Engineering
Senior Security Engineer

We are looking for a hands-on Senior Full-Stack Security Engineer to build secure, reliable products for our cryptocurrency platform. This is not a security-operations-only role. You will work across backend services, web and mobile applications, cloud infrastructure, and developer tooling—shipping production code while strengthening security throughout the engineering lifecycle. You will use AI-assisted development and security tools to improve delivery speed, investigation, testing, and code quality, while independently verifying outputs for correctness and safety. Because our products involve customer funds, identity, payments, and trading, you will help establish strong controls for financial integrity, access management, monitoring, incident response, and recovery.
What will you do:
Design, build, test, deploy, and operate secure features across frontend, backend, APIs, data stores, and cloud infrastructure.
Lead secure architecture reviews, threat modeling, and risk assessments for new and existing systems.
Implement security controls in application code, CI/CD pipelines, cloud environments, containers, and Kubernetes.
Strengthen authentication, authorization, secrets management, encryption, audit trails, and data protection.
Identify and remediate vulnerabilities in web, mobile, API, and infrastructure components.
Build automated security tests, dependency and container scanning, secure deployment checks, and release guardrails.
Develop monitoring and alerts for suspicious activity, abnormal financial behavior, access violations, and system failures.
Lead or support incident investigation, containment, remediation, reconciliation, and post-incident improvement.
Use AI tools for software development, code review, test generation, threat analysis, documentation, and investigation.
What we are looking for:
5+ years of professional software engineering experience, with substantial responsibility for application or infrastructure security.
Strong backend development skills in at least one production language such as Go, Java, TypeScript, Python, or a comparable language.
Experience building modern web applications and integrating frontend clients with secure APIs.
Strong knowledge of API design, relational databases, distributed systems, and asynchronous processing.
Practical experience with AWS, GCP, or Azure, plus Docker, Kubernetes, and infrastructure-as-code.
Strong understanding of authentication, authorization, OWASP risks, encryption, secrets management, network security, and secure SDLC practices.
Experience with automated testing, CI/CD, observability, vulnerability management, and incident response.
Experience using AI coding assistants or agentic development tools in real engineering workflows.
Ability to identify hallucinations, insecure code, missing edge cases, and weak assumptions in AI-generated output.
Strong problem-solving, ownership, communication, and technical mentoring skills.
Plus Points If:
Experience in cryptocurrency, fintech, trading, payments, wallets, or other high-integrity financial systems.
Knowledge of blockchain systems, smart-contract risks, custody, wallet security, and transaction monitoring.
Familiarity with NIST, ISO 27001, CIS Controls, SOC 2, or comparable frameworks.
Experience with SIEM, SAST, DAST, CSPM, vulnerability scanners, penetration testing, and security automation.
Experience designing controls for idempotency, reconciliation, balance integrity, progressive rollout, and recovery.
Contributions to security tooling, open-source projects, technical writing, or responsible vulnerability disclosure.