1 day ago
Denver, CO, USA or New York, NY, USASenior / Staff+
Responsibilities
- Own security operations, including monitoring, alerting, triage, incident response, and endpoint detection and response.
- Manage identity lifecycle processes, including onboarding, offboarding, access provisioning, key rotation, and deprovisioning.
- Own the ImmuneFi bug bounty program by triaging, reproducing, and responding to submissions.
- Prioritize vulnerabilities and collaborate with protocol and engineering teams through remediation.
- Develop internal tooling and processes to improve bug bounty workflow consistency and speed.
- Audit and harden CI/CD pipelines, including secrets management, supply-chain integrity, SAST/DAST integration, and build provenance.
- Identify and remediate vulnerable dependencies across repositories.
- Establish security standards across the software development lifecycle.
- Review and harden cloud environments through access controls, network segmentation, least privilege, and logging.
- Contribute to threat modeling and drive security-tooling implementation across the technology stack.
- Manage external security vendors and service providers, including scope, SLAs, and remediation of findings.
Requirements
- 5–8+ years of experience in software and security engineering, including meaningful experience in DevSecOps or security operations.
- Strong software engineering fundamentals and the ability to write production code and internal tooling.
- Hands-on experience hardening CI/CD pipelines using GitHub Actions, CircleCI, or similar tools.
- Hands-on experience securing cloud infrastructure using AWS, GCP, or equivalent.
- Proficiency with endpoint security tooling such as CrowdStrike or equivalent EDR systems.
- Experience owning identity and access management processes, including onboarding and offboarding workflows.
- Strong written and verbal communication skills for triage reports, developer feedback, and explaining risk to non-technical stakeholders.
- Prior software engineering experience before specializing in security is preferred.
- Experience at a DeFi protocol, crypto exchange, or blockchain infrastructure company is preferred.
- CTF or security competition experience is preferred.
- Contributions to open-source security tooling are preferred.
Benefits
- The role requires working in the office every day; it is not remote.
- The position offers direct ownership of security operations and close collaboration with infrastructure, protocol, and platform engineering teams.
Tech Stack
Categories
About Ether.fi
At ether.fi, our mission is to put you in charge of your wealth. Save, grow and spend your crypto. Our team is in it for the long haul, dedicated to making crypto accessible and approachable, and to help people reach their goals through a full suite of products.
