Lido is hiring a SecOps Engineer in DevOps — Worldwide. The overview below is synthesized from the employer posting on jobs.ashbyhq.com: factual requirements and scope are preserved, but prose is rewritten with editorial context. Verify details and apply via the employer link.
The SecOps contributor workstream is responsible for helping the DAO to integrate security into development processes, managing incidents, and collaborating with teams. This role develops response plans, conducts assessments, and ensures effective communication of security practices.
Responsibilities
Day-to-day scope for the SecOps Engineer as described in the posting:
Security Integration
- Develop secure systems to protect Lido Protocol, DAO, applications, contributors, partners, and stakers.
- Define processes, systems, and applications to make attacks difficult to execute and easy to detect.
- Embed security practices and tools within the development pipeline.
Threats and Incident Management
- Develop and maintain incident response plans and playbooks.
- Perform regular vulnerability assessments and penetration testing.
- Lead or participate in incident response activities, including investigation, containment, eradication, and recovery.
- Monitor security alerts and incidents to identify and respond to threats promptly.
Collaboration and Training
- Collaborate with development and operations teams to ensure security is incorporated from design to deployment and maintenance.
- Provide training and support on security tools and techniques, emphasizing soft skills like communication, negotiation, and influence.
Requirements
Experience and skills the team lists as required:
Must have
- Experience with technical security assessments, code audits, design reviews, and vulnerability research.
- Proficiency in programming languages (Python, Golang, JavaScript, Bash).
- Experience with security tools and technologies (SIEM, IDS/IPS, vulnerability scanners, automated security testing).
- Excellent communication skills to articulate security concepts to technical and non-technical stakeholders.
- Strong problem-solving abilities for security investigations and risk assessments.
- English level: B2+
Good to have
- Experience with blockchain technologies, Ethereum-based networks, web3 bug hunting, and contract analysis.
- Familiarity with DevOps practices and tools (Docker, Kubernetes, GitHub Actions, Git, Ansible, Terraform).
- Experience with supply chain attacks analysis and prevention.
- Focus on improving real-world security, not compliance.
Key Factors
- Contribute from anywhere in the world.
- Competitive compensation level.
- Flexible schedule.
- Compensation for education, including language & professional growth courses.
- Equipment & co-working reimbursement program.
Build a standout application
For the SecOps Engineer at Lido, reviewers look for concise evidence over buzzwords. Mirror the language of the posting sparingly, quantify support or delivery outcomes, and show how you handled ambiguity, time-zone collaboration and user empathy. Keep your resume to impact, keep your cover note to one page, and link to artifacts — tickets resolved, docs shipped, dashboards owned — that prove you can operate in a fast-moving Web3 team. Prepare to discuss a time you turned a confusing user report into a clear fix and how you measure quality in support and operations.
Web3 hiring values reliability: on-time follow-through, clear writing, and a track record of improving runbooks and tooling. Treat the application as a work sample. For interviews, be ready to walk through how you prioritize across time zones, handle a difficult user, and decide when to escalate versus resolve directly. Show how you document decisions so the next teammate benefits.
In a distributed Web3 org, trust builds through written clarity. Use the cover note to demonstrate it.
