ai analyst backend bitcoin blockchain community manager crypto cryptography cto customer support dao data science defi design developer relations devops discord economy designer entry level erc erc 20 evm front end full stack gaming ganache golang hardhat intern java javascript layer 2 marketing mobile moderator nft node non tech open source openzeppelin pay in crypto product manager project manager react refi research ruby rust sales smart contract solana solidity truffle web3 py web3js zero knowledge
| Job Position | Company | Posted | Location | Salary | Tags |
|---|---|---|---|---|---|
Anchorage Digital | United States | $86k - $117k | |||
Anchorage Digital | Porto, Portugal | $68k - $90k | |||
Anchorage Digital | United States | $68k - $90k | |||
Old Harmony | Palo Alto, CA, United States | $102k - $109k | |||
| Learn job-ready web3 skills on your schedule with 1-on-1 support & get a job, or your money back. | | by Metana Bootcamp Info | |||
Binance | South East Asia |
| |||
Solana Foundation | Remote | $77k - $90k | |||
Inmobi | Remote | $88k - $95k | |||
Inmobi | Remote |
| |||
Bitpanda | Remote | $90k - $112k | |||
Bitpanda | Remote | $105k - $117k | |||
Bitpanda | Remote | $117k - $122k | |||
Bitpanda | Remote | $79k - $112k | |||
Polymarket | New York, NY, United States | $84k - $100k | |||
Polymarket | New York, NY, United States | $80k - $92k | |||
Blockchain | Remote | $71k - $102k |
Anchorage Digital
$86k - $117k estimated
Member of the Technical Staff, Security Operations
United States
Engineering – Security Engineering /
Full-Time - Remote /
Remote
Apply for this job
Founded in 2017, Anchorage Digital is a regulated crypto platform that provides institutions with integrated financial services and infrastructure solutions. With the first federally chartered crypto bank in the US, Anchorage Digital offers institutions an unparalleled combination of secure custody, regulatory compliance, product breadth, and client service. We’re looking to diversify our team with people who are humble, creative, and eager to learn.
We are a remote friendly, global team, but provide the option of working in-office in New York City, Sioux Falls, Porto, Lisbon, and Singapore. For our colleagues not located near our beautiful offices, we encourage and sponsor quarterly in-person collaboration days to work together and further deepen our Village
The Security Operations team develops hardware and software solutions designed to establish and test security guardrails across the code, cloud resources, and hardware infrastructure of the Anchorage platform. By managing vulnerabilities in both in-house and third-party components, the team partners with service owners to secure networking and infrastructure while continuously monitoring for anomalies or unexpected configuration changes. To enhance efficiency, they strategically automate investigation tasks, threat isolation, inventory management, and assurance provision for regulated entities, all while conducting rigorous static and dynamic testing of application interfaces throughout the organization.
We have created the Factors of Growth & Impact to help Villagers better measure impact and articulate coaching, feedback, and the rich and rewarding learning that happens while exploring, developing, and mastering the capabilities and contributions within and outside of the Security Operations position.
Technical Skills:
- Build and maintain security automation and tooling to detect vulnerabilities through static and dynamic analysis across code and live systems.
- Conduct application security assessments, penetration tests, and code reviews to identify high-risk security issues and provide secure development guidance.
- Develop and operate vulnerability management workflows, partnering with engineering teams to prioritize and remediate findings.
- Establish and test security guardrails for code, cloud resources, and infrastructure components throughout the Anchorage platform.
Complexity and Impact of Work:
- Monitor and respond to security events and configuration anomalies across the organization, leading investigation and containment efforts.
- Manage the full vulnerability lifecycle from discovery through remediation, tracking progress and ensuring timely closure of findings.
- Lead or substantially contribute to Security Operations initiatives with minimal oversight, coordinating across team boundaries to drive projects to completion.
- Break complex security problems into manageable workstreams with accurate scope and time estimates. Present options clearly and provide well-reasoned priority recommendations.
- Deliver assurance artifacts and evidence for regulated entity requirements, supporting audit and compliance efforts.
- Balance speed of response with thoroughness of investigation, adapting approach based on risk and business impact.
Organizational Knowledge:
- Understand and help implement the company's security strategy by participating in planning and defining Security Operations goals in alignment with Anchorage Digital's overall objectives.
- Stay alert to emerging threats, vulnerabilities, and industry trends that could affect organizational security posture.
- Consider security holistically across the product ecosystem—applications, infrastructure, and third-party integrations—while fostering a security-first culture.
- Collaborate cross-functionally with Engineering, Infrastructure, and Compliance teams to embed security into development and operational processes.
Communication and Influence
- Share knowledge broadly across the team through documentation, runbooks, and post-incident reviews, preventing single points of failure.
- Partner with engineering teams to explain security risks and remediation approaches, translating technical findings into actionable guidance.
- Collaborate across teams to review security configurations, triage findings, and engage in technical discussions. Communicate insights and recommendations clearly to improve processes.
- Demonstrate empathy by understanding others' context, priorities, and constraints—adapting communication >
You may be a fit for this role if you have:
- Security Operations or AppSec experience: You have 3+ years of hands-on experience in security engineering, application security, penetration testing, or security operations.
- Security tooling and automation: You have built or maintained security tools, integrations, or automation workflows using Python, Go, or similar languages.
- Vulnerability assessment: You can identify and assess security vulnerabilities in applications, APIs, and cloud infrastructure, and effectively communicate remediation strategies.
- Static and dynamic analysis: You have experience with tools like Semgrep, CodeQL, Burp Suite, or equivalent for identifying security issues in code and running systems.
- Cloud security: You understand AWS security fundamentals including IAM, VPCs, security groups, and CloudTrail/logging.
- Incident response: You can investigate security events, perform root cause analysis, and coordinate response efforts.
- You have developed "computer science fundamentals," i.e. concurrency, algorithms, and data structures.
- You genuinely care about code quality and operational excellence.
- You prioritize security outcomes, end-user experience, and business value over "cool tech."
- You self-describe as some combination of the following: creative, humble, ambitious, detail-oriented, hardworking, trustworthy, eager to learn, methodical, action-oriented, and tenacious.
Although not a requirement, bonus points if:
- You have experience running or participating in bug bounty programs (HackerOne, Bugcrowd, etc.).
- You have worked in a regulated financial services, fintech, or crypto environment.
- You have exposure to blockchain security, smart contract auditing, or Web3 technologies.
- You have built or contributed to open-source security tools.
- You hold relevant certifications (OSCP, GWAPT, GCIH, AWS Security Specialty, etc.).
- You read blockchain protocol white papers for fun, and stay up to date with the proliferation of crypto-asset innovations.
- You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system. :)
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Apply for this job