Senior Product Security Engineer at Finoa
10405 Berlin, Prenzlauer Berg, Germany -
Full Time


Start Date

Immediate

Expiry Date

08 May, 25

Salary

0.0

Posted On

09 Feb, 25

Experience

0 year(s) or above

Remote Job

No

Telecommute

No

Sponsor Visa

No

Skills

Good communication skills

Industry

Information Technology/IT

Description

YOUR MISSION

We are looking for a Senior Product Security Engineer to enhance our security posture by integrating advanced security tools, implementing Zero-Trust principles, and proactively identifying and mitigating vulnerabilities. This role will play a critical part in ensuring compliance with industry security standards while fostering a culture of security best practices across development and operations.

ABOUT US

Finoa is a regulated crypto asset platform for institutional investors co-founded in 2018 by Christopher May and Henrik Gebbing. The company came to life through the shared aspiration to make institutional interactions with crypto assets simple and secure, and is backed by prominent investors, including Balderton Capital, Coparion, Maven11, Signature Ventures, and Venture Stars.
Finoa has since then grown into a truly international company, powered by a diverse team and serving high-profile clients from around the world. Reference clients include renowned venture capital firms, crypto hedge funds, corporates, Web3 companies, and high-net-worth individuals.
If you want to join one of Europe’s most exciting crypto start-ups, be part of the next wave of innovation disrupting finance, and grow together with us, then this is your chance to apply.
Finoa is an equal opportunity employer devoted to diversity and inclusion in the workplace. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, or disability status.

Responsibilities
  • Integrate SCA, SAST, and DAST tools into CI/CD pipelines to ensure secure software development.
  • Implement Zero-Trust security principles across infrastructure, ensuring robust access controls and identity management.
  • Design and deploy secure and scalable secrets management solutions to protect sensitive data.
  • Develop comprehensive threat models for all services, identifying and mitigating potential risks.
  • Conduct frequent penetration testing of internal applications and services to identify vulnerabilities proactively.
  • Establish unified vulnerability management pipelines, integrating and standardizing security data from multiple sources.
  • Ensure compliance with industry security standards, including SOC 2, ISO 27001, and NIST frameworks.
  • Collaborate with development and operations teams to advocate for security best practices and secure coding principles.
  • Automate security-related tasks, leveraging scripting and security orchestration techniques.
  • Research and implement emerging security technologies, particularly in blockchain and cryptographic security.
Loading...