
Engineering Lead – Security
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in United States.
• Take charge of security across Somnia, encompassing the infrastructure and operations that support the L1, the products and services developed by our teams, the policies and processes that dictate our workflow, and the multisig and key management safeguarding the protocol's most vital assets.
• Assist in establishing the security strategy and posture while actively contributing to the efforts—strengthening infrastructure, outlining incident response protocols, securing signing and treasury operations, and elevating standards across the team.
• Approach security as a facilitator of speed rather than an obstacle, leveraging AI as an enhancement tool.
• Develop and implement the policies and standards that regulate the organization—covering access control, secrets management, secure SDLC, change management, and compliance preparedness. These should be practical enough for engineers to adhere to them.
• Champion application and supply-chain security for Somnia's offerings—implementing secure-by-default patterns, conducting dependency and build-pipeline scans in CI, and performing security reviews in high-stakes scenarios.
• Design and manage multisig governance, signing ceremonies, and the key lifecycle for treasury, upgrades, and privileged operations. Ensure there are no single points of failure and that everything is auditable.
• Create and lead the security incident-response framework—encompassing detection, triage, containment, blameless postmortems—and facilitate tabletop exercises.
• Maintain a hands-on approach—engaging in threat modeling, security reviews, and red-team drills—while coordinating external audits and bug bounty programs to elevate security standards throughout the company.
• Extensive experience in security engineering, with profound expertise in infrastructure security and SecOps at scale, complemented by a broad understanding of application security to enhance product teams.
• Practical experience in securing and managing production systems, including Linux internals, networking, containers/Kubernetes, and Infrastructure as Code (IaC).
• Proven ability to define and implement security policies that an engineering organization actively adopts.
• In-depth key management experience: workflows for signing, hardware security modules (HSMs), secrets management, and key generation/rotation/recovery.
• Strong leadership skills in incident response: detection, containment, forensics, and conducting postmortems.
• Fundamental knowledge of cryptography as it relates to blockchain and key management.
• Senior-level accountability and decision-making; excellent communication skills with the ability to influence without direct authority.
• Comfortable working in high-pressure environments, particularly in financial systems dealing with real money—where errors can be costly and public, and this pressure should be manageable for you.
• A genuine interest in cryptocurrency and on-chain systems.
• Competitive compensation package with token incentives.
Sigma Software Group
Collectly
Allata
Get handpicked remote jobs straight to your inbox weekly.