Hexens
Posted 3mo ago

Senior Information Security Engineer- Application Security Focus

Hexens
United Kingdom
RemoteFull Time
Responsibilities
  • planning assessments
  • collaborating researchers
  • identifying vulnerabilities
Requirements
  • 5+ years offensive security, focus on application security
  • Expert webApp/API security
  • Mobile/browser/desktop apps
  • Proficient in Golang, Rust, TS/JS, Python, Java, or C
  • Cloud/CI/CD/container/network security
  • Readiness to learn web3
  • Scripting
  • Scoping
  • Client-facing skills
Technical tools mentioned
GolangRustTypeScriptJavaScriptPythonJavaCBurp SuiteWeb3

Job description

Hexens.io is looking for a Senior Information Security Engineer  with a strong focus on application security to join our team. At Hexens.io, we deliver cutting-edge cybersecurity services with a core emphasis on blockchain technology. We address complex security challenges, protecting applications and infrastructures that handle multimillion-dollar digital assets.


Remote Availability: Work from anywhere! This is a fully remote role with no location restrictions.


Responsibilities:

  • Alongside our off-chain security lead, plan and deliver advanced application security assessments against API services, application front-ends, wallet software, browser plugins, mobile apps, and SDKs.
  • Collaborate with leading smart contract auditors and cryptography researchers, leveraging your application security expertise to assess attack surfaces outside their on-chain specializations.
  • Work to identify technical vulnerabilities, architectural flaws, and ways to mitigate future risk in the crucial junctions between off-chain and on-chain systems.
  • Interact with developers and key stakeholders when identifying and handling security issues.
  • Deliver clear and concise reporting on issues and attack paths identified.

Required skillset:

  • At least 5 years experience, or equivalent technical expertise, delivering offensive security services, with a primary focus on application security.
  • Expert-level web application and API security experience, with proficiency assessing apps with modern web frameworks, and identifying advanced client-side, back-end, and business logic attacks.
  • Experience assessing mobile applications (Android/iOS), browser extensions, and desktop applications.
  • Practical experience finding complex vulnerabilities and attack paths in Golang, Rust, TS/JS, Python, Java, or C-based codebases during white/grey-box appsec assessments.
  • Working knowledge of cloud, CI/CD, container, CDN, and network security concepts, and how they apply to application security.
  • Knowledge or willingness to learn web3 security concepts and how they apply to web3-centric applications.
  • Decent scripting and automation skills.
  • Assisting with scoping requirements for application security work.
  • Strong client-facing and soft skills.

Big plus if any of the following apply:

  • Significant web2 bug bounty/vulnerability disclosure history.
  • Prior experience as a smart contract auditor or onchain-focused security researcher.
  • Prior experience developing or integrating DeFi protocols, smart contracts, wallet services, or other web3 services.
  • Advanced relevant security certifications (OSWE, Burp Suite Certified Professional, etc.)

Benefits:

  • Work alongside industry-leading specialists
  • Opportunity to work with the most exciting and prominent companies in the industry
  • Highly competitive salary
  • Great work environment


About Hexens

Provides cybersecurity audits and products for blockchain projects.

Year founded
2021
Employees
51
Organization type
Private
Latest investment
Raised $4.20M Seed (2022) — led by IOSG Ventures
Headquarters
GB

Similar jobs

Information Security Engineer roles
1d
Save
Mark Applied
Hide
Information Security Engineer - Classified Systems (3461)
Europe or United Kingdom
OnsiteFull Time
Lockheed Martin
Lockheed MartinNYSE: LMT: Designs and manufactures advanced aerospace, defense, and security systems.
Experience securing classified or regulated IT environments, with expertise in security architecture, risk assessment, accreditation, ATO approvals, system hardening, and enterprise infrastructure. CISSP/CISM and a relevant degree required or preferred.
Microsoft Windows Server, Linux, AWS, IaaS, PaaS, SIEM, NIST, GDPR
5d
Save
Mark Applied
Hide
Information Security Engineer (CISO track)
London, England, United Kingdom
RemoteFull Time
Tangible
Tangible: Technology platform enabling liquidity for private market investments.
5+ YOERequires 5+ years in security engineering or security-focused infrastructure, AWS security expertise, Python and Terraform, SOC 2 experience, privacy knowledge, clear writing, and executive leadership potential.
AWS, Terraform, Python, GuardDuty, Security Hub, CloudTrail, SOC 2, LLM, SSO, SCIM, SFTP, APIs
2w
Save
Mark Applied
Hide
Senior Staff Information Security Engineer
Canada or Bristol
$175k-$195k/yr HybridFull Time
NMI
NMI: Provides an embedded payments platform for software and fintech partners.
Extensive security engineering experience securing AWS and on-premises infrastructure, strong networking and identity knowledge, infrastructure-as-code and CI/CD security experience, scripting with Python or Go, and experience leading cross-team security initiatives.
AWS, Python, Go, Kubernetes, CNAPP, CSPM, SIEM, EDR, DLP, WAF
3w
Save
Mark Applied
Hide
Principal Information Security Engineer
Manchester or London
HybridFull Time
AJ Bell
AJ BellLondon Stock Exchange: AJB: Provides online investment platforms and retail stockbroker services.
5+ YOE5+ years information security experience (financial services preferred), hands-on with Microsoft security stack, cloud and firewall security, SIEM, PAM, IGA, ISO27001 experience, automation/scripting, working towards or attained CISSP.
Microsoft security stack, Windows, MacOS, Linux, SIEM, PAM, IGA, firewalls
4w
Save
Mark Applied
Hide
Information Security Engineer
London or Manchester
OnsiteFull Time
Freshfields
Freshfields: Providing international legal services to global corporations and governments.
Hands-on experience with Azure, M365 and GCP, SIEM and vulnerability management, cyber incident response, IAM and Conditional Access, Terraform/IaC, and broad IT engineering knowledge.
Azure, M365, Google Cloud Platforms (GCP), SIEM, Microsoft Defender, Terraform, EDR, IdP, Windows Server, macOS, Linux
1mo
Save
Mark Applied
Hide
Information Security Engineer
Profondeville or London
€65k-€110k/yr OnsiteFull Time
Fortegra
Fortegra: Provides specialty insurance underwriting and consumer warranty solutions.
4+ YOE4+ years in information security or security engineering; hands-on cloud, vulnerability management, CI/CD security, incident response, and AI/LLM security experience; bachelor’s degree or equivalent experience preferred.
MITRE ATT&CK, OWASP LLM Top 10, NIST AI Risk Management Framework, SIEM, EDR/XDR, SOAR, WAF, CSPM, CNAPP, DLP, SAST, DAST, SCA, secret scanning, IaC scanning, SBOM, Python, PowerShell, Bash, Go
1mo
Save
Mark Applied
Hide
Information Security Engineer
United Kingdom or London
£66k-£92k/yr RemoteFull Time
Algolia
Algolia: AI-powered search and discovery platform for websites and apps.
3+ YOE3–6 years in information security engineering, scripting (Python/Bash/Go), cloud security (AWS/GCP/Azure), SIEM/EDR/SAST/SOAR experience, incident response and strong communication skills.
Python, Bash, Go, Kubernetes, AWS, GCP, Azure, SIEM, EDR, SAST, SOAR, CTI, Crowdstrike, Obsidian, HashiCorp Vault
1mo
Save
Mark Applied
Hide
Information Security Engineer - Vulnerability Management
Southampton, England, United Kingdom
HybridFull Time
Starling
Starling: Digital bank providing personal and business current accounts.
Strong engineering and automation background for vulnerability management, cloud and container security (AWS/GCP, Kubernetes), infrastructure-as-code (terraform), programming (Java/Golang/Python/SQL), API integrations, and strong communication skills.
AWS, GCP, Kubernetes, terraform, Java, Golang, Python, SQL, Slack, MacBook, CIS Benchmarks