Talent.com
Decentralized Masters
DevOps Security EngineerDecentralized Masters • Barcelona, Catalonia, ES
DevOps Security Engineer

DevOps Security Engineer

Decentralized Masters • Barcelona, Catalonia, ES
Hace más de 30 días
Tipo de contrato
  • Teletrabajo
  • Quick Apply
Descripción del trabajo

About Legacy

Legacy is an easy-to-use, non-custodial Web3 wallet designed to protect digital assets through beneficiary protection and seamless DeFi access. Users can swap across chains, earn yield in one click, and safeguard wealth for the next generation.

Legacy is built by the team behind Decentralized Masters - a profitable $50M+ education and investment ecosystem with 4,000+ high-net-worth investors.

We’ve launched. Demand is strong. Now we need someone to own the post-acquisition customer journey and turn users into long-term, high-LTV subscribers.

About the Software Division

We are building a portfolio of software products inside the Decentralized Masters ecosystem, including:

  • Legacy Wallet – a non-custodial Web3 wallet with beneficiary protection and seamless DeFi access
  • Trading Bot – automated crypto execution tools for serious investors
  • Future fintech and investor infrastructure tools

We are now building the retention and lifecycle engine that will power long-term recurring revenue across all products.

About the Role

You will be the single person responsible for the security of a platform that tracks hundreds of millions in digital assets. That is the job. Everything else is secondary.

We need someone who breaks things for a living. Someone who looks at a login page and sees six attack vectors. Someone who reads a pull request and catches the injection vulnerability that two senior developers missed. Someone who lies awake thinking about the phishing campaign that hasn't been invented yet. If that sounds exhausting, this is not your role. If that sounds like Tuesday, keep reading.

Your primary responsibilities are security and quality assurance. You own penetration testing, vulnerability assessments, threat modeling, automated test frameworks, and CI quality gates across every product we ship. You also own infrastructure: AWS, CI/CD pipelines, monitoring, and incident response. And because we are a small, senior team, you will write production code when security and QA responsibilities are covered. You are not a consultant or a checkbox auditor. You are an engineer who ships, and whose code happens to make everything else harder to break.

The ideal candidate has spent time at major product-driven fintech and crypto companies where a single security failure can destroy user trust overnight.

What You Will Own

Security (Primary)

  • Own the security posture across all products: Legacy, Trading Bot, and future platforms. If something gets breached, it is your problem. If nothing gets breached, it is because of your work.
  • Conduct regular penetration testing, vulnerability assessments, and threat modeling aligned with OWASP standards and methodologies
  • Ensure full coverage of the OWASP Top 10 in application security testing, code reviews, and deployment checks
  • Perform security-focused code reviews across frontend, backend, and infrastructure code, catching what standard code reviews miss
  • Implement and manage secrets management (Vault, AWS Secrets Manager, or KMS), access controls, and least-privilege policies
  • Build and maintain incident response playbooks. When something breaks, you lead the response, run the post-mortem, and ship the fix
  • Stay ahead of Web3 and crypto-specific attack vectors: phishing campaigns, wallet exploits, API key compromises, supply chain attacks, and social engineering
  • Manage and coordinate external security audits and penetration tests from third-party firms

Quality Assurance & Testing (Primary)

  • Design and implement test strategies across all products: unit tests, integration tests, end-to-end tests, API tests, and regression suites
  • Build and maintain automated testing frameworks and CI quality gates that prevent broken code from reaching production
  • Define and track quality metrics: test coverage, flakiness rate, regression detection latency, and bug escape rate
  • Write and execute security test cases: authentication flows, authorization controls, input validation, API abuse scenarios, and edge cases around financial data
  • Perform both white-box and black-box testing, leveraging full codebase access to catch issues that surface-level QA would miss
  • Test across the full stack: frontend UI, backend APIs, database queries, third-party integrations, and on-chain interactions

Infrastructure & DevOps (Foundation)

  • Maintain and improve cloud infrastructure on AWS using Infrastructure as Code (Terraform or CloudFormation)
  • Own CI/CD pipelines (GitHub Actions preferred): automated testing, security scanning, linting, and deployment
  • Harden infrastructure: network security, IAM policies, container security, and environment isolation
  • Build logging, monitoring, and alerting across all services (CloudWatch, Prometheus, Grafana, or equivalent)
  • Ensure audit trails for user actions, system changes, and access events
  • Manage production reliability, incident response, and cost optimization

Fullstack Development (When the fortress is secure)

  • Contribute production code across frontend and backend, bringing a security-first mindset to every feature you build
  • Build features, fix bugs, and ship improvements alongside the engineering team
  • Every line you write should make the product better and harder to break: input validation, error handling, authentication, and data protection by default
  • Participate in architecture discussions and code reviews, advocating for testability, reliability, and security in every decision

Requirements

What You Bring

Required

  • 5+ years in software engineering roles with meaningful, hands-on security and QA experience. We will verify this. If your security experience is theoretical, this is not the right fit.
  • Fullstack development experience: you can build and ship features across frontend (React or equivalent) and backend (Node.js, Python, Go, or equivalent)
  • Hands-on penetration testing and vulnerability assessment experience across web applications, APIs, and cloud infrastructure
  • Strong working knowledge of OWASP standards, including the OWASP Top 10, OWASP Testing Guide, and OWASP secure coding practices
  • Experience building automated test frameworks and integrating testing into CI/CD pipelines
  • AWS expertise (EC2, ECS/EKS, Lambda, VPC, IAM, S3, RDS, CloudFront, WAF)
  • Infrastructure as Code experience (Terraform, CloudFormation, or Pulumi)
  • Container technologies: Docker and Kubernetes in production environments
  • Scripting and automation proficiency in Bash and Python
  • Experience with secrets management tools (HashiCorp Vault, AWS Secrets Manager, or similar)
  • Familiarity with security and testing tools (Burp Suite, OWASP ZAP, Selenium, Cypress, Jest, Postman, or equivalent)
  • Strong communication skills: you can explain security risks and quality tradeoffs clearly to non-technical stakeholders

Nice-to-Have

  • Security certifications: OSCP, CISSP, CompTIA Security+, AWS Security Specialty, or equivalent
  • Experience at a crypto, DeFi, Web3, or fintech product company (Coinbase, Phantom, Stripe, Casa, MetaMask, Zerion, Ramp, or similar)
  • Familiarity with Web3-specific security concerns: wallet security, key management, on-chain monitoring, phishing mitigation
  • SDET background or experience in a hybrid development-and-testing role
  • Experience testing financial systems: payment flows, ledger integrity, double-spend prevention, or transaction monitoring
  • Experience implementing zero-trust architectures
  • Bug bounty participation, CVE publications, or contributions to open-source security tooling

Benefits

What We Offer

  • Competitive salary + performance-based incentives tied to retention & LTV improvement
  • Direct exposure to founders
  • Team Offsites
  • Remote work
  • High ownership, high-impact role
Crear una alerta de empleo para esta búsqueda

DevOps Security Engineer • Barcelona, Catalonia, ES

Ofertas similares

Firmware Security Engineer

Ascendionbarcelona, catalunya, es

Hybrid work model: 3 days onsite in office is required.We are looking for an experienced.You will work on embedded Linux systems, implementing secure communication, authentication, and network prot... Mostrar más

 • Oferta promocionada

FULLREMOTE- SIEM Engineer (Cloud & Security Operations) - Capitole

Capitolebarcelona, catalunya, es

Capitole is one of the best IT consulting companies and the place you want to be.We believe in a different model, more human, with the employee in the center of our company.Happiness and low turnov... Mostrar más

 • Oferta promocionada

AWS Security Engineer

RealnautBarcelona, cataluña, Spain

AWS Security Engineer especializado en Palo Alto Networks.La persona seleccionada será responsable del diseño, implementación y operación de soluciones de seguridad en AWS, con un enfoque avanzado ... Mostrar más

 • Oferta promocionada

AWS Network Security Engineer - IOON

IOONbarcelona, catalunya, es

En Ioon estamos convencidos de que la tecnología será el eje de la transformación de nuestras vidas,.Te animas a ser parte de esta revolución?.Te proponemos esta posición por si te quieres sumar a ... Mostrar más

 • Oferta promocionada

Cybersecurity Infrastructure Engineer 100% on-site

Thales Cybersecurity Services – Spain/Portugalparets del vallés, catalunya, es

CheckPoint, PaloAlto, and Fortinet.Operation and administration of equipment and environments within the scope (backups, log management, health monitoring, etc.Management of requests and incidents ... Mostrar más

 • Oferta promocionada

DevOps Engineer (AWS)

Capitolebarcelona, catalunya, es

Capitole is celebrating 10 years!.People First: trust, respect, and professional development.Employee turnover rate of just 13%, well below the industry average.Cutting-edge projects with global cl... Mostrar más

 • Oferta promocionada

Firmware Security Engineer - Ascendion

Ascendionbarcelona, catalunya, es

Hybrid work model: 3 days onsite in office is required.We are looking for an experienced.You will work on embedded Linux systems, implementing secure communication, authentication, and network prot... Mostrar más

 • Oferta promocionada

Service Delivery Lead - DevOps / Security

SOTEC CONSULTINGBarcelona, barcelonés (comarca); provincia de barcelona; cataluña, Spain

At SOTEC Consulting – Astek Group, we are looking for a Service Delivery Lead to join an international environment, working with global stakeholders and leading service delivery for critical system... Mostrar más

 • Oferta promocionada

Security Engineer - K2 Partnering Solutions

K2 Partnering Solutionsbarcelona, catalunya, es

Role: Software engineer / security engineer.Location: hybrid in Barcelona (8 days per month on site).Language: English and Spanish fluent.Develop secure cloud-native services focused on KMS, encryp... Mostrar más

 • Oferta promocionada

DevOps Engineer - Network and Security

ExtiaBarcelona, barcelonés (comarca); provincia de barcelona; cataluña, Spain

Senior DevOps Engineer (Azure Expert) - Barcelona (híbrido)¿Eres un experto en el ecosistema de Microsoft Azure con pasión por la automatización y la infraestructura como código? ¡Únete a Exti... Mostrar más

 • Oferta promocionada

Azure DevOps Engineer

Catch Resource ManagementBarcelona, cataluña, Spain

Azure, Microsoft Entra ID, Azure DevOps, Terraform, Bicep, Infrastructure as Code (IaC), Azure Governance, RBAC, MFA, Azure Networking, VNets, Key Vault, Defender for Cloud, Azure Policy, Logging &... Mostrar más

 • Oferta promocionada

AWS Network Security Engineer

IOONbarcelona, catalunya, es

En Ioon estamos convencidos de que la tecnología será el eje de la transformación de nuestras vidas,.Te animas a ser parte de esta revolución?.Te proponemos esta posición por si te quieres sumar a ... Mostrar más

 • Oferta promocionada

WAF & Cloud Security Engineer | Product Security

Clarivatebarcelona, cataluña, España

A global information services firm in Barcelona is seeking a Cyber Security Engineer to enhance web application security.The role involves managing Web Application Firewalls and collaborating with ... Mostrar más

 • Oferta promocionada

Security Engineer

K2 Partnering SolutionsPlaza Catalunya, cataluña, Spain

Role: Software engineer / security engineer.Location: hybrid in Barcelona (8 days per month on site).Language: English and Spanish fluent.Tiene su CV preparado? Si es así y confía en que este es el... Mostrar más

 • Oferta promocionada

DevOps Engineer - Network and Security Startup

ExtiaBarcelona, barcelonés (comarca); provincia de barcelona; cataluña, Spain

Senior DevOps Engineer (Azure Expert) - Barcelona (híbrido)¿Eres un experto en el ecosistema de Microsoft Azure con pasión por la automatización y la infraestructura como código? ¡Únete a Exti... Mostrar más

 • Oferta promocionada

Software Security Specialist (DevSecOps / SAST)

Omega CRM, A Merkle CompanyBarcelona, Barcelonés (comarca); Provincia de Barcelona; Cataluña, ES

Omega CRM Consulting is looking for a CISOC Application Security Engineer that would like to collaborate with one of the top global pharmaceutical companies.As member of Cyber Intelligence & Securi... Mostrar más

 • Oferta promocionada

WAF Cyber Security Engineer

Clarivatebarcelona, cataluña, España

This position will focus on managing and enhancing Web Application Firewalls (WAFs) and strengthening Product Security.The ideal candidate will bring hands‑on experience with security technologies,... Mostrar más

 • Oferta promocionada

Cloud Security Operations Engineer - Giesecke+Devrient

Giesecke+Devrientbarcelona, catalunya, es

Giesecke+Devrient is a global company that offers security technologies, both in the physical and digital world.Every day, billions of people benefit from G+D innovations in their personal and busi... Mostrar más

 • Oferta promocionada

Senior Security Platform Engineer (DevOps & SIEM)

ING Hubs Spainbarcelona, catalunya, es

At ING Hubs Spain we are looking for a Senior Cybersecurity Platform Engineer.We are looking for a talented and enthusiastic.Cybersecurity Platform Engineer.As a Cybersecurity Platform Engineer, yo... Mostrar más

 • Oferta promocionada

DevOps Engineer

Rezolve Aibarcelona, catalunya, es

Identity and access management, AWS/Google cloud space account creation and deletion of account, creation and Deletion of IAM Users for managed/unmanaged accounts.Telco Infrastructure provisioning,... Mostrar más