Product Security Engineer - Vulnerability Management at Chainalysis - Apr 24

< Back to results

Product Security Engineer - Vulnerability Management


Chainalysis Jobs · Spain - Remote · Engineering & Modelling
Chainalysis logo
This job post has now expired. Please see the other Chainalysis jobs available.
Job Overview

Chainalysis is seeking a dynamic and passionate Product Security Engineer with 2-4 years of experience in application, cloud, or infrastructure security to join our cutting-edge team. As a trailblazer in blockchain forensics, we require a candidate who has a strong understanding of cloud security best practices, application security principles, and excels at communicating and collaborating with various stakeholders within the organization. A background in software development is a valuable addition. In this crucial role, you will be responsible for identifying and managing vulnerabilities within our organization's product portfolio across cloud and application environments, ensuring the security and integrity of our innovative solutions in the blockchain industry. Through effective vulnerability management, you will contribute to the ongoing protection and advancement of our cutting-edge products and services.

Key Responsibilities:

  • Proactively identify, assess, and prioritize security vulnerabilities in our cloud and application environments, and manage them through the remediation process
  • Manage and optimize vulnerability management tools such as Tenable, Lacework, and JFrog, ensuring their effective use and alignment with the organization's security requirements and best practices
  • Develop and maintain meaningful security metrics for vulnerability management tools such as Tenable, Lacework, and JFrog, to evaluate their effectiveness and alignment with the organization's security requirements and best practices
  • Perform container image scanning to identify and remediate vulnerabilities in containerized applications, ensuring that only secure images are deployed within the environment.
  • Conduct instance OS scanning to detect and address vulnerabilities in operating systems running on virtual machines or cloud instances, maintaining the security and compliance of the infrastructure.
  • Establish and maintain container image and instance OS scanning policies and procedures, ensuring that scanning and remediation activities are aligned with the organization's security requirements and best practices.
  • Collaborate with development, operations, and security teams to integrate container image and instance OS scanning into CI/CD pipelines, promoting a proactive approach to vulnerability management.
  • Continuously monitor and report on the effectiveness of container image and instance OS scanning efforts, providing actionable insights and recommendations for improvement.
  • Provide support to internal users of security tools and promptly respond to Jira tickets assigned to the security team, ensuring effective collaboration and addressing security-related concerns across the organization

A background like this helps:

  • Experience with vulnerability management tools such as Tenable, Lacework, and JFrog
  • Experience with AWS cloud security best practices
  • Experience with Containers and Kubernetes in AWS
  • Experience with Patch Management and Configuration Management Tools, including AWS SSM or Ansible.
  • Experience with Bash and/or Python Scripting to automate various tasks, include patch management, repetitive tasks, data collection, security audits and compliance checks
  • Experience with Linux operating systems, including the ability to understand and analyze system components such as patches, libraries, and configurations to identify and remediate vulnerabilities.
  • Familiarity with Linux package management systems (e.g., apt, yum, etc) to effectively manage software updates, patches, and dependencies for maintaining secure and up-to-date systems.
  • Experience with container scanning using JFrog Xray, with the ability to configure and manage policies, integrations, and security rules for effective vulnerability detection and remediation in container images.
  • Experience with JFrog Artifactory and its integration with JFrog Xray for comprehensive artifact management and security scanning in a unified platform.

More Jobs at Chainalysis


Chainalysis Overview

Chainalysis provides global law enforcement agencies, regulators, and businesses with cryptocurrency investigation and compliance solutions to help them collaborate and combat illegal cryptocurrency activities. With the support of prominent venture capital firms such as Benchmark, Chainalysis creates confidence in blockchains.

Website Twitter LinkedIn Job Archive

Chainalysis Jobs by Location

Check below to see all of the open Chainalysis jobs organised by office location.

Chainalysis Jobs by Team

Check below to see all of the open Chainalysis jobs organised by team.

Latest Crypto Blog Posts

From Blockchain To Bureaucracy: Web3 Vs Civil Service Jobs


In recent years, the job market in the UK has seen a significant evolution with the emergence of Web3 jobs alongside traditional roles in the Civil Se...

Posted by Jane Lepson · 4th November 2023 12:53 PM

The Role Of Cryptocurrency In Decentralized Digital Identity Solutions


Cryptocurrency, often associated with financial transactions and investments, has an important role to play in the development of decentralized digita...

Posted by Jackson Matlock · 2nd August 2023 12:14 PM

The Impact Of Cryptocurrencies On The Aerospace And Defense Industry: A New Era Of Innovation


Cryptocurrencies have been a game changer for the financial industry, but their impact is now being felt in other sectors as well. One such sector is ...

Posted by Jackson Matlock · 2nd August 2023 05:38 AM

Understanding Cryptocurrency Trading Regulations: Compliance And Legal Considerations


Cryptocurrency trading has become increasingly popular over the years, but it has also come under increased scrutiny from regulators and lawmakers. Un...

Posted by Sean Lakers · 1st August 2023 11:31 AM

Cryptocurrency And The Medical Industry: A New Era Of Patient Care And Innovation


Cryptocurrency and blockchain technology have been making waves in the finance industry for some time now, but their potential applications outside of...

Posted by Tommy Layton · 31st July 2023 01:38 AM

The Role Of Cryptocurrency In Decentralized Finance (DeFi) Derivatives Markets


Decentralized finance (DeFi) is an emerging sector in the cryptocurrency industry that is rapidly gaining traction. DeFi aims to provide an alternativ...

Posted by Tommy Layton · 30th July 2023 11:38 AM

The Impact Of Cryptocurrencies On The Media And Entertainment Industry: A New Era Of Creativity


The Rise of Cryptocurrencies in the Media and Entertainment Industry The rise of cryptocurrencies has not only revolutionized the financial industry ...

Posted by Ramon Cretlin · 30th July 2023 04:40 AM

Understanding Cryptocurrency Trading Platforms: From Centralized To Decentralized Exchanges


Cryptocurrency trading platforms have revolutionized the way we buy, sell, and exchange digital currencies. These platforms come in different forms, i...

Posted by Jane Lepson · 30th July 2023 07:26 AM

Cryptocurrency And The Consumer Goods Industry: A New Era Of Retail And Manufacturing


The consumer goods industry is on the verge of a major transformation, thanks to the rise of cryptocurrency. With blockchain technology enabling secur...

Posted by Ramon Cretlin · 27th July 2023 11:40 AM

The Role Of Cryptocurrency In Decentralized Intellectual Property Solutions


As the world becomes more digitized, intellectual property protection has become a more complex task. Intellectual property, including patents, tradem...

Posted by Jackson Matlock · 27th July 2023 12:14 PM