Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior DevSecOps Engineer image - Rise Careers
Job details

Senior DevSecOps Engineer

Full time - Remote

 

About Us

Parity is one of the world's most experienced core blockchain infrastructure companies, having built and pioneered some of the most advanced technologies in the blockchain sector. Parity was founded by Dr. Gavin Wood, co-founder and former CTO of Ethereum, the primary engineer behind the Ethereum Virtual Machine (EVM), inventor of the Solidity programming language, and primary author of the Ethereum Yellow Paper.

Based in Berlin, London, and Lisbon, Parity has built clients for Ethereum, Bitcoin, and Zcash and has pioneered a completely new, next-generation blockchain protocol with Polkadot and the framework it’s built with, Substrate. Parity builds the open-source technologies needed to power an unstoppable, decentralised web—known as Web3—and helps developers and organisations implement and build upon the Web3 tech stack.

People in Our Collective Are

  • Highly motivated to contribute to Parity’s mission and be part of something bigger

  • Excited to work on projects that are groundbreaking and complex

  • Autonomous workers that self-initiate, but also collaborate well with others

  • Taking maximum accountability and having minimum ego at work

  • Comfortable with chaos and adapting to the ever-changing Web3 space

Continuously educating themselves about Parity and the wider ecosystem

 

About the team:

The DevSecOps team is pivotal in helping infrastructure and Release management teams to secure our networks, operating systems, containers, pipelines and code. We are part of the Security team with a mission of reducing the impact of threats to Parity and its products, bolstering their resilience against potential cyber threats.

About the position:

This is a crucial role where your understanding of people, systems and security will allow you to advocate for and influence best practices in a diverse free thinking organisation while facilitating smooth development and implementation processes.  It is a unique opportunity to help secure an innovative organisation where feedback is direct and honest and understands that a check box approach doesn’t get results.

 

It involves :

  • Advising Infra Engineering and IT teams on security topics and supporting their work from the security standpoint — maintaining things practical using a risk-based approach with a focus on following areas

    • Automation of security controls, security hardening of the developer and IaC processes (building, testing, release), supply chain security (part of the build process), related metrics and monitoring/audits

    • Network, Vm & container image and  system hardening, Cloud issues and misconfigurations 

    • Endpoint Security, Infrastructure Identity and Access Management, SIEM, Threat intelligence, common misconfigs (DNS, email, networking, etc.)

  • Organising and performing penetration testing of our infrastructure, and collaborating with external parties on those tests.

  • Picking tools, methods and approaches to maintain and improve the security stance of the company. (And we have a strong preference towards FOSS tooling when possible)

  • Writing and enabling adoption of  company-wide security standards and guidelines, as well as implementing tools and automation to enable their deployment.

  • Mentoring other team members on all matters related to security and IT and infrastructure engineering.

About you:

You should be able to demonstrate : 

  • A focus on outcomes (rather than activities) and outcome based delivery

  • Ability  to partner with multiple teams in order to  (including but not only tackle issues, clarifying requirements, communicating and convincing stakeholders, etc..) 

  • Comfortable with a Linux-based tech stack (managed VMs, SSH, VPNs, firewalls,)

  • Experience with Kubernetes (incl. managed), Terraform, Ansible, Github, Gitlab,, ArgoCD, Image registries

  • Experience with various cloud platforms including, Google Cloud, non-managed providers

  • We’d love it if you had an understanding of blockchain tech and associated tooling (wallets, keys, RPC nodes and indexers etc.)

  • Ideally you'll live within 2 hours of UTC+0, but exceptional candidates outside of this timezone will also be considered.

 

About working for us:

  • Competitive remuneration packages based on iterative market research, including tokens (where legally possible)

  • “Future of work” environment that’s remote-first and self-initiating with flexible hours

  • Team mates that are genuinely excited about their impact and projects

  • Access to the brightest minds in this space to learn about Web3 and develop your skills and knowledge while on the job

  • Becoming part of the wider ecosystem (career and networking opportunities)

  • Team and company-wide retreats

  • Work laptop

 

Average salary estimate

$140000 / YEARLY (est.)
min
max
$120000K
$160000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior DevSecOps Engineer, Parity

Are you ready to take your career to the next level? At Parity, we're seeking a passionate and skilled Senior DevSecOps Engineer to join our dynamic, remote team! As one of the world's most experienced core blockchain infrastructure companies, founded by Dr. Gavin Wood, we are at the forefront of pioneering advanced technologies in the blockchain sector. This is more than just a job; it's a chance to be part of something groundbreaking and transformative! In this pivotal role, you'll collaborate closely with our infrastructure and release management teams, ensuring that our networks, operating systems, containers, and pipelines are secure against potential threats. You'll have the opportunity to influence best practices, advocate for security measures, and contribute to the overall resilience of Parity's innovative products. Your responsibilities will include advising IT teams, automating security controls, conducting penetration tests, and mentoring fellow team members. We're looking for someone who is focused on outcomes, comfortable working with a Linux-based tech stack, and experienced with Kubernetes, Terraform, and various cloud platforms. If you share our passion for decentralized technologies and are eager to continuously learn and adapt, then Parity is the perfect place for you to thrive. Join us in making an impact in the Web3 space and helping us build the future of decentralized infrastructure!

Frequently Asked Questions (FAQs) for Senior DevSecOps Engineer Role at Parity
What are the primary responsibilities of a Senior DevSecOps Engineer at Parity?

As a Senior DevSecOps Engineer at Parity, your primary responsibilities include advising the Infrastructure Engineering and IT teams on security matters, automating security controls, conducting penetration testing, and collaborating with external parties for testing. You'll focus on enhancing our security posture through practical, risk-based approaches while maintaining a keen understanding of our complex systems.

Join Rise to see the full answer
What qualifications are necessary for the Senior DevSecOps Engineer position at Parity?

To be considered for the Senior DevSecOps Engineer role at Parity, you should have a solid understanding of Linux-based tech stacks, experience with Kubernetes, Terraform, Ansible, and cloud platforms like Google Cloud. Additionally, familiarity with blockchain technology and security practices, along with strong communication and partnership abilities, will stand you in good stead.

Join Rise to see the full answer
What does the team culture look like for a Senior DevSecOps Engineer at Parity?

The culture at Parity for a Senior DevSecOps Engineer is highly collaborative and open-minded. We value autonomy, accountability, and a shared commitment to innovation within a fast-changing environment. Team members are encouraged to self-initiate, give honest feedback, and continuously learn about the evolving Web3 space, making it a thrilling place to work.

Join Rise to see the full answer
How does Parity support the professional development of its Senior DevSecOps Engineers?

Parity invests in the professional development of its Senior DevSecOps Engineers by providing access to leading minds in the Web3 sector, as well as opportunities for networking and learning. Team and company-wide retreats further promote growth and knowledge sharing, allowing you to expand your skill set while contributing to exciting projects.

Join Rise to see the full answer
What is the expected work location for a Senior DevSecOps Engineer at Parity?

This is a remote position for a Senior DevSecOps Engineer at Parity, offering flexible hours and a ‘Future of Work’ environment. While we prefer candidates to be within 2 hours of UTC+0, exceptional talents located outside this timeframe will also be considered, ensuring we find the best fit for our innovative team.

Join Rise to see the full answer
Common Interview Questions for Senior DevSecOps Engineer
Can you describe your experience with automating security controls?

When discussing your experience, focus on specific tools and processes you've implemented, such as using Terraform or Ansible for automation. Highlight how these efforts improved the security posture of previous projects and share any metrics that demonstrate your impact.

Join Rise to see the full answer
How do you approach collaboration with cross-functional teams at Parity?

Explain your philosophy on collaboration, emphasizing the importance of clear communication, active listening, and understanding the perspectives of other teams. Provide an example of how you've successfully partnered with engineers or IT teams to resolve security issues.

Join Rise to see the full answer
What strategies do you use to stay updated with the latest security threats?

Share the resources you rely on, such as blogs, forums, or continuous education courses. Discuss any relevant communities you participate in, such as security groups or blockchain forums, and provide an example of how staying informed has directly benefitted your work.

Join Rise to see the full answer
Describe a time when you identified and mitigated a significant security risk.

Share a specific instance where you used your skills to pinpoint a security vulnerability. Explain the steps you took to address the risk, the stakeholders involved, and the positive outcome that resulted from your actions.

Join Rise to see the full answer
What tools and technologies do you prefer for penetration testing?

Discuss the penetration testing tools you're most familiar with, such as Metasploit, Burp Suite, or any custom scripts you've developed. Detail your methodology for conducting tests and how you analyze the results to enhance security practices.

Join Rise to see the full answer
How would you explain a complex security concept to a non-technical team member?

Make sure to emphasize the importance of knowing your audience. Describe how you would use analogies and simplify jargon to convey the core message. Providing examples of past experiences where you've successfully explained complex concepts helps reinforce your communication skills.

Join Rise to see the full answer
What steps do you take to ensure compliance with security standards?

Outline your approach to compliance, including the frameworks you are familiar with (e.g., ISO 27001, NIST). Discuss how you integrate compliance checks into daily processes and how you communicate requirements to the entire team to ensure adherence.

Join Rise to see the full answer
Can you discuss your experience with cloud security and misconfigurations?

Focus on specific cloud platforms you've worked with and the security practices you've implemented, including IAM policies, VPC configurations, and monitoring setups. Share examples where you identified and rectified common misconfigurations.

Join Rise to see the full answer
What is your experience working with security hardening in a DevOps pipeline?

Discuss the practices you've implemented to secure CI/CD pipelines, such as integrating security testing tools into the pipeline, code reviews, and automated security scans. Share how these efforts intersect with development practices and lead to safer deployments.

Join Rise to see the full answer
How do you measure the effectiveness of your security initiatives?

Describe the key performance indicators (KPIs) you utilize to assess the success of security initiatives. Mention metrics like reduction in vulnerabilities, time to remediation, or employee training completion rates as tangible examples of effective security practices.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
Posted 2 days ago
Fortune Brands Hybrid 1750 Indian Wood Cir, Maumee, OH 43537, USA
Posted 7 days ago
Photo of the Rise User
College Track Hybrid Denver, Colorado
Posted 6 days ago
Photo of the Rise User
Posted 8 days ago
Photo of the Rise User
Veolia Environnement SA Hybrid 461 From Rd, Paramus, NJ 07652, USA
Posted 2 days ago
Photo of the Rise User
PosiGen Remote Remote - UT, LA, PA, TX, NY
Posted 21 hours ago
Photo of the Rise User
G-P Remote Ireland (Remote-First)
Posted 8 days ago

Parity Technologies is a core blockchain infrastructure company. It is creating an open-source creative commons that will enable people to create better institutions through technology. This started with work building Ethereum. Today, Parity is fo...

12 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
January 10, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!