Job Description

Summary

Immutable’s mission is to power the next generation of web3 games. Bringing the next million users into web3 requires that our products are safe for everyone and anyone to use.

The Immutable security team ensures the organisation has the knowledge, tools, and drive required to build that trust.

Immutable needs to know its adversaries, their tools, tactics and procedures and deploy mitigating controls and detections to deter them. We need to understand the attack paths, the probabilities of these paths and the cost of controls and detections. We need to elevate the cost to the attacker while amortising our own cost.

Detection and response can be seen as a closed loop, with detections such as code-driven automated playbooks that deliver enriched information for a human or a machine/model to make a decision.

This role will lead the Detection and Response and IT Identity and Access functions at Immutable, unifying enterprise security, detection and response, and identity and access engineers under a single lead.

We hire the best and provide them with the best tooling. From the security platform to web2 and web3 intelligence, the successful candidate will be able to build the flywheel that incrementally improves our controls across endpoints, cloud, and blockchain, incorporating new information from intelligence, adversary simulations, incidents, and metrics to prioritise mitigating controls and improve their effectiveness. If this sounds like you, please apply!

You’ll Be Empowered To 🎮

  1. Manage/Coach a team of 4 and ensure they deliver impact.
  2. Leverage the autonomy and agency provided to you to set the strategy across your functional areas. The strategy should be integrated (enterprise, cloud, blockchain), incorporate new knowledge, and you can demonstrate it is effective and delivers results (data and metrics).
  3. Provide the capability to treat the risk of Immutable being unable to respond effectively to a significant security incident + the risk of security incidents being detected by third parties or the public before Immutable.
  4. Come in and heavily automate detection and response playbooks using code and AI.
  5. Dive deep into detection engineering and detections (and playbooks) as code.
  6. Facilitate deep work, understanding the problem empirically and knowing where to place our preventative controls and detections.
  7. Leverage the fantastic platforms and tooling that Immutable has acquired to move fast and deliver impact.
  8. Benefit from iterating on attack graphs (non-linear threat models) that allow you to focus on the most important detections to protect Immutable’s crown jewels.
  9. Unlock impact daily, creating a positive feedback loop and delivering results and impact quickly.
  10. Work with significant agency and autonomy, with the responsibility to drive a roadmap incorporating enterprise IT, detection and response and identity and access.

We'd Love You To Bring 🤝

  1. Strong capabilities in prioritising actions based on security effectiveness and their cost (time/delay/money) to the organisation—must be able to set a strategy, understand that the strategy requires transition states, and know when those states need to be changed.
  2. Repeated demonstration that you are a strong people manager/coach and can unlock scale and impact in their coaches - using 1:1s to guide individuals, set growth plans and guide the right work to the people that need it.
  3. Willingness and interest in incorporating AI and sophisticated tooling into your security philosophy.
  4. Comfort working in smaller teams and delivering 10x results - you won’t be able to use large teams to solve your problems but need to think in terms of small, focused teams that drive sophisticated tooling and AI.
  5. World-class intuition - it needs to be close or on the mark every time.
  6. The ability to design, implement and monitor security metrics that indicate their business's current or desired state.
  7. Knowledge of what good looks like as a lead of a number of functions, your intuition needs to be close or on the mark every time.
  8. Effective communication skills, with the ability to speak with empathy and influence the work of other teams.
  9. Experience in building teams and working in a scaling tech company.
  10. An interest in Blockchain is not required but is a very strong indicator.

Skills
  • Communications Skills
  • Problem Solving
  • Risk Analysis
© 2024 cryptojobs.com. All right reserved.