At a Glance
- Tasks: Lead security operations and protect sensitive data in a cutting-edge crypto environment.
- Company: Join a pioneering cybersecurity firm focused on secure cloud solutions for crypto.
- Benefits: Enjoy competitive salary, equity options, remote work, and generous paid time off.
- Why this job: Be at the forefront of crypto security and make a real impact in the digital asset industry.
- Qualifications: 10+ years in security engineering with expertise in incident response and API security.
- Other info: Work in a dynamic, fully remote team with opportunities for professional growth.
The predicted salary is between 72000 - 108000 £ per year.
Our client is a cybersecurity company that builds custody SaaS protocol for web3 apps. Their mission is to bring serenity to DeFi by eliminating new blockchain risks and making crypto transactions easier, faster, more affordable, and compliant with existing regulations.
You will contribute to one of the most ambitious technology projects in crypto today: building a trustless custody infrastructure for the trillion-dollar digital asset industry. You will join an amazing team of leaders and experts in a highly challenging and collaborative environment.
We are looking for a Principal Security Engineer to run security operations within our company. You will have to demonstrate excellent surveillance and emergency response skills. You will need a strong commitment to security rules and knowledge of all hazards and threats to safety. Ultimately, you will work to ensure the security of our business information, employee data and client information throughout our entire network.
As Principal Security Engineer, you will:
- Detect insecure features and malicious activities within our networks and infrastructure.
- Implement customized application security assessments for client-based asset risk and corporate policy compliance.
- Conduct vulnerability assessments.
- Have an advanced understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements.
- Focus on assessing vulnerabilities and how those risks could be mitigated.
- Make things more secure by protecting system boundaries, keeping computer systems and network devices hardened against attacks and securing highly sensitive data.
Your primary goal will be to create and preserve environments where employees, clients and assets are monitored, safe, and well-protected.
Your day-to-day projects will involve:
- Sharing the big picture to your team, defining the levels of priority within the product roadmap, and being accountable for the deadlines and the quality of production.
- Acting as a powerhouse of ideas on all security and technical issues.
- Determining security violations and inefficiencies by conducting periodic audits.
- Keeping customers updated via performance and system status reports.
- Analyzing security systems, researching weaknesses, reporting possible threats or software issues, and finding ways to counter them on a daily basis.
- Creating and maintaining artefacts in a protected repo established as a single source of truth.
- Finding and removing outdated and vulnerable code and code libraries.
- Building security tooling and automation for internal use that enable SecTeam to operate at high speed and at scale.
- Detecting and responding to company-wide security incidents.
- Running security forensics in the case of a cyber attack and/or a data leak.
- Identifying and mitigating complex security vulnerabilities before an attacker exploits them.
- Taking initiatives to curb known abusive activity, and identifying unknown abuse vectors.
- Focusing on designing, researching, and executing attacks to challenge the blue team.
- Reporting on the red team engagements providing in-depth analysis of the security issues.
- Developing technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks.
- Writing comprehensive reports including assessment-based findings, outcomes and propositions for further system security enhancement.
- Authoring and updating internal and external docs, and formally initiating and delivering requirements.
- Facilitating cross-branch communication and know-how exchange between team members.
- Handling communications with independent vulnerability researchers and designing appropriate mitigation strategies for reported vulnerabilities.
- Implementing security best practices and new ideas to encourage innovation within your team.
- Working closely with CISO to embed best-in-class information security processes within the corporate policies, processes, and internal workflows.
- Making proposals across several teams on cross-functional security initiatives.
- Acting as DRI and escalation point for teams facing extremely complex technical challenges.
- Keeping abreast of the latest developments in crypto, DeFi and blockchain to feed the company's strategic orientations.
- Continually researching current and emerging technologies and propose changes.
Requirements:
- 10+ years experience as a Principal Security Engineer, 2+ years direct experience with incident response, and 2+ years experience in anti-abuse processes.
- Recognized security expert in multiple specialty areas, with cross-functional team experience.
- Ownership of significant sub-department objectives, goals and OKRs.
- Engineering expert capabilities of challenging the reasoning of other engineers.
- Experience in designing and securing APIs (RESTful, GraphQL, SWIFT).
- In-depth understanding of coding languages, namely Rust, Go, Python, and/or Typescript.
- Hands-on experience analyzing high volumes of logs, network data and attack artefacts.
- Proficiency with antivirus, vulnerability scanning and information security software.
- Detailed technical knowledge of database and operating system security.
- Hands-on experience in security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, etc.
- Ability to discover and patch SQLi, XSS, CSRF, SSRF, authentication and authorization flaws, and other web-based security vulnerabilities (OWASP Top 10 and beyond).
- Experience with cloud platforms such as AWS, GCP, and setting up environments between them.
- Thorough understanding of the latest security principles, techniques, and protocols.
- Excellent knowledge of security procedures and relevant industry standards (ISO, SOC, etc.).
- Experience testing secure, fault-tolerant, and resilient systems.
- Excellent analytical and problem-solving skills.
- Excellent written and verbal communication skills.
- Humble, respectful, and very professional to others.
- Able to decide even in stressful, unstable situations.
- Appetite for Cybersecurity, Fintech, Blockchain and/or Crypto industries.
Benefits:
- Salary: K / year (avg base range).
- Equity: % M in case of 2B exit.
- Bonus: Peer and spot bonuses after 8 months with us.
- Location: Hybrid. You can either work in our offices, from home, or remote.
- Paid time off: No less than 30 days per year, plus national holidays.
- Employee benefits: Healthcare, life insurance, retirement plan, sponsored transportation, gym cards, food, Apple devices and home office equipment, tuition fee assistance, team retreats, and more.
Principal Security Engineer in London employer: Growtoday AB
Contact Detail:
Growtoday AB Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Principal Security Engineer in London
✨Network Like a Pro
Get out there and connect with people in the cybersecurity field! Attend meetups, webinars, or conferences related to crypto and security. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Show Off Your Skills
Don’t just tell them what you can do; show them! Create a portfolio of your projects, especially those related to security assessments or vulnerability management. This will give potential employers a taste of your expertise and problem-solving skills.
✨Ace the Interview
Prepare for technical interviews by brushing up on your knowledge of TCP/IP, security protocols, and common vulnerabilities. Practice explaining complex concepts in simple terms, as communication is key in this role. Remember, they want to see how you think!
✨Apply Through Our Website
When you find a role that excites you, apply directly through our website! It shows you're genuinely interested and makes it easier for us to track your application. Plus, we love seeing candidates who take that extra step!
We think you need these skills to ace Principal Security Engineer in London
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Principal Security Engineer role. Highlight your relevant experience in cybersecurity, especially around incident response and API security, to show us you’re the perfect fit!
Show Off Your Skills: Don’t hold back on showcasing your technical expertise! Include specific examples of how you've tackled security vulnerabilities or improved systems in your previous roles. We love seeing real-world applications of your skills.
Be Clear and Concise: When writing your application, keep it clear and to the point. Use bullet points where possible to make it easy for us to read through your achievements and qualifications. We appreciate a well-structured application!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates from our team. Let’s get started on this journey together!
How to prepare for a job interview at Growtoday AB
✨Know Your Stuff
Make sure you brush up on your knowledge of security principles, especially those relevant to the crypto and DeFi space. Be ready to discuss TCP/IP, OSI model, and common vulnerabilities like SQLi and XSS. The more you can demonstrate your expertise, the better!
✨Showcase Your Experience
Prepare specific examples from your past roles that highlight your incident response skills and your experience with security audits. Talk about how you've tackled complex security challenges and what tools or methodologies you used. This will show them you’re not just a theorist but someone who gets things done.
✨Ask Smart Questions
Don’t just wait for them to ask if you have questions. Prepare insightful queries about their security practices, the tech stack they use, or how they handle emerging threats in the crypto space. This shows your genuine interest and helps you gauge if the company is the right fit for you.
✨Be Ready for Technical Challenges
Expect some technical questions or even practical tests during the interview. Brush up on your coding skills, especially in Rust, Go, Python, or Typescript. They might want to see how you approach problem-solving in real-time, so be prepared to think on your feet!