Decentralized Masters-posted 18 days ago
Full-time • Mid Level
Remote • Miami, FL

We are seeking a Security Specialist to develop, maintain, and continuously improve the security infrastructure across Decentralized Masters and our new SaaS venture. This role focuses on operational security, data protection, risk prevention, and proactive threat mitigation. You’ll work cross-functionally with engineering, data protection, compliance, operations, and product teams to ensure the confidentiality, integrity, and availability of our systems, data, and customer assets. This is a hands-on role, ideal for someone who thrives in a fast-moving, high-ownership environment.

  • Monitor, analyze, and respond to security events across systems, cloud environments, applications, and internal tools.
  • Implement and manage SIEM, IDS/IPS, endpoint protection, vulnerability scanners, and logging infrastructure.
  • Conduct regular vulnerability assessments and coordinate remediation with engineering teams.
  • Oversee secure configuration baselines for infrastructure, servers, cloud accounts, and internal systems.
  • Implement and enforce Data Loss Prevention (DLP) policies, tools, and controls to prevent unauthorized data transfers, including hands-on work with data classification and monitoring systems.
  • Perform detailed data flow mapping to understand how customer data moves across internal systems, SaaS apps, APIs, and third-party integrations.
  • Secure cloud environments (AWS preferred) including data at rest and in transit using encryption and cloud-native security tools.
  • Manage cloud access policies, network segmentation, secrets management, and continuous monitoring.
  • Support compliance frameworks including GDPR, SOC 2, ISO 27001, and crypto-specific security standards as required.
  • Develop and maintain internal security policies, procedures, and security controls.
  • Partner with the Data Protection & Information Security Officer to ensure alignment across security, privacy, and data governance.
  • Serve as the Access & Control Monitoring expert, managing IAM, RBAC policies, least-privilege access, MFA, and anomaly detection systems.
  • Perform regular access reviews, privilege audits, and segregation-of-duty checks.
  • Maintain strong audit logging practices and monitoring of access behavior.
  • Deliver training, simulations, and internal education to strengthen internal security awareness.
  • Lead phishing simulation programs and social engineering prevention initiatives.
  • Lead the incident response process: detection, escalation, containment, investigation, and post-incident review.
  • Maintain and improve the incident response playbook; run annual and quarterly tabletop exercises.
  • Collaborate with engineering teams to embed secure-by-design practices into our SaaS products.
  • Conduct application security reviews, threat modeling, and code analysis (bonus).
  • Contribute to architecture decisions for new features and infrastructure.
  • 3+ years of experience in cybersecurity, information security, or security operations.
  • Hands-on experience with Data Loss Prevention (DLP) tools and data classification frameworks.
  • Strong data flow mapping expertise with the ability to trace data across systems, integrations, and APIs.
  • Solid understanding of cloud security concepts, encryption, and cloud-native security tools (AWS preferred).
  • Expertise in IAM and Access Control Monitoring, including least-privilege models, RBAC, MFA, and anomaly detection.
  • Familiarity with audit logging, SIEM tools, vulnerability management, and endpoint security.
  • Experience with incident response processes and playbooks.
  • Strong understanding of MITRE ATT&CK, threat actors, and common attack vectors.
  • Working knowledge of compliance standards such as GDPR, SOC 2, and data protection regulations.
  • Excellent communication skills and the ability to collaborate with technical and non-technical teams.
  • Experience working in fintech, blockchain, or DeFi environments.
  • Familiarity with cryptographic concepts, wallets, smart contracts, or key-management practices.
  • Certifications such as Security+, CySA+, GSEC, GCIH, OSCP, CCSP, or similar.
  • Experience automating security workflows using scripting languages.
  • Exposure to ISO 27001, SOC 2 Type II audits, or similar security frameworks.
  • Competitive salary package
  • Flexible 40-hour workweek
  • Unlimited PTO and flexible work schedules
  • Team off-sites and events
  • Fully remote work setup — join our global team from anywhere!
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service