Security Engineer

Ether.fi

Denver (CO)

On-site

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ether.fi is seeking a Security Engineer to own security operations end-to-end, embedded with the engineering team. You will harden CI/CD pipelines, review authentication changes, and triage bug bounty submissions daily, working in person in Denver with the team.

You’ll drive vulnerability management, threat modeling, and security tooling adoption across the stack, collaborating with infrastructure and protocol engineers as security concerns arise.

Qualifications

  • 5–8+ years of experience in software and security engineering.
  • Hands-on experience hardening CI/CD pipelines and cloud infrastructure.
  • Proficiency with endpoint security tooling.
  • Comfort owning identity and access management processes.
  • Strong communication to explain risk to non-technical stakeholders.

Responsibilities

  • Own day-to-day security operations: monitoring, alerting, triage, and response.
  • Manage endpoint security via EDR and drive incidents to resolution.
  • Lead identity lifecycle management (onboarding/offboarding, key rotation).
  • Triage and respond to ImmuneFi bug bounty submissions daily.
  • Audit and harden CI/CD pipelines and enforce security standards across SDLC.

Skills

Software engineering fundamentals
DevSecOps
Cloud security
Endpoint security
IAM management
Threat modeling
Security operations

Tools

GitHub Actions
CircleCI
AWS
GCP
EDR tooling

Job description

About the Role:

We’re looking for a Security Engineer who is equally at home hardening a CI/CD pipeline, reviewing a change to the authentication system on the backend, and triaging a bug bounty submission before lunch.This is a hands-on, builder-first role — not a governance checkbox. You’ll own security operations end-to-end, embedded directly into the engineering team and working closely with infrastructure, protocol and platform.

If you treat threat modeling as a design conversation and not a compliance exercise, you’re our kind of person. You should only apply for this role if you are ready to come into the office every day and work in person with our team!

What You’ll Do:
Security Operations
  • Own day-to-day security operations: monitoring, alerting, triage, and response
  • Manage and monitor endpoint security via an EDR system — tune detections, investigate alerts, and drive incidents to resolution
  • Lead identity lifecycle management, including employee onboarding and off boarding (access provisioning, key rotation, deprovisioning)
Bug Bounty & Vulnerability Management
  • Be the primary owner of our ImmuneFi program — triaging, reproducing, and responding to incoming submissions daily
  • Prioritize and track vulnerabilities through to remediation in close collaboration with protocol and engineering teams
  • Develop internal tooling and processes to make the bounty workflow faster and more consistent
DevSecOps & Pipeline Hardening
  • Audit and harden CI/CD pipelines — secrets management, supply chain integrity, SAST/DAST integration, build provenance
  • Own dependency security: identify and remediate vulnerable packages across repositories (yes, including the npm dependency hell)
  • Establish and enforce security standards across the SDLC
Infrastructure Security
  • Partner with the infrastructure team to review and harden cloud environments (access controls, network segmentation, least privilege, logging)
  • Contribute to threat modeling for new systems and architectural changes
  • Drive implementation of security tooling across the stack
Vendor & External Partner Management
  • Own relationships with external security vendors and service providers — holding them accountable toSLAs, managing scope, and ensuring findings are actioned
  • Evaluate and onboard new security tooling as the team and threat landscape evolve
What We’re Looking For:

5–8+ years of experience in software and security engineering, with meaningful time in a DevSecOps or security operations context

  • Strong software engineering fundamentals — you’re a builder who writes code, not just policy
  • Hands‑on experience hardening CI/CD pipelines (GitHub Actions, CircleCI, or similar) and cloud infrastructure (AWS, GCP, or equivalent)
  • Proficiency with endpoint security tooling (CrowdStrike or equivalent EDR)
  • Comfort owning identity and access management processes, including onboarding/offboarding workflows
  • Strong communication skills — you can write a clear triage report, give direct feedback to a developer and explain risk to a non‑technical stakeholder
Nice to Have:
  • You were a traditional software engineer before specializing in security
  • Prior experience at a DeFi protocol, crypto exchange, or blockchain infrastructure company
  • CTF/security competition background
  • Contributions to open-source security tooling
What Success Looks Like:

In your first 90 days, you’ve mapped our attack surface, established a daily rhythm on ImmuneFi, and shipped at least a few meaningful PRs across the full stack. Within six months, you’ve built enough trust in the team that engineers come to you before shipping sensitive PRs, not after.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Piplabs • Palo Alto (CA)

On-site
USD 140,000 - 190,000
Staff Software Engineer, Security
Staff Software Engineer, Security

XOXO AI Inc. • San Francisco (CA)

On-site
USD 250,000 - 500,000
Health benefits
Dental benefits
Vision benefits
Member of Technical Staff (Software Engineer, Security)
Member of Technical Staff (Software Engineer, Security)

Perplexity • California (MO)

On-site
USD 120,000 - 180,000
Security Engineer, Privy
Security Engineer, Privy

Socket.dev • New York (NY)

On-site
USD 140,000 - 190,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Security Engineer
Security Engineer

OP Recruiting • New York (NY)

On-site
USD 110,000 - 150,000
100% health benefits
Professional development budget
Weekly meal allowances
Security Engineer
Security Engineer

Stripe • New York (NY)

On-site
USD 120,000 - 160,000
Security Administrator
Security Administrator

Aegis AI • United States

On-site
USD 65,000 - 90,000
Senior Software Engineer, Security
Senior Software Engineer, Security

Flex • Northern (KY)

Hybrid
USD 170,000 - 230,000
Security Administrator
Security Administrator

aegis-ai • United States

On-site
USD 65,000 - 90,000