Full time - Remote
About Us
Parity is one of the world's most experienced core blockchain infrastructure companies, having built and pioneered some of the most advanced technologies in the blockchain sector. Parity was founded by Dr. Gavin Wood, co-founder and former CTO of Ethereum, the primary engineer behind the Ethereum Virtual Machine (EVM), inventor of the Solidity programming language, and primary author of the Ethereum Yellow Paper.
Based in Berlin, London, and Lisbon, Parity has built clients for Ethereum, Bitcoin, and Zcash and has pioneered a completely new, next-generation blockchain protocol with Polkadot and the framework it’s built with, Substrate. Parity builds the open-source technologies needed to power an unstoppable, decentralised web—known as Web3—and helps developers and organisations implement and build upon the Web3 tech stack.
Continuously educating themselves about Parity and the wider ecosystem
The DevSecOps team is pivotal in helping infrastructure and Release management teams to secure our networks, operating systems, containers, pipelines and code. We are part of the Security team with a mission of reducing the impact of threats to Parity and its products, bolstering their resilience against potential cyber threats.
This is a crucial role where your understanding of people, systems and security will allow you to advocate for and influence best practices in a diverse free thinking organisation while facilitating smooth development and implementation processes. It is a unique opportunity to help secure an innovative organisation where feedback is direct and honest and understands that a check box approach doesn’t get results.
It involves :
Advising Infra Engineering and IT teams on security topics and supporting their work from the security standpoint — maintaining things practical using a risk-based approach with a focus on following areas
Automation of security controls, security hardening of the developer and IaC processes (building, testing, release), supply chain security (part of the build process), related metrics and monitoring/audits
Network, Vm & container image and system hardening, Cloud issues and misconfigurations
Endpoint Security, Infrastructure Identity and Access Management, SIEM, Threat intelligence, common misconfigs (DNS, email, networking, etc.)
Organising and performing penetration testing of our infrastructure, and collaborating with external parties on those tests.
Picking tools, methods and approaches to maintain and improve the security stance of the company. (And we have a strong preference towards FOSS tooling when possible)
Writing and enabling adoption of company-wide security standards and guidelines, as well as implementing tools and automation to enable their deployment.
Mentoring other team members on all matters related to security and IT and infrastructure engineering.
You should be able to demonstrate :
We believe people do their best work when they’re driven by their own curiosity and interest. We align people with the projects they’re passionate about.
Flexible schedule and location. Work from home or bring your dog to the office. Most communication is done asynchronously through GitHub and chat.