Infrastructure Security Engineer

Blockchain
Paris, France

Who this role is best for

A natural match if you have 4+ years in security engineering with hands-on cloud automation, scripting, and infrastructure-as-code skills, and can commit to a Paris-based office presence four days a week.

Best fit for

  • Candidates with a bias toward automation and experience in cloud-native security tooling.
    — “a bias toward automation over manual workflows
  • Engineers who can influence platform architecture through collaboration with SRE and product teams.
    — “drive technical discussions with engineering teams and influence the overall architecture
  • Professionals comfortable with incident response and integrating security into CI/CD pipelines.
    — “Participate in security incident response when engineering expertise or automation support is needed
  • Individuals who can research and embed AI/LLM utilities securely into infrastructure.
    — “Research, architect, and safely embed cutting-edge AI utilities and Large Language Model (LLM) agents

Things to consider

  • Mandatory in-office presence four days per week in Paris, with limited remote flexibility.
    — “mandatory in-office presence four days per week
  • Personal data will be transferred to the United States for recruitment processing.
    — “your personal data will be transferred to the United States

How to stand out

  • Show examples of security controls you built for GCP or AWS environments.
    — “GCP or AWS are preferred
  • Demonstrate how you operationalized security standards like CIS Benchmarks or NIST.
    — “Knowledge of security standards and governance frameworks (e.g., CIS Benchmarks, NIST
  • Highlight experience with Wazuh or other HIDS systems in production environments.
    — “Familiarity with maintaining HIDS systems (Wazuh preferred)
  • Detail your contributions to threat modeling and architectural assessments.
    — “Assist in threat modeling, design reviews, and architectural assessments
Pace · Fast PacedCollaboration · HighAutonomy · MediumDecision Impact · TeamLevel · Senior

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • design and implement security controls
  • build automated tooling
Typical background
4+ years of experience in security engineering, platform security, or DevSecOps roles

Skills & requirements

Required

Security ControlsAutomationCloud EnvironmentsScriptingInfrastructure As Code

Preferred

AI Tools

Stack & domain

Security ControlsAutomationProcessesCloud EnvironmentsScriptingInfrastructure As CodeSecurity StandardsGovernance FrameworksSecurity RequirementsSecurity PostureSecurity Incident ResponseAI UtilitiesLarge Language Model (llm) AgentsCloudflareOSS SIEM ToolsIncident Management PlatformsCi/cd SystemsHIDS SystemsCollaborationProblem-solvingSecurity EngineeringPlatform SecurityDevSecOpsCloud SecuritySecurity AutomationAI In Security

About the role

Original posting from Blockchain via Greenhouse

Blockchain is connecting the world to the future of finance. As the most trusted and fastest-growing global crypto company, it helps millions of people worldwide safely access cryptocurrency. Since its inception in 2011, Blockchain has earned the trust of over 90 million wallet holders and more than 40 million verified users, facilitating over $1 trillion in crypto transactions.

We are looking for a Senior Infrastructure Security Engineer with a proven track record in keeping systems safe. You will play a critical role in building and providing tooling that monitors our entire stack, from supporting our consumer-facing products and our institutional offerings to ensuring that we are capable of rapidly responding to cyber attacks on our colleagues and endpoints.

Throughout our company, Security is a well-established mindset that leverages novel engineering approaches - as a Senior Infrastructure Security Engineer, you will lead by example and drive technical discussions with engineering teams and influence the overall architecture of our platform.

Our day-to-day work is interesting and dynamic, driven by a focus on proactive threat actor identification and in-depth investigation of security issues. These practices are key to ensuring strong product security and fostering continuous, iterative improvement.

WHAT YOU WILL DO:

Design, build, and implement security controls, automation, and processes across product, platform, and infrastructure environments.

Identify operational and technical security gaps, propose solutions, and drive engineering initiatives to close them.

Collaborate with the SRE and engineering teams to integrate security into CI/CD pipelines, deployment workflows, and cloud-native architectures.

Build automated tooling and services to enforce secure configurations, detect misconfigurations, and support continuous compliance.

Assist in threat modeling, design reviews, and architectural assessments for new and existing systems.

Contribute to internal security documentation, best practices, and developer guidance.

Participate in security incident response when engineering expertise or automation support is needed.

AI-Driven Innovation: Research, architect, and safely embed cutting-edge AI utilities and Large Language Model (LLM) agents directly into our secure infrastructure.

WHAT YOU WILL NEED:

4+ years of experience in security engineering, platform security, or DevSecOps roles.

Hands-on experience implementing security controls and automation within cloud environments, GCP or AWS are preferred.

Proficiency in modern scripting, automation and infrastructure as code e.g. Python, Bash, Go, Terraform, or similar.

Ability to collaborate closely with engineering teams and translate security requirements into practical, scalable solutions.

Strong analytical and problem-solving skills, with a bias toward automation over manual workflows.

Curiosity, ownership, and a drive to continuously improve the security posture of complex systems.

Familiarity with some of the following: Cloudflare (DDoS protection, WAF), OSS SIEM tools (Splunk, Elastic, etc), Incident management platforms (e.g. Incident.io, PagerDuty)

Familiarity with at least one of the following CI/CD systems (Github Actions, Concourse, CircleCI)

Familiarity with maintaining HIDS systems (Wazuh preferred).

NICE TO HAVE

Knowledge of security standards and governance frameworks (e.g., CIS Benchmarks, NIST, SOC2, ISO 27001, PCI DSS) and how to operationalize them.

Hands-on experience with building and maintaining a SIEM comprised of open-source and hosted components

Experience securing consumer-facing web and iOS / Android applications

Experience designing policies and administering Vault & other Hashicorp products.

Experience managing security vendors

COMPENSATION & PERKS

Unlimited vacation policy; work hard and take time when you need it.

Unlimited books policy; order the technical resources you need or simply pick something up from our company library.

Apple equipment.

Full-time salary based on experience and meaningful equity in an industry-leading company.

Role based in our Paris office, with a mandatory in-office presence four days per week

Work from Anywhere Policy: You can work remotely from anywhere in the world for up to 20 days per year.

Blockchain is committed to diversity and inclusion in the workplace and is proud to be an equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, religion, color, national origin, gender, gender expression, sex, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law. This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, and apprenticeship. Blockchain makes hiring decisions based solely on qualifications, merit, and business needs at the time.

You may contact our Data Protection Officer by email at dpo@blockchain.com. Your personal data will be processed for the purposes of managing Controller’s recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results thereto, and as is otherwise needed in the recruitment and hiring processes. Such processing is legally permissible under Art. 6(1)(f) of Regulation (EU) 2016/679 (General Data Protection Regulation) as necessary for the purposes of the legitimate interests pursued by the Controller, which are the solicitation, evaluation, and selection of applicants for employment.

Your personal data will be shared with Greenhouse Software, Inc., a cloud services provider located in the United States of America and engaged by Controller to help manage its recruitment and hiring process on Controller’s behalf.  Accordingly, if you are located outside of the United States, your personal data will be transferred to the United States once you submit it through this site. Because the European Union Commission has determined that United States data privacy laws do not ensure an adequate level of protection for personal data collected from EU data subjects, the transfer will be subject to appropriate additional safeguards under the standard contractual clauses. 

Your personal data will be retained by Controller as long as Controller determines it is necessary to evaluate your application for employment.  Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.

Source: Blockchain careers (Greenhouse)

Similar roles