
Senior Security Engineer
Job description
About the role
The is responsible for owning the design and execution of the company's comprehensive security program in partnership with the Head of Security. This role requires establishing and maintaining build standards for cryptographic operations and transaction processing across all blockchain environments to ensure resilience in adversarial conditions. You will lead the design of intake workflows to clarify and document security requirements for new vault products and infrastructure modifications. The position demands conducting in-depth reviews of user access patterns and security detection rules while tuning monitoring to identify emerging threat behaviors specific to onchain finance. You will develop and ship automation for security controls that scale efficiently with increasing transaction volume and protocol complexity. Additionally, you will forge strategic partnerships with protocol teams and infrastructure owners to align on risk treatment plans and mitigation strategies. The role involves mapping data flows for all onchain services, documenting trust boundaries, trust assumptions, and data integrity requirements to protect billions in onchain decentralized finance activity. You will perform evaluations of vendor and third-party integrations, verifying that financial interfaces meet strict resilience and security expectations for institutional clients.
Key facts
What you'll do
- Lead the design of intake workflows to clarify and document security requirements for new vault products and infrastructure modifications.
- Establish and maintain build standards for cryptographic operations and transaction processing across all blockchain environments.
- Conduct in-depth reviews of user access patterns and security detection rules, tuning monitoring to identify emerging threat behaviors.
- Develop and ship automation for security controls that scale efficiently with increasing transaction volume and protocol complexity.
- Forge strategic partnerships with protocol teams and infrastructure owners to align on risk treatment plans and mitigation strategies.
- Map data flows for all onchain services, documenting trust boundaries, trust assumptions, and data integrity requirements.
- Perform evaluations of vendor and third-party integrations, verifying that financial interfaces meet strict resilience and security expectations.
- Maintain and update runbooks for incident response, ensuring clarity and procedural accuracy during events affecting critical financial systems.
- Translate complex protocol specifications and change proposals into actionable security controls for financial operations.
- Implement infrastructure as code patterns and configuration management to harden secure deployment pipelines against tampering.
- Coordinate security testing schedules and remediation tracking across engineering teams to reduce time-to-resolution for vulnerabilities.
- Define metrics and reporting frameworks to measure the effectiveness of security controls and risk mitigation efforts.
- Evaluate emerging threats in the onchain ecosystem and adapt detection rules accordingly to protect digital assets.
- Collaborate with compliance and risk stakeholders to ensure security frameworks align with regulatory expectations for traditional and digital asset management.
Requirements
- Possess a minimum of three years of professional experience in security or risk-oriented engineering roles.
- Hold hands-on experience with public blockchain transaction models and common smart contract vulnerability classes.
- Demonstrate the ability to assess cryptographic signing systems and key management architectures.
- Show proficiency in reading and interpreting protocol specifications and change proposals that impact financial operations.
- Exhibit comfort with infrastructure as code patterns and configuration management for secure deployment pipelines.
- Maintain a strong understanding of threat modeling techniques applied to financial systems and digital asset custody solutions.
- Communicate effectively with both technical and non-technical stakeholders to align on risk acceptance and treatment plans.
- Adhere to strict documentation standards for security policies, controls, and audit artifacts to ensure clarity during assessments.
Nice to have
Prior experience with formal audit processes and collaboration with external security assessors is preferred.
Skills & Tools
Security frameworks, Public blockchain, Cryptographic signing, Key management, Incident response, Risk assessment.
Practical notes
Location is New York.
Engagement is Full Time.
Compensation is $180,000 base salary per year.
No details on visa sponsorship, hours, travel, or application deadlines were provided in the source material.