Security Engineer

ether.fi

New York (NY)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading fintech company in New York is seeking a Security Engineer to oversee security operations, manage bug bounty programs, and enhance CI/CD pipeline security. The ideal candidate has 5–8+ years of experience, strong software engineering skills, and proficiency with endpoint security tools. The role is on-site and involves collaborating closely with engineering and infrastructure teams. A builder-first mindset and excellent communication skills are critical for success in this position.

Qualifications

  • 5–8+ years of experience in software and security engineering.
  • Hands-on experience hardening CI/CD pipelines and cloud infrastructure.
  • Strong communication skills for technical and non-technical stakeholders.

Responsibilities

  • Own day-to-day security operations including monitoring and response.
  • Manage endpoint security via EDR system.
  • Lead identity lifecycle management processes.
  • Be the primary owner of the ImmuneFi bug bounty program.
  • Audit and harden CI/CD pipelines.
  • Partner with infrastructure teams to harden cloud environments.

Skills

Software engineering fundamentals
Experience in DevSecOps
Cloud infrastructure experience
Endpoint security tooling proficiency
Identity and access management
Strong communication skills

Tools

CrowdStrike EDR
GitHub Actions
CircleCI

Job description

Location

Cayman; Denver; New York

Employment Type

Full time

Location Type

On-site

Department

Engineering

About the Role:

We're looking for a Security Engineer who is equally at home hardening a CI/CD pipeline, reviewing a change to the authentication system on the backend, and triaging a bug bounty submission before lunch. This is a hands‑on, builder‑first role — not a governance checkbox. You'll own security operations end‑to‑end, embedded directly into the engineering team and working closely with infrastructure, protocol and platform.

If you treat threat modeling as a design conversation and not a compliance exercise, you're our kind of person.

You should only apply for this role if you are ready to come into the office every day and work in person with our team!

What You'll Do:

Security Operations

Own day‑to‑day security operations: monitoring, alerting, triage, and response

Manage and monitor endpoint security via an EDR system — tune detections, investigate alerts, and drive incidents to resolution

Lead identity lifecycle management, including employee onboarding and off boarding (access provisioning, key rotation, deprovisioning)

Bug Bounty & Vulnerability Management

Be the primary owner of our ImmuneFi program — triaging, reproducing, and responding to incoming submissions daily

Prioritize and track vulnerabilities through to remediation in close collaboration with protocol and engineering teams

Develop internal tooling and processes to make the bounty workflow faster and more consistent

DevSecOps & Pipeline Hardening

Audit and harden CI/CD pipelines — secrets management, supply chain integrity, SAST/DAST integration, build provenance

Own dependency security: identify and remediate vulnerable packages across repositories (yes, including the npm dependency hell)

Establish and enforce security standards across the SDLC

Infrastructure Security

Partner with the infrastructure team to review and harden cloud environments (access controls, network segmentation, least privilege, logging)

Contribute to threat modeling for new systems and architectural changes

Drive implementation of security tooling across the stack

Vendor & External Partner Management

Own relationships with external security vendors and service providers — holding them accountable toSLAs, managing scope, and ensuring findings are actioned

Evaluate and onboard new security tooling as the team and threat landscape evolve

What We're Looking For:

5–8+ years of experience in software and security engineering, with meaningful time in a DevSecOps or security operations context

Strong software engineering fundamentals — you're a builder who writes code, not just policy

Hands‑on experience hardening CI/CD pipelines (GitHub Actions, CircleCI, or similar) and cloud infrastructure (AWS, GCP, or equivalent)

Proficiency with endpoint security tooling (CrowdStrike or equivalent EDR)

Comfort owning identity and access management processes, including onboarding/offboarding workflows

Strong communication skills — you can write a clear triage report, give direct feedback to a developer and explain risk to a non‑technical stakeholder

Nice to Have:

You were a traditional software engineer before specializing in security

Prior experience at a DeFi protocol, crypto exchange, or blockchain infrastructure company

CTF/security competition background

Contributions to open‑source security tooling

What Success Looks Like:

In your first 90 days, you've mapped our attack surface, established a daily rhythm on ImmuneFi, and shipped at least a few meaningful PRs across the full stack. Within six months, you've built enough trust in the team that engineers come to you before shipping sensitive PRs, not after.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineer, Security
Software Engineer, Security

XOXO AI Inc. • San Francisco (CA)

On-site
USD 250,000 - 500,000
Health, dental, vision benefits
Equity between 1% and 5%
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Security Engineer
Security Engineer

factory • San Francisco (CA)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Security Software Engineer, Open Source Frameworks
Security Software Engineer, Open Source Frameworks

United States Digital Space LLC • San Francisco (CA)

Hybrid
USD 155,000 - 190,000
Competitive compensation
Equity
Healthcare package
Staff Software Engineer, Security
Staff Software Engineer, Security

XOXO AI Inc. • San Francisco (CA)

On-site
USD 250,000 - 500,000
Health benefits
Dental benefits
Vision benefits
Security Engineer
Security Engineer

Liberty Personnel Services, Inc. • Feasterville-Trevose

Hybrid
USD 90,000 - 120,000
Security Engineer, Privy
Security Engineer, Privy

United States Digital Space LLC • New York (NY)

On-site
USD 120,000 - 190,000
Security Engineer
Security Engineer

MLabs • Austin (TX)

On-site
USD 150,000 - 175,000
Direct mentorship from a CISO
Significant organizational investment
Autonomy in tool selection
Staff Security Engineer (Product Security and Architecture)
Staff Security Engineer (Product Security and Architecture)

Compass • Ventura (CA)

On-site
USD 150,000 - 230,000