Job Description
Coinspaid Dev is the engineering brand behind the technology, infrastructure, and R&D expertise built within Coinspaid. With more than 120 engineers and over 11 years of industry experience, Coinspaid Dev brings together software engineering, infrastructure, security and R&D teams with experience building distributed systems and blockchain infrastructure operating across more than 20 blockchain networks.
Coinspaid Dev emerges as an independent engineering brand with a straightforward mission: to advance blockchain infrastructure engineering and contribute practical expertise back to the industry. The structure is new. The experience behind it is not.
Responsibilities:
- Support and continuously improve the company's Vulnerability Management process.
- Perform vulnerability triage, risk assessment, prioritization, and remediation tracking.
- Work with engineering teams to ensure timely remediation of identified vulnerabilities.
- Analyze findings from multiple security tools and sources and reduce noise through effective prioritization.
- Monitor vulnerability remediation SLAs and provide visibility into security posture through reporting and metrics.
- Participate in threat modeling activities for new systems, services, and significant architectural changes.
- Conduct security risk assessments and provide actionable recommendations.
- Define and maintain application security requirements in collaboration with engineering teams.
- Support Secure SDLC initiatives and help integrate security practices into development workflows.
- Provide guidance to developers and DevOps engineers on vulnerability remediation and secure design practices.
Requirements:
- 4+ years of experience in Application Security, Product Security, Vulnerability Management, or a related security discipline.
- Hands-on experience managing and prioritizing vulnerabilities across applications, infrastructure, containers, and cloud environments.
- Strong understanding of OWASP Top 10, CWE, CVSS, EPSS, MITRE ATT&CK, and risk-based vulnerability management approaches.
- Experience with security testing technologies such as SAST, DAST, SCA, Container Security, and Cloud Security tools.
- Experience conducting threat modeling and security risk assessments.
- Understanding of modern software development practices and CI/CD pipelines.
- Familiarity with Kubernetes and cloud platforms (AWS, GCP, or Azure).
- Ability to analyze security findings and make risk-based remediation recommendations.
- Strong stakeholder management and communication skills.