Senior Security Engineer – Product Security

🔥 il y a 3 heures

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Ondo Finance

Ondo Finance

51 - 200 employés

₿ Crypto

💳 Fintech

💸 Finance

💰 Initial Coin Offering - Ondo Finance en 2024-01

Crypto • Fintech • Finance

Ondo est une entreprise spécialisée dans la création d'une infrastructure financière onchain de niveau institutionnel et de produits qui connectent la finance traditionnelle (TradFi) à la finance décentralisée (DeFi). Ses offres incluent des valeurs mobilières publiques tokenisées (Ondo Stocks) qui rendent ces valeurs librement transférables et utilisables dans la DeFi, USDY (un stablecoin à rendement sans permission), et OUSG (un produit institutionnel offrant une exposition aux bons du Trésor américain à court terme avec une émission et un rachat instantanés 24/7). Ondo met l'accent sur la conformité, une sécurité de niveau institutionnel, des audits tiers, et des partenariats avec des gestionnaires d'actifs et des prestataires de services régulés. La technologie Nexus de l'entreprise permet l'émission et le rachat instantanés pour les bons du Trésor américains et les stablecoins tokenisés, et soutient l'émission et la distribution omnichain. Ondo collabore avec des partenaires tels que Broadridge, J. P. Morgan, Mastercard, Ripple, et des gestionnaires d'actifs pour apporter des capacités de vote et de rachat transfrontalier aux actifs tokenisés.

Description

• Drive threat modeling for new features, integrations, and architectural changes across the product surface • Own secure code review for high-risk changes involving authentication, session management, cryptographic paths, wallet and signing flows, RPC and third-party integrations, and permission and consent surfaces • Expand and tune the AppSec tooling stack, including reducing false positives and supporting AI-native integrations • Design and evolve the secure SDLC, including security workflow integration, review triggers, security sign-offs, and control validation • Run the responsible disclosure and bug bounty program, including scope-setting, report triage, payout decisions, and remediation tracking • Support and own intake and closure of findings from external audits and penetration tests; coordinate with audit vendors and engineering owners • Partner with engineering leads on secure-by-default libraries, templates, defaults, and paved-road implementations • Threat model blockchain-integrated components such as wallet flows, RPC integrations, signing infrastructure, and on-chain admin actions triggered by off-chain systems • Contribute to hiring, mentoring, and raising the technical bar on the Security team

🎯 Exigences

• 5+ years in Product Security or Application Security, including senior IC experience at a fast-moving product company • Deep secure code review skills in at least one of TypeScript/JavaScript, Python, or Go • Ability to move across technology stacks at the level required to threat model • Strong threat modeling skills, including applying industry-relevant TTPs and IoCs to products • Practical experience owning or majorly contributing to an AppSec tooling program; shipping rules, tuning noise, and measuring impact • Experience running or building a bug bounty/responsible disclosure program end-to-end • Strong working knowledge of modern web and API security, including session and authentication flows, OAuth, OIDC, browser security model, and web/API vulnerability classes • Ability to read Terraform, cloud IAM policies, and CI/CD configuration to assess product vulnerabilities and infrastructure risk • Strong engineering partnership skills and ability to make and document risk-control decisions • Willingness to grow into blockchain-adjacent product security, including wallet, signing, and on-chain integration attack surfaces • By Day 1, strong intuitions about how blockchains make product security experiences unique, knowledge of common terminology, and ability to discuss relevant Web2-to-Web3 incident post-mortems • Prior work at a crypto, fintech, or high-value/irreversible-action company • Familiarity with wallet, signing, or key-management flows • Reading-level familiarity with Solidity or Rust • Bug bounty history, such as reports, CVEs, or published write-ups • Familiarity with browser-extension security, mobile app security, or account-abstraction wallet designs • Public output such as talks, blog posts, open-source tools, or CVEs

Postuler Maintenant

Emplois Similaires

🔥 il y a 3 heures

Experian

10 000+ employés

💼 Conseil

📣 Marketing

📦 Logistique

Senior incident manager commanding Experian's enterprise cybersecurity response. Leading investigations, executive communications, recovery, and cyber-resilience improvements across global data and technology operations.

🗣️🇺🇸🇬🇧 Anglais requis

Cloud

Cyber Security

🔥 il y a 5 heures

Curtiss-Wright Corporation

5001 - 10000

🏭 Fabrication

💼 Conseil

🚀 Aérospatiale

Senior SAP Security Lead managing S/4HANA roles, access controls, audits, and compliance for Curtiss-Wright’s diversified industrial technology business. Advising executives and supporting secure SAP operations across landscapes.

🇺🇸 États-Unis – Télétravail

💵 $144 100 - $192 100 / an

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

ITSM

🔥 il y a 7 heures

Illumination Works

51 - 200

💼 Conseil

📦 Logistique

📣 Marketing

Information System Security Officer supporting Illumination Works’ data and cloud technology solutions. Managing DoD RMF, ATO, FISCAM audit readiness, continuous monitoring, and enterprise finance-system security controls.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

AWS

Azure

Cloud

Cyber Security

🔥 il y a 9 heures

Zepz

501 - 1000

💳 Fintech

👥 B2C

Senior Security Engineer scaling incident response and vulnerability management for Zepz, powering WorldRemit and Sendwave cross-border payments. Automating SIEM workflows and strengthening security operations across cloud and containerized environments.

🇺🇸 États-Unis – Télétravail

💰 €165 000 000 Debt Financing - Zepz en 2025-03

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Cloud

Cyber Security

Terraform

🔥 il y a 11 heures

MoneyGram

1001 - 5000

💳 Fintech

₿ Crypto

👥 B2C

Senior cybersecurity GRC leader modernizing governance, risk, compliance, and resilience programs at MoneyGram. Scaling automation and global teams for a regulated fintech organization.

🇺🇸 États-Unis – Télétravail

💰 Corporate round en 2023-09

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis