ScoutGet started
ConsensysSecurity

SOC Analyst

Remote - Europe (hybrid)FullTime
The role
ABOUT CONSENSYS Consensys Incorporated is an independent blockchain infrastructure company, spun out of Consensys Software Inc. — one of the world's leading blockchain technology companies and the primary development organization behind the Ethereum ecosystem. We build and operate neutral, institutional-grade blockchain infrastructure that connects banks, asset managers, custodians, and financial market infrastructures to digital asset networks, meeting the non-negotiable standards of institutional finance: privacy, scalability, resilience, security, and regulatory readiness. Headquartered in Miami, Florida, and operating across the US, Europe, and Australia, Consensys Incorporated launched as an independent entity in September 2026 and is building the team to match its ambition. WHY THIS ROLE EXISTS Following Consensys's strategic transition into two independent entities (MetaMask for consumer platforms and Consensys focusing on protocols and institutional infrastructure), we are seeking an experienced Security Operations Center (SOC) Analyst to join our security organization. Consensys powers the core infrastructure driving the decentralized web, including Linea mainnet and the open-source Lineth ZK rollup stack recently donated to Linux Foundation Decentralized Trust. The SOC Analyst will be responsible for architecting, building, and operating a comprehensive 24/7 monitoring and alerting ecosystem across our entire digital asset footprint. This role spans enterprise IT SaaS environments, core blockchain infrastructure, and Web3 smart contract security. The SOC Analyst will bridge traditional cybersecurity operations with cutting-edge Web3 threat detection, protecting our corporate IT stack (JumpCloud, AWS, Google Workspace, GitHub, Notion, Zoom), Linea mainnet infrastructure, and ecosystem DeFi protocols against emerging cyber threats and exploits using tools such as Hypernative, Hexagate, and Blockaid. WHAT YOU’LL OWN 1. Enterprise IT Security & SaaS Monitoring - Architect and maintain centralized log collection, SIEM integration, and incident response services across AWS (utilizing Amazon GuardDuty and AWS CloudTrail) and corporate IT services including JumpCloud, Google Workspace, GitHub, Notion, and Zoom. - Develop custom detection rules and alert logic to detect unauthorized access, privilege escalation, credential compromise, and anomalous user activity. - Ensure complete security logging visibility, audit readiness, and access control management across all corporate platforms. 2. Infrastructure & ZK-Rollup Monitoring (Linea & Lineth) - Establish real-time security monitoring for Linea mainnet and the open-source Lineth ZK rollup stack (including Besu execution layer, Maru consensus, coordinator, and provers). - Monitor RPC endpoints, sequencer performance, L1/L2 messaging reliability, state root finalization, and infrastructure telemetry. - Collaborate with the DevOps team and core engineering teams to detect and mitigate infrastructure threats, DDoS attacks, and zero-day vulnerabilities. 3. Web3 & Smart Contract Threat Detection - Implement and tune real-time Web3 threat monitoring platforms including Hypernative, Hexagate, and Blockaid. - Build automated alerts to detect suspicious smart contract interactions, flash loan attacks, reentrancy exploits, liquidity drains, and unauthorized bridge activity on Linea mainnet. - Perform onchain forensics and transaction trace analysis to safeguard ecosystem DeFi protocols and institutional assets. 4. Incident Response & Threat Hunting - Serve as a primary responder for security alerts originating from IT SaaS, cloud infrastructure, and Web3 protocol layers, utilizing Grafana Cloud IRM to manage on-call rotations and incident management. - Lead triage, investigation, containment, and post-mortem root cause analysis for confirmed security incidents. - Proactively conduct threat hunting across system logs, cloud environments, and onchain transaction streams. 5. Security Automation & Detection Engineering - Automate incident response playbooks and triage workflows using SOAR tools and custom scripts (Python, Go, Bash). - Continuously refine detection rules to reduce false positives and improve Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). - Integrate automated containment mechanisms across access management, cloud IAM, and Web3 security providers. 6. Compliance, Governance, and Reporting - Maintain detailed incident records, forensic evidence, and documentation in alignment with SOC2 and ISO compliance frameworks. - Prepare security operational metrics, alert volume analysis, and threat reports for leadership. - Ensure compliance with corporate security policies and access controls across all environments. 7. Threat Intelligence & Ecosystem Collaboration - Monitor Web3 threat landscapes, tracking emerging smart contract exploit techniques and threat actors targeting L2 ecosystems. - Coordinate with external security researchers, bug bounty programs, and Web3 security alliances to share intelligence. - Participate in incident response drills, security reviews, and audit remediation with external security partners. WHAT WE ARE LOOKING FOR - 3–5+ years of experience in Security Operations, Detection Engineering, or Incident Response within cloud-native or Web3 environments. - Hands-on experience configuring and maintaining monitoring, threat detection, and incident analysis services for AWS (such as Amazon GuardDuty and AWS CloudTrail) and enterprise IT platforms (JumpCloud, Google Workspace, GitHub, Notion, and Zoom). - Direct experience using Web3 security and onchain monitoring tools such as Hypernative, Hexagate, and Blockaid. - Deep technical understanding of Ethereum, L2 scaling architectures, ZK-rollups (Lineth stack, Besu execution, prover systems), and smart contract vulnerabilities. - Proficiency in log management, monitoring platforms (such as Grafana), SIEM/SOAR platforms, and scripting languages (Python, Go, Bash, or SQL). - Familiarity with SOC2, ISO 27001, NIST, or SANS security frameworks. - Strong communication, problem-solving, and analytical skills in a fast-paced, remote-first environment. BENEFITS OF THIS ROLE - The opportunity to safeguard cutting-edge Web3 and ZK-rollup infrastructure at the forefront of blockchain technology. - A dynamic and collaborative work environment with a passionate and talented team. - Competitive compensation package, including salary, benefits, and performance-based incentives. - A platform to influence the future of decentralized technologies and financial systems. REPORTING STRUCTURE - Reports to: Head of Security. - Team: Working closely with our dedicated DevOps team, Head of Security, and Site Reliability Engineer, this role will serve as the founding member of the incident response team. WORKING AT CONSENSYS We are a fully remote, globally distributed company. We hire the best people wherever they are, work asynchronously, and judge each other on impact rather than hours or location. We offer competitive compensation, meaningful equity, and the chance to work on genuinely open source software at the frontier of web3. Consensys is an equal opportunities employer. We celebrate diversity and are committed to building an inclusive environment for all employees.