About the job
Join Brale as a Senior Security Engineer and become an integral part of our dedicated security engineering team. Your role will be pivotal in enhancing our existing security frameworks while leveraging your extensive industry experience to pinpoint and fortify vulnerabilities across our applications, systems, and processes.
Your passion for threat modeling, security protocol design, and vulnerability discovery in software systems will drive you to collaborate closely with our team to document and address known risks. By staying informed about the latest security trends and threats, you will continuously improve the organization's security posture.
With your background in cryptography and secure coding practices, you will help Brale safeguard both on-chain and off-chain assets by architecting systems that utilize multi-party authorization and adhere to robust processes. Experience with blockchain technologies is a plus!
Working in a dynamic startup environment, you will undertake various responsibilities, including:
- Maintaining threat models and other security-related documentation.
- Coordinating penetration testing efforts with external teams and managing the resolution of identified issues.
- Conducting white-box security assessments of critical features.
- Engaging in the design process for application features and AWS infrastructure by establishing security requirements and reviewing designs to ensure compliance with best practices.
- Assisting in the design and implementation of controls for regulatory compliance.
- Defining internal best practices for secure development and data management, including key material handling.
- Identifying SIEM tooling needs and helping select appropriate solutions based on our scale and budget.
- Maintaining the security incident response plan and leading response efforts during security incidents.
- Understanding the threat landscape and establishing monitoring for endpoints and application systems.
- Sharing knowledge with other engineering roles to enhance collective understanding of security issues.

