Figment Logo

Figment

Senior Red Team Operator

Sorry, this job was removed at 05:28 p.m. (MST) on Wednesday, Nov 27, 2024
Be an Early Applicant
Canada
Internship
Canada
Internship
You could work anywhere. Why Figment?

Figment powers the future of Web3 through industry-leading blockchain infrastructure. As the leading provider of staking solutions, we help 500+ institutional clients optimize their crypto rewards, including top exchanges, asset managers, wallets, foundations, custodians, and major token holders. Our clients trust Figment for a comprehensive suite of services, including reward optimization, cutting-edge API development, detailed rewards reporting, seamless partner integrations, governance support, and slashing protection.

Backed by a team of passionate and intelligent Figmates, with a 100% remote-first global presence across 12 countries, our company is on a mission to accelerate the adoption, growth, and long-term success of the Web3 ecosystem. We’re building the infrastructure that will power the decentralized future.

As a fast-growing tech company, we’re looking for builders and innovators — people who thrive in the face of uncertainty and are motivated to make an impact. We are also looking for true teammates - people who are genuine, humble, and driven to level up together. If you're excited to shape the future, contribute to an energetic company culture, and work at the cutting edge of blockchain technology, we want you to join our team and help us lead the charge!

About the opportunity

As a senior member of the Figment Security Red Team, your responsibility will be to design and execute campaign-based security testing for Figment. This will involve targeting multiple types of assets. Successful applicants should have the ability to evaluate environments, applications, systems, or processes to identify vulnerabilities. Furthermore, they should be able to translate these findings into practical attack strategies for real-world scenarios.

To effectively support Figment's security initiatives, you will need to utilize your knowledge of cloud platforms, CI/CD pipelines, operating system security, networking and protocols, firewalls, databases, middleware applications, and scripting. You will also need to effectively communicate highly technical information to internal customers. Additionally, you will be responsible for providing remediation recommendations and validating security remediation findings.

How you will make an impact

  • Document processes, procedures, and workflows for red team operations.
  • Perform a full range of red team activities including network intrusion, cloud and development pipeline exploitation, web and application testing, source code reviews, threat analysis, and detection evasion techniques.
  • Develop comprehensive and accurate reports and presentations for both technical and executive audiences.
  • Collaborate with seniors in the security team to enhance the red team strategy and improve the company's security posture.
  • Effectively communicate findings and strategies to stakeholders, including technical staff, executive leadership, and legal counsel.
  • Provide practical and risk-appropriate recommendations to address vulnerabilities.
  • Configure and safely use attacker tools, tactics, and procedures in Figment environments.
  • Enhance Figment's red teaming processes by developing and improving scripts, infrastructure, tools, and methodologies.
  • Offer recommendations and guidance to enhance the defensive capabilities of the team and its ability to defend the Figment Enterprise.
  • Provide mentoring and training to blue team members and actively participate in cross-team security exercises.
  • Provide technical expertise and support during incident response and assist in creating post-incident action plans.

Who you are

  • Bachelor's degree or four or more years of work experience
  • Experience in cloud-based exploitation or security assessments
  • Experience in network penetration testing and manipulation of network infrastructure.
  • Experience in API and web application assessments.
  • Experience in scripting and automation of simple tasks using Bash, Python, or similar
  • Experience developing, extending, or modifying exploits, shellcode or exploit tools.
  • Experience with container orchestration management tools such as Docker and Kubernetes.
  • Experience with source code review for control flow and security flaws.
  • Experience with red, blue, or purple teaming exercises.
  • Strong knowledge of offensive security and pentesting tooling such as Kali Linux, Burp Suite, Mythic C2, and other open source tools.
  • Strong technical writing.

Even better if you have

  • Industry certifications such as OSCP/OSCE, OSEP, OSWE, GPEN, GCPN, GWAPT, or GXPN.
  • Solid understanding and experience working with Github and Github deployment pipelines
  • Solid understanding of public cloud environments including AWS, Azure and Google.
  • Solid understanding of OWASP Top 10 and how to effectively exploit them.
  • Thorough understanding of network protocols, data on the wire, and covert channels.
  • Programming skills as well as the ability to read and assess applications written in multiple languages such as Go, Rust, and Ruby.
  • Understanding of security risks for blockchain and crypto.
  • Familiarity with Solidity, Vyper, Yul, Cairo, Rust, or Move.

Why you might be excited about us

At Figment, we offer an exciting range of competitive benefits designed to support and empower every member of our team:

  • 100% remote-first environment. Our flagship office is in Toronto, Canada. We also have additional co-working spaces in New York, Montreal, London, and Singapore. That means if you want to do your things in the office (if you’re near one), at home, or a bit of both, it’s up to you.
  • 4 weeks of PTO that kick in day one, with an additional 1 week of flex days.
  • Extended company-paid health benefits that kick in day one.
  • Best in class parental leave and flexible arrangements.
  • A home office stipend to create a space that you enjoy working in.
  • Monthly Wifi reimbursement.
  • A yearly Learning & Development budget.
  • 401K (US) or RRSP match (Canada).
  • Stock Options in the company.
  • A competitive bonus (based on company performance) that is distributed bi-annually - we believe that the company’s success should be shared with our employees often
    • For roles listed within the Sales Department, there is instead a competitive commissions structure which will be outlined during your first interview with Figment
  • Annual onsite company gatherings and retreats to inspire team bonding, collaboration, and fun!

Other reasons you may love working at Figment

  • We are a team of under 200 members, which allows for an impactful contribution from day one.
  • We place a strong focus on personal career development to shape a role that fits your goals and interests. Your satisfaction and well-being matter to us, and we’re here to support your ongoing growth.
  • Our culture is one of honesty, professionalism and risk taking in a high-growth environment.
  • Our team members themselves recommend working at Figment - with an eNPS score of 54 (which is ranked as ‘great’!).
  • We are also extremely proud of ranking as one of the top Web3 employers by Talent Titans.

Compensation

One of Figment’s core principles is “Making the Invisible Visible” - ensuring transparency and information sharing in all communication. Figment is committed to transparency regarding pay, benefits, and other compensation types for all internal roles as well as all roles being hired for.

Base Salary: The CAD base salary range for this position is CAD $150,000 - $180,000. The US base salary range for this position is USD $150,000 - $180,000. This range reflects base salary only, and does not include additional compensation or benefits. For candidates in other countries, the pay range will be disclosed upon your first interview with Figment (being a globally remote company, the list of salary ranges would simply be too long to note here!). The range displayed reflects the minimum and maximum range for a new hire across all Canada or the US. A candidate’s specific pay within the range will be determined by various factors including job-related skills, relevant education, and training.

Interview process

At Figment, we try to go above and beyond in making sure that you have the best possible experience interviewing with us. We strive for a smooth, organized, and informative process.

  • During your first Recruiter Call, you will be provided with more information about Figment, the position and what to expect for the rest of the interview process. Please be prepared to discuss why you are interested in joining Figment and what excites you about the position and company.
  • As we go through the process, we work to make sure that you hear back from us in a timely fashion. If we decide at any point that we’re unfortunately not moving forward, we will give you feedback on why it was not a fit.
  • We aim for the entire process to take around 2-3 weeks from initial screen to offer. There can be exceptions on either side of the bell curve here, but as a rule, that’s the time-frame you can expect.


See here for Figment's Privacy Policy and California Employee Privacy Policy.

At Figment, we have a thorough hiring process to verify the identity of all job candidates. This includes checking documents, conducting in-person interviews, biometric authentication and completing background checks. Candidates must pass all these steps to be considered for a job with Figment. Anyone who provides false information or tries to skip these steps will be disqualified from the hiring process immediately.

To learn more about Figment, our team, and the amazing work we are doing, visit our website. Are you ready to join us?

Similar Jobs

3 Hours Ago
8 Locations
Remote
Hybrid
3,500 Employees
Senior level
3,500 Employees
Senior level
Blockchain • Fintech • Mobile • Payments • Software • Financial Services
The Knowledge Management Lead will develop and implement knowledge management strategies to enhance customer support and achieve operational excellence. Responsibilities include leading a team, designing and managing Knowledge Management Systems, applying KCS methodologies, and overseeing cross-functional projects while tracking metrics for effectiveness.
Be an Early Applicant
4 Hours Ago
Canada
Remote
2,200 Employees
Mid level
2,200 Employees
Mid level
Big Data • Fintech • Mobile • Payments • Financial Services
The Strategic Partnerships Lead at Affirm will be responsible for expanding the platform footprint by signing and managing partnership deals, developing competitive proposals, and collaborating with internal teams. The role requires strong relationship-building skills with decision-makers and the ability to drive partner value.
Be an Early Applicant
4 Hours Ago
Canada
Remote
2,200 Employees
Senior level
2,200 Employees
Senior level
Big Data • Fintech • Mobile • Payments • Financial Services
The Director of Learning will lead Affirm's Learning & Development function, focusing on the design and delivery of solutions to elevate individual and leadership capabilities. Responsibilities include program development, partnership with stakeholders, and performance metrics analysis to enhance employee growth in a remote-first culture.

What you need to know about the Calgary Tech Scene

Employees can spend up to one-third of their life at work, so choosing the right company is crucial, not just for the job itself but for the company culture as well. While startups often offer dynamic culture and growth opportunities, large corporations provide benefits like career development and networking, especially appealing to recent graduates. Fortunately, Calgary stands out as a hub for both, recognized as one of Startup Genome's Top 100 Emerging Ecosystems, while also playing host to a number of multinational enterprises. In Calgary, job seekers can find a wide range of opportunities.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account