D

DevOps Security Engineer

Decentralized Mastersvia LinkedIn
RemotoRio de JaneiroSêniorCLT5 dias atrás

Salário Estimado

R$ 14.300,00 - R$ 21.450,00

Descrição da Vaga

About LegacyLegacy is an easy-to-use, non-custodial Web3 wallet designed to protect digital assets through beneficiary protection and seamless DeFi access.


Users can swap across chains, earn yield in one click, and safeguard wealth for the next generation.


Legacy is built by the team behind Decentralized Masters - a profitable $50M+ education and investment ecosystem with 4,000+ high-net-worth investors.


We've launched.


Demand is strong.


Now we need someone to own the post-acquisition customer journey and turn users into long-term, high-LTV subscribers.


About The Software DivisionWe are building a portfolio of software products inside the Decentralized Masters ecosystem, including:Legacy Wallet - a non-custodial Web3 wallet with beneficiary protection and seamless DeFi accessTrading Bot - automated crypto execution tools for serious investorsFuture fintech and investor infrastructure toolsWe are now building the retention and lifecycle engine that will power long-term recurring revenue across all products.


About The RoleYou will be the single person responsible for the security of a platform that tracks hundreds of millions in digital assets.


That is the job.


Everything else is secondary.


We need someone who breaks things for a living.


Someone who looks at a login page and sees six attack vectors.


Someone who reads a pull request and catches the injection vulnerability that two senior developers missed.


Someone who lies awake thinking about the phishing campaign that hasn't been invented yet.


If that sounds exhausting, this is not your role.


If that sounds like Tuesday, keep reading.


Your primary responsibilities are security and quality assurance.


You own penetration testing, vulnerability assessments, threat modeling, automated test frameworks, and CI quality gates across every product we ship.


You also own infrastructure: AWS, CI/CD pipelines, monitoring, and incident response.


And because we are a small, senior team, you will write production code when security and QA responsibilities are covered.


You are not a consultant or a checkbox auditor.


You are an engineer who ships, and whose code happens to make everything else harder to break.


The ideal candidate has spent time at major product-driven fintech and crypto companies where a single security failure can destroy user trust overnight.


What You Will OwnSecurity (Primary)Own the security posture across all products: Legacy, Trading Bot, and future platforms.


If something gets breached, it is your problem.


If nothing gets breached, it is because of your workConduct regular penetration testing, vulnerability assessments, and threat modeling aligned with OWASP standards and methodologiesEnsure full coverage of the OWASP Top 10 in application security testing, code reviews, and deployment checksPerform security-focused code reviews across frontend, backend, and infrastructure code, catching what standard code reviews missImplement and manage secrets management (Vault, AWS Secrets Manager, or KMS), access controls, and least-privilege policiesBuild and maintain incident response playbooks.


When something breaks, you lead the response, run the post-mortem, and ship the fixStay ahead of Web3 and crypto-specific attack vectors: phishing campaigns, wallet exploits, API key compromises, supply chain attacks, and social engineeringManage and coordinate external security audits and penetration tests from third-party firmsQuality Assurance & Testing (Primary)Design and implement test strategies across all products: unit tests, integration tests, end-to-end tests, API tests, and regression suitesBuild and maintain automated testing frameworks and CI quality gates that prevent broken code from reaching productionDefine and track quality metrics: test coverage, flakiness rate, regression detection latency, and bug escape rateWrite and execute security test cases: authentication flows, authorization controls, input validation, API abuse scenarios, and edge cases around financial dataPerform both white-box and black-box testing, leveraging full codebase access to catch issues that surface-level QA would missTest across the full stack: frontend UI, backend APIs, database queries, third-party integrations, and on-chain interactionsInfrastructure & DevOps (Foundation)Maintain and improve cloud infrastructure on AWS using Infrastructure as Code (Terraform or CloudFormation)Own CI/CD pipelines (GitHub Actions preferred): automated testing, security scanning, linting, and deploymentHarden infrastructure: network security, IAM policies, container security, and environment isolationBuild logging, monitoring, and alerting across all services (CloudWatch, Prometheus, Grafana, or equivalent)Ensure audit trails for user actions, system changes, and access eventsManage production reliability, incident response, and cost optimizationFullstack Development (When the fortress is secure)Contribute production code across frontend and backend, bringing a security-first mindset to every feature you buildBuild features, fix bugs, and ship improvements alongside the engineering teamEvery line you write should make the product better and harder to break: input validation, error handling, authentication, and data protection by defaultParticipate in architecture discussions and code reviews, advocating for testability, reliability, and security in every decisionRequirementsWhat You BringRequired5+ years in software engineering roles with meaningful, hands-on security and QA experience.


We will verify this.


If your security experience is theoretical, this is not the right fitFullstack development experience: you can build and ship features across frontend (React or equivalent) and backend (Node.js, Python, Go, or equivalent)Hands-on penetration testing and vulnerability assessment experience across web applications, APIs, and cloud infrastructureStrong working knowledge of OWASP standards, including the OWASP Top 10, OWASP Testing Guide, and OWASP secure coding practicesExperience building automated test frameworks and integrating testing into CI/CD pipelinesAWS expertise (EC2, ECS/EKS, Lambda, VPC, IAM, S3, RDS, CloudFront, WAF)Infrastructure as Code experience (Terraform, CloudFormation, or Pulumi)Container technologies: Docker and Kubernetes in production environmentsScripting and automation proficiency in Bash and PythonExperience with secrets management tools (HashiCorp Vault, AWS Secrets Manager, or similar)Familiarity with security and testing tools (Burp Suite, OWASP ZAP, Selenium, Cypress, Jest, Postman, or equivalent)Strong communication skills: you can explain security risks and quality tradeoffs clearly to non-technical stakeholdersNice-to-HaveSecurity certifications: OSCP, CISSP, CompTIA Security+, AWS Security Specialty, or equivalentExperience at a crypto, DeFi, Web3, or fintech product company (Coinbase, Phantom, Stripe, Casa, MetaMask, Zerion, Ramp, or similar)Familiarity with Web3-specific security concerns: wallet security, key management, on-chain monitoring, phishing mitigationSDET background or experience in a hybrid development-and-testing roleExperience testing financial systems: payment flows, ledger integrity, double-spend prevention, or transaction monitoringExperience implementing zero-trust architecturesBug bounty participation, CVE publications, or contributions to open-source security toolingBenefitsWhat We OfferCompetitive salary + performance-based incentives tied to retention & LTV improvementDirect exposure to foundersTeam OffsitesRemote workHigh ownership, high-impact role

Vagas Semelhantes

H

Full Stack Engineer

HeartCentrix SolutionsLinkedIn
São Paulo6 dias atrás

R$ 16k - 23k/mês

SêniorCLT

Senior Full Stack Engineerhttps://bit.ly/m/CodeReportSeniority Requirements3–5+ years of professional experience in full-stack engineering or a related fieldDemonstrated success delivering high-quality solutions in commercial and/or consulting environmentsFluency in Portuguese and English (both writ...

T

Senior Platform Engineer

TimescaleLinkedIn
RemotoBrazil5 dias atrás

R$ 12k - 18k/mês

SêniorCLT

At Tiger Data, formerly Timescale, we empower developers and businesses with the fastest PostgreSQL platform designed for transactional, analytical, and agentic workloads. Trusted globally by thousands of organizations, Tiger accelerates real-time insights, drives intelligent applications, and power...

RemotoBr11 dias atrás

R$ 17k - 28k/mês

EspecialistaCLT

Responsabilidades e atribuições • Participar do ciclo de vida dos produtos, com atuação full‑stack e foco em back‑end; • Contribuir ativamente em decisões técnicas e arquiteturais; • Participar da definição e implementação da arquitetura de aplicações, incluindo abordagens distribuídas e serverless;...

J

Desenvolvedor(a) Full Stack

JOYn GroupLinkedIn
RemotoBlumenau, Santa Catarina, Brazil4 dias atrás

R$ 11k - 17k/mês

SêniorCLT

A JOYn RH é uma consultoria especializada em recrutamento, conectando talentos a empresas em crescimento no Brasil e no mundo.Sobre a VagaBuscamos um(a) Desenvolvedor(a) Backend para atuar diretamente na evolução da plataforma, contribuindo com desenvolvimento de novas funcionalidades, melhorias téc...

Interessado nesta vaga?

Candidatar-se

Você será redirecionado para o site original

Informações

NívelSênior
ContratoCLT
LocalRio de Janeiro
RemotoSim
MoedaBRL
Publicada5 dias atrás
FonteLinkedIn

Análise de Vaga com IA

Estimativa salarial, match de tecnologias e análise de requisitos feitos com Inteligência Artificial

Quer se preparar melhor? Pratique entrevistas com IA no Recrutadoria ou melhore suas habilidades no BitMentor

← Voltar às Vagas