Product Security Engineer
Brak informacji o wynagrodzeniu
SeniorFull-time
#401774·Dodano 2 dni temu·2
Źródło: GoMiningTech Stack / Keywords
SecurityCloudArchitectureBackendTestingSDLCCI/CDKubernetes
Firma i stanowisko
GoMining is an international crypto company reshaping Bitcoin mining through its Liquid Bitcoin Hashrate (LBH) protocol. It creates Digital Miners backed by real hashrate that generate daily BTC rewards, develops the LBH protocol for DeFi integration, and offers the Play-to-Earn strategy game Miner Wars. The company operates proprietary data centers and its ecosystem includes the GOMINING Token, serving over 3.7 million users worldwide, with listings on major exchanges.
Wymagania
- 4+ years of experience in Product Security, Application Security, Software Engineering, or Security Engineering.
- Strong software engineering background.
- Experience securing backend systems, REST APIs, and microservices.
- Experience with cloud platforms: AWS, GCP, or Azure.
- Strong understanding of Kubernetes, Docker, networking, and infrastructure security.
- Experience with Secure SDLC and security automation.
- Hands-on experience with SAST, DAST, dependency scanning, and secrets management.
- Understanding of OWASP Top 10, common attack vectors, and secure coding practices.
- Ability to work closely with software engineers and influence technical decisions.
- Fluent English.
Nice to have:
- Mobile application security experience.
- Experience in fintech, crypto, payments, or blockchain.
- Offensive security or penetration testing experience.
- Security certifications are a plus but not required.
Obowiązki
Application Security:
- Review application architecture and new product features from a security perspective.
- Identify security vulnerabilities across backend services, APIs, mobile applications, and web platforms.
- Perform threat modeling and security design reviews.
- Support internal and external penetration testing activities.
Secure Development:
- Build and improve Secure SDLC across engineering teams.
- Integrate security tooling into CI/CD pipelines.
- Improve developer security practices and provide technical guidance.
- Help engineering teams remediate vulnerabilities.
Cloud & Infrastructure Security:
- Improve the security posture of cloud infrastructure.
- Secure Kubernetes, IAM policies, secrets management, and infrastructure components.
- Implement security monitoring and hardening best practices.
- Collaborate with Platform and DevOps teams.
Security Automation:
- Deploy and maintain SAST, DAST, dependency scanning, container scanning, and secret detection tools.
- Automate security checks and developer workflows.
- Continuously improve security visibility across engineering.
Benefity
- Professional growth support: courses, conferences, and English learning up to 100% coverage.
- Remote or hybrid work format with flexible hours.
- Paid leave: up to 20 vacation days, 8 company holidays, and 5 personal days per year.
- Recognition programs including structured performance reviews and team awards.
- Team retreats in international locations, e.g., company apartments in Cyprus.
Elastyczne godziny
Płatny urlop
Dofinansowanie szkoleń
Budżet konferencyjny
Spotkania integracyjne
Kursy językowe
GoMining
5 aktywnych ofert