Staff Application Security Engineer (Web3)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Staff Application Security Engineer (Web3): Leading technical strategy to secure critical attack surfaces including on-chain, exchange, and credit card systems with an accent on AI-driven security tooling and agentic SDLC. Focus on designing automated threat modeling, secure code generation, and performing high-risk architecture reviews.
Location: Must be based in the United States (Hybrid in New York or Miami, or Remote within the US).
Salary: $168,000–$240,000 (Base salary in New York State).
Company
A global crypto and Web3 platform bridging traditional finance with the emerging cryptoeconomy.
What you will do
- Own and evolve secure software development lifecycle guardrails as a subject matter expert.
- Lead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk services.
- Design and build AI agents to automate threat modeling and secure code review processes.
- Deliver hands-on application security training to engineering teams at scale.
- Participate in on-call rotations and lead post-incident hardening efforts.
Requirements
- Must be based in the United States.
- 7-10+ years of experience in application or product security.
- Deep proficiency in Scala, Java, or Go, with hands-on experience in Python or Go for tooling.
- Strong background in application security best practices and common vulnerabilities.
- Experience working in highly regulated environments like fintech or crypto.
- Strong cross-functional communication skills.
Nice to have
- Experience building AI application security tooling using agents.
- Knowledge of supply chain security frameworks like SLSA or OWASP SPVS.
- Experience with microservice architectures and cloud-native environments.
Culture & Benefits
- Competitive base pay with discretionary annual bonus and equity grants.
- Comprehensive health plans and 401K with company matching.
- Paid parental leave and flexible time off.
- Hybrid work approach at hub offices with remote flexibility.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →