About Marketnode
Marketnode, an SGX Group and Temasek joint venture, is Asia-Pacific’s trusted and neutral DLT powered financial markets infrastructure (FMI).
At Marketnode, we operate two flagship platforms, Gateway and Fundnode. Gateway is a one-stop, end-to-end platform enabling market participants to accelerate workflows, lower time to market, and capitalise on the transformative potential of tokenisation. Fundnode is Singapore’s investments fund utility on blockchain, providing the funds ecosystem with a single platform for transaction management, funds processing, and record-keeping.
Our company is looking to re-invent the way traditional financial instruments are originated, traded, booked, and serviced with the use of distributed ledger technologies. This goes across Ethereum, Polygon, blockchains and DEX(s) like Uniswap or Aave and would interact with stablecoins, CBDCs or other forms of tokenized money.
Our vision is to build an end-to-end infrastructure for truly native digital assets and their tokenization.
If you are passionate about and interested in the nexus between fintech and capital markets, we would like to talk to you.
This job is based in Singapore.
Who are we looking for:
We are looking for a DevSecOps Engineer to join us! You will work with the DevOps team to shape and secure our platform.
Key Responsibilities:
- Be responsible for overall security of critical systems and services
- Review cloud deployment architectures and implement required security controls
- Set security best practices for AWS, Azure and Kubernetes
- Identify security vulnerabilities in the system and implement necessary solutions to remediate the vulnerabilities
- Implement tools to shift security left and reduce the time taken to detect vulnerabilities
- Articulate associated risks and propose mitigations on related source code reviews, vulnerability assessments, DevSecOps and pentest findings to stakeholders and management Work with partners and vendors to ensure compliance of security requirements
Requirements:
- 5+ years of Cloud Security/DevSecOps experience
- Experience and working knowledge of SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing) and SCA (Software Composition Analysis) tools (including their strength and weakness)
- Excellent knowledge of cloud security best practices and solutions in cloud security posture management and cloud security workload management
- Ability to perform automation using Terraform, Docker/Kubernetes, and any one CI tools (e.g. Azure DevOps Pipeline, Jenkings, Bitbucket pipeline etc.)
- Professional or Speciality (Security) Certifications in AWS, Azure, Kubernetes or Cyber security certifications including CISSP, CISM, CompTIA Security+ and GSEC is a plus
- Experience / knowledge in blockchain, digital assets and their associated weaknesses is a plus
- Knowledge of regulatory requirements related to Privacy, including but not limited to MAS TRM, GDPR, HIPAA, CCPA, ISO 27001, SOC and the NIST standards or equivalent