
Senior Security Engineer – Product Security
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in United States.
• Lead threat modeling efforts for new features, integrations, and architectural modifications across the product landscape.
• Oversee secure code reviews for significant changes related to authentication, session management, cryptographic paths, wallet and signing processes, RPC and third-party integrations, as well as permission and consent surfaces.
• Enhance and refine the AppSec tooling stack, focusing on minimizing false positives and facilitating AI-native integrations.
• Design and advance the secure Software Development Life Cycle (SDLC), incorporating security workflow integration, review triggers, security approvals, and control validation.
• Manage the responsible disclosure and bug bounty program, which includes defining scope, triaging reports, making payout decisions, and tracking remediation efforts.
• Support and take ownership of the intake and resolution of findings from external audits and penetration tests, coordinating with audit vendors and engineering teams.
• Collaborate with engineering leads on secure-by-default libraries, templates, defaults, and paved-road implementations.
• Threat model components integrated with blockchain, such as wallet processes, RPC integrations, signing infrastructure, and on-chain administrative actions initiated by off-chain systems.
• Participate in hiring, mentoring, and elevating the technical standards within the Security team.
• A minimum of 5 years in Product Security or Application Security, with senior individual contributor experience in a dynamic product company.
• Proficient in secure code review for at least one programming language: TypeScript/JavaScript, Python, or Go.
• Capability to navigate across technology stacks as needed for threat modeling.
• Strong skills in threat modeling, including the application of industry-relevant tactics, techniques, and procedures (TTPs) and indicators of compromise (IoCs) to products.
• Practical experience in owning or significantly contributing to an AppSec tooling program, including deploying rules, reducing noise, and measuring impact.
• Experience in managing or developing a bug bounty/responsible disclosure program from start to finish.
• Solid understanding of modern web and API security, covering session and authentication flows, OAuth, OIDC, the browser security model, and web/API vulnerability classes.
• Ability to interpret Terraform, cloud IAM policies, and CI/CD configurations to evaluate product vulnerabilities and infrastructure risks.
• Strong partnership skills in engineering and the capability to make and document risk-control decisions.
• Openness to grow into blockchain-related product security, including wallet, signing, and on-chain integration attack surfaces.
• By Day 1, possess a solid understanding of how blockchains uniquely influence product security experiences, familiarity with common terminology, and the ability to engage in discussions about relevant Web2-to-Web3 incident analyses.
• Previous experience with a cryptocurrency, fintech, or high-stakes/irreversible-action organization.
• Knowledge of wallet, signing, or key management processes.
• Reading-level familiarity with Solidity or Rust.
• A history of bug bounty contributions, including reports, CVEs, or published write-ups.
• Familiarity with browser-extension security, mobile application security, or account-abstraction wallet designs.
• Public contributions such as presentations, blog articles, open-source tools, or CVEs.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Generous paid time off and flexible working arrangements.
• Opportunities for professional development and career growth.
• Engaging and collaborative work environment.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.