<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>5061e245-c0f</externalid>
      <Title>DevSecOps Engineer</Title>
      <Description><![CDATA[<p>The DevSecOps engineer plays a crucial role in ensuring that every step of the software development lifecycle (SDLC) follows security best practices. This involves automating security processes, embedding security testing, and fostering a culture of shared responsibility between development, operations, and security teams.</p>
<p>Key responsibilities include:</p>
<ul>
<li>Implementing secure coding practices and identifying vulnerabilities early through tools</li>
<li>Reviewing for secure cloud infrastructure and ensuring compliance with security standards</li>
<li>Integrating, monitoring, and improving DevSecOps tools and processes</li>
<li>Performing continuous vulnerability assessments, risk mitigation, and risk management</li>
<li>Designing and implementing Zero Trust security models, platform-based controls, and automated guardrails</li>
</ul>
<p>Additionally, the DevSecOps engineer will support and consult with product and development teams to address application security risks throughout the lifecycle, provide security training and outreach to internal teams and customers, and monitor KPIs and customer experience to refine security processes and adherence.</p>
<p>This role requires strong development or scripting experience, specifically in Java, to automate routine tasks and improve system reliability. The ideal candidate will have a deep familiarity with common security flaws and the use of security libraries and static analysis tools (SAST).</p>
<p>Bachelor&#39;s degree in a relevant field or an equivalent combination of education, training, and experience is required. A minimum of 3 years of professional experience is also necessary. Certification in DevSecOps, Kubernetes, or HashiCorp is desirable but not essential.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Java, security libraries, static analysis tools, DevSecOps, Kubernetes, HashiCorp</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Unknown</Employername>
      <Employerlogo></Employerlogo>
      <Employerdescription>The company is a technology firm that specialises in software development and security.</Employerdescription>
      <Employerwebsite></Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/60738</Applyto>
      <Location>Unknown</Location>
      <Country></Country>
      <Postedate>2026-04-24</Postedate>
    </job>
    <job>
      <externalid>2798986b-685</externalid>
      <Title>Security Engineering Lead</Title>
      <Description><![CDATA[<p>As a Security Engineering Lead on our team, you&#39;ll be leading the security and auditing efforts for Espresso&#39;s codebase leading up to, and beyond, launch. We are looking for an experienced security engineering and software auditing professional who can lead review processes of our design and codebase.</p>
<p>Responsibilities:</p>
<p>Lead security audits of (a subset of) the Espresso codebase
As a project leader, you will have mobility in how you choose to organize security and audit efforts
Dive into the code of a fairly complex distributed system, learning and developing an understanding of the system on the fly (with help from the engineering team that built it, of course)
Coordinate with several engineering teams to aid in your audit, raise concerns and communicate results, and guide the effort to harden the system based on your findings
Coordinate with, manage, and review the work of external security auditing teams, in certain cases
Suggest improvements to testing and engineering practices to promote more secure and maintainable code</p>
<p>Requirements:</p>
<p>Solid grasp of software engineering principles, both low-level (e.g. language-specific best practices) and high-level (e.g. reliable software architecture, particularly in distributed systems)
If focused on Rust: ≥ 1 year experience writing Rust, particularly with async Rust.
If focused on Solidity: Multiple years experience writing smart contracts; experience with smart contract security audits or formal verification of smart contracts
Experience as an engineer or software architect in a security-critical industry
Be capable of describing the stakes, the challenges you&#39;ve faced in building secure software, and the steps/processes you&#39;ve taken to mitigate risk
Experience as an auditor, pentester, QA tester, etc.
Have a well thought-out approach to testing software and designing it to be testable/auditable
Ability to think adversarially, and identify potential reliability or security vulnerabilities even in software that is correct in common or “happy path” scenarios
Experience on the design and/or testing of distributed systems
Comfort diving into unknowns and asking questions</p>
<p>Preferred:</p>
<p>Knowledge of relevant testing and static analysis tools (e.g. Foundry, Slither) is a plus
Blockchain knowledge/experience is preferred, but could also be include IoT, automotive, finance, etc.
Ideally, the candidate should have a general philosophy of software design that has been molded by experience working on security-critical systems</p>
<p>Benefits:</p>
<p>Fully remote with flexible hours
Work alongside the brightest minds in the crypto space
Competitive salary + equity package
Regular team off-sites to international locations
Unlimited vacation policy
Top-tier health, dental, and vision coverage for US employees</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Rust, async Rust, Solidity, smart contract security audits, formal verification of smart contracts, software engineering principles, low-level programming, high-level programming, distributed systems, testing and static analysis tools, Foundry, Slither, blockchain knowledge, IoT, automotive, finance</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Espresso Systems</Employername>
      <Employerlogo>https://logos.yubhub.co/espressosystems.com.png</Employerlogo>
      <Employerdescription>Espresso Systems builds foundational infrastructure to power tomorrow&apos;s internet, providing rollups with secure, real-time visibility into what&apos;s happening on all integrated chains.</Employerdescription>
      <Employerwebsite>https://www.espressosystems.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/Espresso/135f4767-f690-41f8-9ab0-95fd9d398677</Applyto>
      <Location>Remote</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
  </jobs>
</source>