Member of Technical Staff, Security Operations
Develops security automation, conducts vulnerability assessments, penetration tests, and manages security operations including incident response and cloud guardrails for a crypto platform. Requires 3+ years in security engineering with strong coding and AWS skills.
About the job
Responsibilities
- Build and maintain security automation and tooling to detect vulnerabilities through static and dynamic analysis across code and live systems.
- Conduct application security assessments, penetration tests, and code reviews to identify high-risk security issues and provide secure development guidance.
- Develop and operate vulnerability management workflows, partnering with engineering teams to prioritize and remediate findings.
- Establish and test security guardrails for code, cloud resources, and infrastructure components.
- Monitor and respond to security events and configuration anomalies, leading investigation and containment efforts.
- Manage the full vulnerability lifecycle from discovery through remediation.
- Lead Security Operations initiatives with minimal oversight.
- Deliver assurance artifacts for regulated entity requirements.
Requirements
- 3+ years of hands-on experience in security engineering, application security, penetration testing, or security operations.
- Experience building or maintaining security tools, integrations, or automation workflows using Python, Go, or similar.
- Proficiency in vulnerability assessment in applications, APIs, and cloud infrastructure.
- Experience with static and dynamic analysis tools like Semgrep, CodeQL, Burp Suite.
- AWS security fundamentals including IAM, VPCs, security groups, CloudTrail.
- Incident response skills: investigate events, root cause analysis.
- Computer science fundamentals (concurrency, algorithms, data structures).
Nice-to-Haves
- Experience with bug bounty programs (HackerOne, Bugcrowd).
- Regulated financial services, fintech, or crypto environment.
- Blockchain security, smart contract auditing, Web3 technologies.
- Open-source security tools contributions.
- Certifications (OSCP, GWAPT, GCIH, AWS Security Specialty).
Skills
Python, Go, Semgrep, Codeql, Burp Suite, AWS, IAM, Vpcs, Cloudtrail, Vulnerability Management
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.