Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Security Engineer SDLC image - Rise Careers
Job details

Senior Security Engineer SDLC

We're making the world of digital assets accessible and secure for everyone. Join the mission. Founded in 2014, Ledger is the global platform for digital assets and Web3. Over 20% of the world’s crypto assets are secured through our Ledger Nanos.

Headquartered in Paris and Vierzon, with offices in UK, US, Switzerland and Singapore, Ledger has a team of more than 900 professionals developing a variety of products and services to enable individuals and companies to securely buy, store, swap, grow and manage crypto assets – including the Ledger hardware wallets line with more than 6 millions units already sold in 200 countries.


At Ledger, we embody the values that make us unique: Pragmatism, Audacity, Commitment, Trust and Transparency. Hear from our employees how they shape the work we do here.


You will be part of our Security team and your responsibility will be to define and promote secure software development best practices across our engineering team and help ensure compliance with internal and external security standards and requirements.


Your mission


● Define, document and promote secure software development practices across Ledger’s engineering teams.

● Build and maintain security tooling to support automated analysis, vulnerability detection, and enforcement of secure coding standards.

● Drive the adoption of security checks and controls in the CI/CD pipeline (e.g. linters, SAST, dependency scanning).

● Own and improve our quorum-based release security process, ensuring that only reviewed, signed, and approved builds can be released to production.

● Provide guidance and support to developers on secure design and implementation decisions.

● Contribute to the definition and implementation of internal security standards, guidelines, and checklists.

● Partner with the Product Security, Donjon, and Software teams to ensure security is a shared responsibility throughout the SDLC.

● Monitor industry trends and adapt internal practices to evolving threats and technologies.

● Help ensure compliance with internal and external security requirements (e.g. certifications, audits).



What we’re looking for


● Strong experience with secure software development processes and practices (e.g. threat modeling, secure coding, security testing). ● Practical experience implementing and managing security tooling in a CI/CD environment.

● Experience writing or maintaining security-related documentation and standards.

● Familiarity with modern software delivery practices (e.g. GitOps, infrastructure as code).

● A pragmatic mindset focused on enabling developers rather than blocking them.

● Prior experience working with or managing secure release models is a plus.

● Good understanding of risk assessment and software architecture security.



Technical Skills


● Proficiency in scripting and automation (Python, Bash, etc).

● Familiarity with code analysis tools (linters, SAST, dependency scanners like Snyk or Trivy).

● Understanding of common software vulnerabilities (e.g. OWASP Top 10) and how to prevent them.

● Experience with GitHub workflow and build systems.

● Knowledge of secure release workflows (signing, approvals, reproducible builds).

● Experience in C, Rust, Scala, or embedded environments is a plus.

● Basic knowledge of cryptography and secure communications protocols is a plus.


What’s in it for you?


● Equity: Employees are the foundation of our success, and we award stock options so you can share in that success as we grow.

● Flexibility: A hybrid work policy.

● Social: Annual company outing for Ledgerdary Days, plus frequent social events, snacks and drinks.

● Medical: Comprehensive health insurance policy offering extensive medical, dental and vision care coverage.

● Well-being: Personal development, coaching & fitness with our dedicated partners.

● Vacation: Five weeks of paid leave per year, in addition to national holidays and rest & relaxation (RTT) days.

● High tech: Access to high performance office equipment and gadgets, including Apple products.

● Transport: Ledger reimburses part of your preferred means of transportation.

● Discounts: Employee discount on all our products.


Ledger Glassdoor Company Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Ledger DE&I Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Ledger
Ledger CEO photo
Pascal Gauthier
Approve of CEO

Average salary estimate

$95000 / YEARLY (est.)
min
max
$70000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Security Engineer SDLC, Ledger

At Ledger, we're on a thrilling mission to make digital assets accessible and secure for everyone. As a Senior Security Engineer specializing in the Software Development Life Cycle (SDLC), you will play a pivotal role in shaping the security landscape at our company. Founded in 2014, Ledger is recognized as the global leader in the crypto space, securing over 20% of the world’s crypto assets with our innovative Ledger Nanos. Based in the tech-savvy hub of Paris, you’ll be part of a diverse team of over 900 professionals committed to developing state-of-the-art products that empower individuals and enterprises to manage their crypto securely. In this role, you'll define and promote secure software development best practices, drive security checks within our CI/CD pipeline, and foster a culture of security across our engineering teams. You’ll also have the opportunity to lead efforts in security tooling, automate vulnerability detection, and ensure compliance with both internal and external security standards. By collaborating closely with various teams, you'll help us enhance the trust and transparency that are core to Ledger's values. If you're passionate about molding a secure digital future and enhancing the security of software development practices, we can’t wait for you to join us on this journey!

Frequently Asked Questions (FAQs) for Senior Security Engineer SDLC Role at Ledger
What responsibilities does a Senior Security Engineer SDLC at Ledger have?

As a Senior Security Engineer specializing in the SDLC at Ledger, you will be tasked with defining, documenting, and promoting secure software development practices across our engineering teams. Your role involves building and maintaining security tooling, integrating security checks in our CI/CD pipeline, and ensuring compliance with internal and external security standards.

Join Rise to see the full answer
What qualifications do I need to apply for the Senior Security Engineer position at Ledger?

To apply for the Senior Security Engineer SDLC role at Ledger, you should possess strong experience with secure software development processes, familiarity with security tooling in a CI/CD environment, and a solid understanding of risk assessment and software architecture security. Practical skills in scripting and automation are also essential.

Join Rise to see the full answer
How does Ledger support the development of its Senior Security Engineers?

At Ledger, we offer a robust environment for career growth as a Senior Security Engineer SDLC, where continuous learning and personal development are highly valued. You will have access to coaching and fitness programs through dedicated partners, ensuring you succeed both professionally and personally.

Join Rise to see the full answer
What tools and technologies will I be using as a Senior Security Engineer at Ledger?

As a Senior Security Engineer SDLC at Ledger, you will work with various tools such as code analysis tools, linters, and dependency scanners like Snyk or Trivy. You’ll also be using scripting languages like Python and Bash, and working within GitHub workflows and build systems.

Join Rise to see the full answer
What kind of work culture can I expect at Ledger?

Ledger prides itself on a culture built on pragmatism, audacity, commitment, trust, and transparency. You can expect a collaborative environment with a focus on enabling developers, complemented by a hybrid work policy and social events that enhance team spirit.

Join Rise to see the full answer
Common Interview Questions for Senior Security Engineer SDLC
Can you explain the role of secure coding practices in software development?

Secure coding practices are essential in preventing vulnerabilities in software. As a senior security engineer, you should emphasize how these practices protect against common threats, such as SQL injection or cross-site scripting, ultimately ensuring software integrity and trust.

Join Rise to see the full answer
How would you approach integrating security into the CI/CD pipeline?

When integrating security into the CI/CD pipeline, prioritize implementing automated security checks and validation steps at each stage of the pipeline. Discussing tools like SAST, DAST, and dependency scanning can also demonstrate your technical proficiency and strategic thinking.

Join Rise to see the full answer
What experience do you have with threat modeling?

Discuss any specific frameworks you've used for threat modeling, such as STRIDE or PASTA, and share examples of how you've successfully identified potential vulnerabilities early in the development lifecycle, resulting in better outcomes.

Join Rise to see the full answer
Explain the importance of security documentation.

Security documentation is vital for ensuring that all security processes and practices are effectively communicated across teams. Highlight how well-maintained documentation can serve as a resource for training and compliance, promoting security awareness company-wide.

Join Rise to see the full answer
How do you keep up with the latest security trends?

Show your initiative by mentioning specific blogs, podcasts, or conferences you follow. Share how you implement your learnings into practical strategies that enhance security practices within your previous teams.

Join Rise to see the full answer
Describe your experience with common software vulnerabilities.

You should be able to acknowledge and explain vulnerabilities listed in the OWASP Top 10, providing examples of how you've successfully mitigated them in previous roles. This shows a practical understanding of real-world risks.

Join Rise to see the full answer
How would you ensure compliance with security standards in a project?

Explain the importance of early involvement in the project lifecycle, discussing how setting clear security guidelines and performing regular audits can help teams stay compliant while maintaining developmental agility.

Join Rise to see the full answer
What role do you think developers play in security?

Developers are the first line of defense when it comes to software security. Emphasize how fostering a culture of shared responsibility for security within development teams can significantly reduce vulnerabilities and enhance overall project security.

Join Rise to see the full answer
Can you give an example of a security incident you managed?

Discuss a specific incident where you played a role in incident response. Highlight your decision-making process, team collaboration, and how the experience informed future security practices.

Join Rise to see the full answer
What’s your experience with cryptography and secure communications protocols?

Touch on your familiarity with different cryptography methods and secure communication protocols, providing examples of when you applied these in your previous roles to enhance data security.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 20 hours ago

Lead cross-functional teams in delivering impactful products at Ledger, a global digital assets platform, as their next Senior Project Manager.

Photo of the Rise User

Join Ledger as an Associate Product Manager and help shape the future of digital assets within a dynamic and international team.

Photo of the Rise User
Posted 13 days ago

Join Splice as a Senior Engineering Manager and lead a team in driving innovation for a top-tier music creation platform.

iberdrola Hybrid United States Of America, New York, Rochester
Posted 6 days ago

As a Principal Engineer - Civil at Avangrid, you'll oversee major infrastructure projects while mentoring engineering talent and ensuring compliance with industry standards.

Join International Vitamin Corporation as a Manufacturing Engineer II, focusing on process control and automation improvements in a dynamic manufacturing environment.

Serco North America Remote OH-Dayton US-OH-Beavercreek US-OH-Columbus US-OH-Dayton US-OH-Delaware
Posted 5 days ago

We are looking for an experienced Network and Enterprise Architecture Engineer to support the MQ-9 Pred/Reaper UAS at Serco, based at Wright Patterson AFB.

Photo of the Rise User
Insomnia Cookies Hybrid Philadelphia PA (Center City HQ)
Posted yesterday

Insomnia Cookies is on the lookout for a hands-on Director of Engineering to elevate their web and mobile applications while managing a talented engineering team.

Photo of the Rise User
AECOM Remote Phoenix, AZ, United States
Posted 9 days ago

AECOM is looking for a motivated Junior Geotechnical Engineer to support key mining and civil infrastructure projects remotely from Phoenix, AZ.

We are looking for a Systems Methods and Tools Functional Architect to join Airbus and contribute to innovative aircraft design solutions.

Photo of the Rise User
Posted 3 hours ago

Visa seeks an experienced Staff DevOps Engineer who thrives on solving complex challenges and enhancing software development processes.

Founded in 2014, Ledger is the global platform for digital assets and Web3. Over 15% of the world’s crypto assets are secured through Ledger Nanos. Headquartered in Paris and Vierzon, with offices in London, New York and Singapore, Ledger has a te...

99 jobs
MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 6, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Warren just viewed Senior Front-End Developer at Worldly
Photo of the Rise User
Someone from OH, Tiffin just viewed Game Operations Specialist at Genius Sports
u
Someone from OH, Loveland just viewed Customer Service Agent - Part Time at uhaul
Photo of the Rise User
Someone from OH, Cleveland just viewed HR Manager at Shearer's Foods
Photo of the Rise User
Someone from OH, Columbus just viewed Mid Level, System Administrator - (ETS) at Delivery Hero
Photo of the Rise User
Someone from OH, Mason just viewed Inside Sales Co-Op at VEGA Americas
Photo of the Rise User
Someone from OH, Sandusky just viewed Director of IT at Kyo
Photo of the Rise User
Someone from OH, Delaware just viewed Practice Group Manager at LifeStance Health
Photo of the Rise User
6 people applied to Machinist Apprentice at LLNL
Photo of the Rise User
Someone from OH, Avon Lake just viewed Advancement Specialist at Sierra Club
Photo of the Rise User
Someone from OH, Sidney just viewed Database Engineer Principal at Sagent
Photo of the Rise User
Someone from OH, North Canton just viewed Manager, Customer Success at impact.com
Photo of the Rise User
Someone from OH, Columbus just viewed Customer Experience Representative at MYOB
Photo of the Rise User
Someone from OH, Lakewood just viewed Production Scheduling Supervisor at Shearer's Foods
Photo of the Rise User
Someone from OH, Hilliard just viewed General Manager at Super Soccer Stars