Skip to content
Ether.FiEther.Fi

Security Engineer

Hands-on security engineer responsible for security operations, bug bounty and vulnerability management, DevSecOps pipeline hardening, cloud security, and identity management. Requires 5+ years of software and security engineering experience and strong coding fundamentals.

About the job

Responsibilities

Security Operations

  • Own day-to-day security operations, including monitoring, alerting, triage, and incident response.
  • Manage endpoint security through an EDR system; tune detections, investigate alerts, and drive incidents to resolution.
  • Lead identity lifecycle management, including onboarding, offboarding, access provisioning, key rotation, and deprovisioning.

Bug Bounty and Vulnerability Management

  • Own the ImmuneFi program by triaging, reproducing, and responding to submissions.
  • Prioritize and track vulnerabilities through remediation with protocol and engineering teams.
  • Develop internal tooling and processes to improve the speed and consistency of bounty workflows.

DevSecOps and Pipeline Hardening

  • Audit and harden CI/CD pipelines, including secrets management, supply-chain integrity, SAST/DAST integration, and build provenance.
  • Identify and remediate vulnerable dependencies across repositories.
  • Establish and enforce security standards across the software development lifecycle.

Infrastructure Security

  • Review and harden cloud environments, including access controls, network segmentation, least privilege, and logging.
  • Contribute to threat modeling for new systems and architectural changes.
  • Drive implementation of security tooling across the technology stack.

Vendor Management

  • Manage relationships with external security vendors and service providers, including SLAs, scope, and remediation follow-through.
  • Evaluate and onboard security tools as the team and threat landscape evolve.

Requirements

  • 5–8+ years of experience in software and security engineering, including meaningful DevSecOps or security operations experience.
  • Strong software engineering fundamentals and the ability to write production code.
  • Hands-on experience hardening CI/CD pipelines using GitHub Actions, CircleCI, or similar tools.
  • Experience securing cloud infrastructure such as AWS, GCP, or equivalent platforms.
  • Proficiency with endpoint security tooling such as CrowdStrike or an equivalent EDR.
  • Experience owning identity and access management processes, including onboarding and offboarding workflows.
  • Strong written and verbal communication skills, including triage reporting, developer feedback, and explaining risk to non-technical stakeholders.

Nice to Have

  • Prior experience as a software engineer before specializing in security.
  • Experience at a DeFi protocol, cryptocurrency exchange, or blockchain infrastructure company.
  • CTF or security competition experience.
  • Contributions to open-source security tooling.

Skills

CI/CD, GitHub Actions, CircleCI, AWS, GCP, Crowdstrike, Edr, Identity And Access Management, SAST, DAST, Threat Modeling, Vulnerability Management, Incident Response, Immunefi

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

hud

hud

San Francisco, CA

Security Engineer
No salary listedOn-siteSecurity Engineering

Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.

Stripe

Stripe

United States

Abuse Research Engineer
No salary listedRemote5+ YOESecurity Engineering

Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Offensive Security
$300k+/yrHybrid5+ YOESecurity Engineering

Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.