Security Specialist
Role details
Job location
Tech stack
Job description
While our growth has been remarkable, we take even greater pride in the success of our clients. To date, we have empowered over 4000 investors to break into the DeFi world. At Decentralized Masters, we don't just offer education; we cultivate a powerhouse of knowledge combined with an engaging community, innovative technology, and a team of leading DeFi and blockchain experts. Our commitment is to deliver unparalleled resources designed for long-term success in the world of DeFi and Web3, ensuring our members not only safeguard but also enhance their financial future., We are seeking a Security Specialist to develop, maintain, and continuously improve the security infrastructure across Decentralized Masters and our new SaaS venture. This role focuses on operational security, data protection, risk prevention, and proactive threat mitigation.
You'll work cross-functionally with engineering, data protection, compliance, operations, and product teams to ensure the confidentiality, integrity, and availability of our systems, data, and customer assets.
This is a hands-on role, ideal for someone who thrives in a fast-moving, high-ownership environment., Operational & Technical Security
- Monitor, analyze, and respond to security events across systems, cloud environments, applications, and internal tools.
- Implement and manage SIEM, IDS/IPS, endpoint protection, vulnerability scanners, and logging infrastructure.
- Conduct regular vulnerability assessments and coordinate remediation with engineering teams.
- Oversee secure configuration baselines for infrastructure, servers, cloud accounts, and internal systems.
- Implement and enforce Data Loss Prevention (DLP) policies, tools, and controls to prevent unauthorized data transfers, including hands-on work with data classification and monitoring systems. Perform detailed data flow mapping to understand how customer data moves across internal systems, SaaS apps, APIs, and third-party integrations.
Cloud Security
- Secure cloud environments (AWS preferred) including data at rest and in transit using encryption and cloud-native security tools. Manage cloud access policies, network segmentation, secrets management, and continuous monitoring.
Risk Management & Compliance
- Support compliance frameworks including GDPR, SOC 2, ISO 27001, and crypto-specific security standards as required.
- Develop and maintain internal security policies, procedures, and security controls. Partner with the Data Protection & Information Security Officer to ensure alignment across security, privacy, and data governance.
Access & Identity Management
- Serve as the Access & Control Monitoring expert, managing IAM, RBAC policies, least-privilege access, MFA, and anomaly detection systems.
- Perform regular access reviews, privilege audits, and segregation-of-duty checks. Maintain strong audit logging practices and monitoring of access behavior.
Requirements
Do you have experience in Scripting?, Do you have a Bachelor's degree?, * 3+ years of experience in cybersecurity, information security, or security operations.
- Hands-on experience with Data Loss Prevention (DLP) tools and data classification frameworks.
- Strong data flow mapping expertise with the ability to trace data across systems, integrations, and APIs.
- Solid understanding of cloud security concepts, encryption, and cloud-native security tools (AWS preferred).
- Expertise in IAM and Access Control Monitoring, including least-privilege models, RBAC, MFA, and anomaly detection.
- Familiarity with audit logging, SIEM tools, vulnerability management, and endpoint security.
- Experience with incident response processes and playbooks.
- Strong understanding of MITRE ATT&CK, threat actors, and common attack vectors.
- Working knowledge of compliance standards such as GDPR, SOC 2, and data protection regulations. Excellent communication skills and the ability to collaborate with technical and non-technical teams., * Experience working in fintech, blockchain, or DeFi environments.
- Familiarity with cryptographic concepts, wallets, smart contracts, or key-management practices.
- Certifications such as Security+, CySA+, GSEC, GCIH, OSCP, CCSP, or similar.
- Experience automating security workflows using scripting languages. Exposure to ISO 27001, SOC 2 Type II audits, or similar security frameworks.
Benefits & conditions
- Competitive salary package
- Flexible 40-hour workweek
- Unlimited PTO and flexible work schedules
- Team off-sites and events Fully remote work setup - join our global team from anywhere!