Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Staff Cloud Security Engineer (f/m) image - Rise Careers
Job details

Staff Cloud Security Engineer (f/m)

We're making the world of digital assets accessible and secure for everyone. Join the mission. 


Founded in 2014, Ledger is the global platform for digital assets and Web3. Over 15% of the world’s crypto assets are secured through our Ledger Nanos. Headquartered in Paris and Vierzon, with offices in the UK, US, Switzerland and Singapore, Ledger has a team of more than 600 professionals developing a variety of products and services to enable individuals and companies to securely buy, store, swap, grow and manage crypto assets – including the Ledger hardware wallets line with more than 5 millions units already sold in 180 countries.  

At Ledger, we embody the values that make us unique: Pragmatism, Audacity, Commitment, Trust, and Transparency. Have a look at our Origins video here


Reporting to the Cyber Security Operations & Engineering Senior Manager, you will be a part of Ledger's Cyber Security team. 


Your mission : Building and driving the cybersecurity transformation by integrating secure development practices, ensuring application security via automated scanning, and collaborating closely with the Infrastructure, Engineering, and The product security (Donjon)  teams. 


As Ledger is at the forefront of the Web3 space, an interest in this area and in hardware wallets is a distinct advantage. We're a rapidly moving company and need individuals who can adapt quickly to our dynamic environment. 


We are looking for an experienced candidate in cybersecurity who is passionate about cloud technologies security, can work autonomously, and is eager to propose improvements to bolster the security posture of Ledger's applications, infrastructure and services.


The mission
  • Collaborate with the Infrastructure, the engineering and the Donjon teams to integrate security into the delivery plans, ensure early detection and mitigation of security vulnerabilities 
  • Work closely with the Donjon, the product Security team responsible, to provide automation and tooling for product security evaluation integration in CI/CD pipeline.   
  • Engage in proactive security practices, including penetration testing, vulnerability assessments, and Infrastructure Security (IaC) code reviews to ensure Ledger's platforms and applications are secure.
  • Participate in the design and implementation of security architectures, from the design to the risk assessment.
  • Act as the primary point of contact for any security incidents, ensuring rapid response, mitigation, and post-incident analysis.
  • Drive the adoption of DevSecOps culture, best practices, and methodologies across the organization, ensuring continuous security improvement.


What we're looking for
  • 5+ years of experience in DevSecOps & automation, security assessment, and cloud-native environments.
  • 8+ years of experience on information security
  • Proficiency working in Unix/Linux environments, Git, Python, Terraform, Kubernetes, AWS cloud solutions and architectures, CI/CD tools, configuration management, etc.
  • Hands-on experience with security tooling deployment, monitoring, and incident response.
  • Proven track record of cross-functional work, with the ability to collaborate effectively with various teams and stakeholders.
  • Excellent presentation and written communication skills.
  • Ability to work autonomously, deal with ambiguity, and handle high-pressure situations.


What's in it for you?
  • Equity: Employees are the foundation of our success, and we award stock options so you can share in that success as we grow. Flexibility: A hybrid work policy.
  • Social: Annual company outing for Ledgerdary Days, plus frequent social events, snacks and drinks
  • Medical: Comprehensive health insurance policy offering extensive medical, dental and vision care coverage. Well-being: Personal development, coaching & fitness with our dedicated partners.
  • Vacation: Five weeks of paid leave per year, in addition to national holidays and rest & relaxation (RTT) days.
  • High tech: Access to high performance office equipment and gadgets, including Apple products. 
  • Transport: Ledger reimburses part of your preferred means of transportation. 
  • Discounts: Employee discount on all our products.


We are an equal opportunity employer for all without any distinction of gender, ethnicity, religion, sexual orientation, social status, disability or age.


#LI-Hybrid #LI-RDH

Ledger Glassdoor Company Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Ledger DE&I Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Ledger
Ledger CEO photo
Pascal Gauthier
Approve of CEO

Average salary estimate

$105000 / YEARLY (est.)
min
max
$90000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Staff Cloud Security Engineer (f/m), Ledger

Are you ready to take on a meaningful role as a Staff Cloud Security Engineer at Ledger? Based in the vibrant city of Paris, France, you'll be joining a company that's on a mission to make digital assets accessible and secure for everyone. Here at Ledger, we're pioneers in the crypto space, ensuring over 15% of the world's crypto assets are protected through our innovative hardware wallets. In this role, you will report to the Cyber Security Operations & Engineering Senior Manager and work closely with our extraordinary Cyber Security team. Your primary mission will be to drive our cybersecurity transformation by integrating secure development practices and automating application security through proactive measures. With your wealth of experience in cloud technologies and cybersecurity, you'll collaborate with our Infrastructure, Engineering, and product security teams to enhance our security posture across applications, infrastructure, and services. You'll engage in tasks ranging from penetration testing to designing security architectures, all while maintaining a fun and supportive atmosphere where your ideas are truly valued. If you have a passion for technology and an interest in the rapid developments of the Web3 landscape, we'd love to hear from you. At Ledger, we believe in the mix of pragmatism, audacity, and trust, and we can’t wait for you to bring your unique talents and experiences to our passionate team. Join us and help shape the future of digital security!

Frequently Asked Questions (FAQs) for Staff Cloud Security Engineer (f/m) Role at Ledger
What are the key responsibilities of a Staff Cloud Security Engineer at Ledger?

As a Staff Cloud Security Engineer at Ledger, your primary responsibilities will include integrating security into delivery plans, conducting vulnerability assessments, and collaborating with the Infrastructure, Engineering, and product security teams to ensure we proactively safeguard our applications. Additionally, you will handle security incidents and drive the adoption of DevSecOps practices, aiming for continuous security enhancement.

Join Rise to see the full answer
What qualifications are required for the Staff Cloud Security Engineer position at Ledger?

To succeed as a Staff Cloud Security Engineer at Ledger, candidates should have at least 5 years of experience in DevSecOps, cloud-native environments, and security automation, alongside 8 years in information security. Proficiency in Unix/Linux, security tooling, and a solid understanding of AWS cloud solutions and CI/CD tools is essential.

Join Rise to see the full answer
How does the Staff Cloud Security Engineer position contribute to Ledger's mission?

The Staff Cloud Security Engineer plays a crucial role in Ledger's mission by ensuring the security of our digital asset platforms and services. By integrating security measures and driving proactive practices, you will help us maintain a secure environment for our customers' crypto assets, contributing directly to their trust in our products.

Join Rise to see the full answer
What kind of work culture can one expect at Ledger as a Staff Cloud Security Engineer?

At Ledger, we foster a work culture filled with pragmatism, commitment, and trust. We value flexibility and encourage collaboration across teams while supporting individual autonomy. You'll enjoy a dynamic environment that thrives on innovation and provides opportunities for personal and professional growth.

Join Rise to see the full answer
What benefits can a Staff Cloud Security Engineer expect at Ledger?

As a Staff Cloud Security Engineer at Ledger, you'll enjoy various benefits including equity in the company, a hybrid work policy, comprehensive health insurance, five weeks of paid leave per year, access to high-performance equipment, and incredible opportunities for personal development.

Join Rise to see the full answer
Common Interview Questions for Staff Cloud Security Engineer (f/m)
Can you describe your experience with integrating security into CI/CD pipelines?

When discussing your experience with CI/CD pipelines, share specific examples where you implemented security measures. Highlight your familiarity with tools and processes that automate security checks, and demonstrate how those integrations improved the overall security posture of the projects you worked on.

Join Rise to see the full answer
How do you approach vulnerability assessments in a cloud environment?

In your answer, outline a systematic approach to vulnerability assessments, emphasizing methodologies you've used like OWASP or SANS. Discuss your experience with tools for scanning and assessing vulnerabilities in cloud solutions, along with how you prioritize remediation actions based on risk assessment.

Join Rise to see the full answer
What security challenges do you foresee in the Web3 landscape?

Illustrate your understanding of the Web3 landscape by identifying various security challenges such as smart contract vulnerabilities, decentralized identity management issues, and the importance of user education. Providing examples of how you've addressed similar challenges in the past can strengthen your response.

Join Rise to see the full answer
Can you give an example of a security incident you managed?

When asked about a security incident, detail the context, actions taken during the incident response, and the outcome. Experts appreciate candidates who showcase their problem-solving skills and demonstrate their ability to learn from experience and implement changes to enhance security.

Join Rise to see the full answer
What tools have you found most effective for monitoring and incident response?

Discuss specific tools you're proficient with, detailing how you used them for real-time monitoring and incident response. Explain the rationale for your choices and any success stories of effectively mitigating threats using those tools.

Join Rise to see the full answer
Describe your experience with security tooling deployment.

In your response, share examples of security tools you've deployed in cloud environments. Explain the deployment process, the issues encountered, and how you addressed them to enhance existing security protocols.

Join Rise to see the full answer
How do you prioritize security in a fast-paced development environment?

Explain your methods for integrating security into the software development lifecycle, ensuring it doesn't hinder productivity. Discuss strategies for promoting a culture of security awareness among developers while balancing speed and security effectively.

Join Rise to see the full answer
What experience do you have in conducting penetration tests?

In your answer, specify how you have conducted penetration tests in the past. Detail your planning process, tools used, and how you reported findings to stakeholders. Make sure to illustrate how your tests led to actionable changes in security measures.

Join Rise to see the full answer
How do you stay updated on the latest cybersecurity trends and threats?

Emphasize your commitment to continuous learning in cybersecurity. Mention specific resources you follow, such as industry blogs, newsletters, webinars, or professional organizations. This shows your proactive approach in staying informed and prepared.

Join Rise to see the full answer
Can you describe your experience with cloud-native security?

Share your familiarity with cloud-native security practices such as Identity and Access Management (IAM), secure configuration, and network security. Provide examples of how you’ve applied these practices in your previous roles to enhance overall security in a cloud environment.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 11 days ago
Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Sopra Steria Remote 1 Rue Serpentines, 92400 Courbevoie, France
Posted 12 days ago
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Posted 6 days ago

Founded in 2014, Ledger is the global platform for digital assets and Web3. Over 15% of the world’s crypto assets are secured through Ledger Nanos. Headquartered in Paris and Vierzon, with offices in London, New York and Singapore, Ledger has a te...

26 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 3, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!