Senior Security Engineer - Automation

Remote $210k–$221k senior 3 months ago full-time quality 9/10

Role in brief

MoonPay seeks a Senior Security Engineer to automate security tooling and manage vulnerabilities. This role involves integrating SAST, DAST, SCA, and secrets scanning into CI/CD pipelines, streamlining security workflows, and ensuring timely remediation. Candidates with a software development background and a strong focus on cybersecurity automation, especially with Go, Python, or Node.js, should apply.

GoPythonNode.jsSASTDASTSCASecrets ScanningGitHubAWSGCP

About the role

This role centers on enhancing MoonPay's security posture through automation and vulnerability management. The engineer will design and implement security tooling integrations into CI/CD pipelines, develop automation scripts, and manage the full vulnerability lifecycle from identification to reporting. This involves close collaboration with engineering teams to guide secure coding practices and ensure prompt remediation of issues.

A key aspect of this position is driving the adoption of the SLSA framework to strengthen supply chain security. The engineer will continuously evaluate and improve existing automation and vulnerability management workflows, bringing innovation to these processes. This includes researching emerging threats relevant to the tech stack and translating findings into actionable prevention mechanisms.

The Product Security Squad at MoonPay emphasizes proactive defense, rigorous security reviews, and threat modeling. The team provides various security services to engineering teams, including cloud security advice and penetration testing. Success in this role means fostering a secure development environment by embedding best practices throughout the SDLC and contributing to a culture of security within the organization.

The annual salary for this full-time role is between $209,664 and $220,699.

Skills that matter here

  • Go: This role requires a solid background in software development, ideally using languages like Go for backend or infrastructure development.
  • Python: The engineer should have experience with Python for software development, particularly for scripting automation and streamlining security processes.
  • Node.js: Experience with Node.js is beneficial, as it is one of the common languages used in backend or infrastructure development relevant to this role.
  • SAST: The role involves designing and managing the integration of SAST tooling into CI/CD pipelines to identify security vulnerabilities early.
  • GitHub: A deep understanding of GitHub's functionalities, including advanced features and API capabilities, is essential for managing security settings and workflow automation.
  • AWS: Familiarity with cloud security principles in AWS is beneficial for providing tailored security advice and managing cloud environments.

Who this role suits

  • Someone with a strong software development background who is passionate about cybersecurity and wants to specialize in automation.
  • An individual who is self-motivated, innovative, and takes ownership of their work in a remote, fast-paced setting.
  • A person with excellent collaboration skills who can clearly explain complex security concepts and tooling requirements to technical teams.
  • A problem-solver who can identify inefficiencies and propose automated solutions to improve security workflows.

From the employer

  • Design, implement, and manage the integration of security tooling (SAST, DAST, SCA, Secrets Scanning) into our CI/CD pipelines.
  • Develop and maintain automation scripts and platforms to streamline security processes and workflows.
  • Own and operate the end-to-end vulnerability management lifecycle: identification, triage, prioritization, distribution, tracking, and reporting.
  • Collaborate closely with engineering teams to ensure timely remediation of identified vulnerabilities and provide guidance on secure coding practices.
  • Drive the adoption and implementation of the SLSA framework to enhance supply chain security.
  • Continuously evaluate and improve existing security automation and vulnerability management workflows, bringing innovation and ownership to the process.
  • Research emerging threats and vulnerabilities, particularly those relevant to our tech stack and development practices, translating findings into actionable detection or prevention mechanisms.
  • Develop and maintain documentation for security automation tools, processes, and vulnerability management procedures.
  • Assist in triaging and validating findings from various sources, including automated scanners, penetration tests, and bug bounty programs.
  • Contribute to security training materials focused on secure development practices and the tools you implement.
  • Support incident response activities, particularly where automation or vulnerability data can aid investigation and remediation.
  • Champion and execute the security team's automation strategy for cross-functional needs, actively seeking and implementing automation opportunities based on team feedback.
  • Solid background in software development with demonstrable experience, ideally using languages common in backend or infrastructure development (e.g., Go, Python, Node.js).
  • Strong passion for cybersecurity and keen to focus your career on security automation and vulnerability management.
  • Understanding of security tools like SAST, DAST, SCA, and secrets scanning solutions within a CI/CD environment (here at MoonPay we use Github).
  • Understanding of the principles of vulnerability management, including prioritization frameworks (e.g., CVSS) and remediation tracking.
  • Familiarity with the concepts and goals of the SLSA framework or similar supply chain security initiatives.
  • Excellent collaboration skills with technical teams, explaining security concepts and tooling requirements clearly.
  • Strong analytical and problem-solving skills, with an ability to identify inefficiencies and propose automated solutions.
  • Self-motivated, innovative, take ownership of your work, and can operate effectively in a remote, fast-paced environment.
  • Experience working in disruptive technology, FinTech, SaaS, or Crypto sectors is a plus.
  • Familiarity with cloud security principles (AWS, GCP) is beneficial.
  • Deep understanding of GitHub's functionalities, including advanced features, security settings, and API capabilities.
  • Strong administrative skills in managing and maintaining GitHub Enterprise environments, including user access, repository management, and organization settings.
  • Familiarity with GitHub Actions for workflow automation and security enforcement.
  • Salary: $209,664 - $220,699 a year.
  • Full-time employment.
  • Opportunity to work in a dynamic and innovative environment.

Questions about this role

What is the remote work policy for this position?

This is a fully remote position, allowing you to work from anywhere.

What is the seniority level for this role?

This is a senior-level position.

What is the salary range for this role?

The salary for this full-time position ranges from $209,664 to $220,699 per year.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to MoonPay.