across the organization.
  • Great organizational skills, high attention to detail, and strong sense of urgency, driven by results.

#LI-Remote #LI-AM1

Listed in: , , , , , , , , , , .

Digital Assets Research Analyst

We are looking for a full-time Digital Assets Research Analyst who is passionate about digital assets and DeFi ecosystems, and who wishes to gain experience working in a blockchain FinTech startup. The candidate will work closely with the founders and other teams, with a focus on building Treehouse’s research franchise and contributing to the holistic product-building process.

You will be working in the Research team in our Singapore office and reporting to our Strategy Lead.

Roles & Responsibilities

  • Monitor markets across TradFi/CeFi/DeFi and contribute to jointly-authored daily newsletter 

  • Conduct meaningful research into thematic topics or protocols and produce periodic deep-dive research articles 

  • Work closely with founders and product/marketing/quant teams as internal consultants to provide research-as-a-service

  • Conceptualise scenarios and use cases of Treehouse products; document proof-of-concept ideas 

  • Participate in key Crypto/DeFi events and represent Treehouse in collaboration with leading institutions and projects

Skills & Requirements

  • At least an undergraduate degree

  • 0-3 years of relevant professional experience

  • Experience in trading DeFi/preferably in traditional markets (previous equity/macro research experiences a plus)

  • Good understanding of global markets

  • Extremely strong written and oral communication skills

  • Meticulous and analytical thinker

  • Excellent Microsoft Excel modelling skills, experience with APIs/VBA

  • Strong work ethic, detail-oriented, and a passion for excellence

Company Description

Treehouse provides DeFi users with live analytics and risk metrics of their digital assets. We are building a unified and user-friendly interface to help users successfully manage their portfolio in the ever-changing world of DeFi. We aim to be the gateway for all traders to effectively manage their DeFi risk across chains, and are backed by some of the world’s top VCs. We strive to provide a people-centred culture with a focus on personal development and professional growth.

Listed in: , , , , , , .

Senior Product Security Engineer-Application Security

Chainalysis is seeking a dynamic and passionate Application Security Engineer with experience to join our cutting-edge team. As a trailblazer in blockchain forensics, we require a candidate with a strong understanding of application security principles, excellent communication skills, and the ability to collaborate with various stakeholders. A background in software development is valuable. In this crucial role, you will safeguard our organization’s critical data and applications within cloud and application environments, contributing to the advancement of our innovative blockchain solutions.

Key Responsibilities:

  • Proactively identify, assess, and prioritize security issues in cloud and application environments, managing remediation processes
  • Collaborate with development teams to integrate security best practices throughout the application development life cycle
  • Manage and optimize application security tools, such as JFrog Xray, SonarCloud, and Burp Suite, ensuring alignment with organizational security requirements and best practices
  • Develop and maintain Software Bill of Materials (SBOMs) for applications, ensuring accurate tracking of software components and their dependencies, and perform Software Composition Analysis (SCA) on the SBOMs to identify and address potential security vulnerabilities, license compliance issues, and outdated dependencies.
  • Implement and manage security workflows and processes, focusing on application security testing to maintain a secure and compliant ecosystem
  • Develop and maintain meaningful security metrics for application security tools and testing, evaluating effectiveness and alignment with organizational security requirements and best practices
  • Provide support to internal users of security tools, promptly responding to Jira tickets assigned to the security team, ensuring effective collaboration and addressing security-related concerns
  • Conduct security assessments and penetration testing on applications and systems to identify and address vulnerabilities
  • Develop and maintain security policies, procedures, and standards to ensure compliance with regulatory and industry requirements
  • Perform comprehensive security reviews of applications hosted on AWS by threat modeling, identifying potential vulnerabilities, and providing remediation strategies. 
  • Design, develop, and implement security automation using AWS security services and third-party tools to automate the security review process for applications hosted on AWS. 

Key Technical Skills:

  • Knowledge of OWASP Top 10 vulnerabilities and mitigation techniques; experience identifying and exploiting common vulnerabilities in web applications and networks
  • Proficiency in web application security frameworks and tools, including Burp Suite, Nmap, Metasploit, and experience with network and application security testing
  • Familiarity with secure development practices, such as secure coding, threat modeling, and security risk assessment
  • Experience in programming languages, using secure coding practices, such as Python, Java, or Javascript, and familiarity with Agile and DevOps methodologies
  • Knowledge of containerization technologies (e.g., Docker) and orchestration platforms (e.g., Kubernetes)
  • Experience with security testing tools, including Sonarcloud, Jfrog, or Burp, and integration into CI/CD pipelines
  • Experience using GitHub for secure code development and knowledge of GitHub Actions for automated security testing and deployment pipelines
  • Experience with AWS security services and tools: Proficiency in AWS security services such as AWS Security Hub, AWS Config, AWS Inspector, and AWS GuardDuty, among others.
  • Understanding of Infrastructure as Code (IaC) security: Knowledge of best practices for securing Infrastructure as Code (IaC) scripts, such as AWS CloudFormation templates or Terraform scripts. Experience in using tools like Checkov or Bridgecrew for IaC security scanning and remediation.

#LI-BD1 #LI-Remote

Listed in: , , , , , , , , , , .