Security Engineer, Privy

United States Digital Space LLC

New York (NY)

On-site

USD 120,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Privy is seeking a Security Engineer to help keep a rapidly growing platform secure through hands-on investigation, on-call rotation, and building production-grade tooling. You will partner with engineering, security, and product teams to detect threats and automate responses across cloud environments.

The ideal candidate has strong Python/Go/Ruby skills, experience with AWS or GCP, and a proactive, independent approach to solving complex security problems in a fast-paced startup setting.

Qualifications

  • Experience as a security engineer, detection engineer, or similarly hands-on engineer in a technically demanding environment.
  • Strong software-engineering skills in Python, Go, Ruby, or a similar language with ability to build maintainable tooling.
  • Experience investigating security signals, incidents, vulnerabilities, or anomalous activity through to resolution.
  • Familiarity with security operations, incident response, vulnerability management, and access reviews.
  • Solid understanding of web, browser, infrastructure, or cloud security and practical application.
  • Good judgment under pressure with an independent, methodical investigative approach.
  • Strong communication and collaboration skills to explain risks and actions clearly

Responsibilities

  • Own security engineering work end to end: investigate alerts, findings, anomalies, and security requests; identify root causes; drive remediation; document outcomes.
  • Participate in security-on-call rotation; respond to incidents, triage alerts, support vulnerability workflows, complete access reviews, and handle escalations.
  • Build and maintain production-quality tooling to reduce manual work: alert enrichment, automated triage, remediation workflows, and access-review automation.
  • Lead focused investigations into suspected security events or compromises, gathering evidence and coordinating response.
  • Identify recurring sources of toil and engineer durable solutions to improve speed and scale.
  • Partner with product and engineering to assess risks and make practical security tradeoffs to deliver quickly with quality and soundness.

Skills

Security engineer
Python
Go
Ruby
Incident response
Detection engineering
Cloud security
Communication

Tools

AWS
GCP
CI/CD tooling

Job description

Who we are
About Privy

Our mission is to make privacy and user ownership the default online. To do so, we build simple, flexible APIs and tools for developers that make it easy to build new products on crypto rails.

Privy owns the abstractions and infrastructure layer above wallets, integrating across chains, third-party providers, and the company products like Treasury and Link. We get to solve hard technical problems while leveraging the company's distribution to reach customers like Ramp, Klarna, Deel, Kraken, Hyperliquid, and Fomo - powering experiences for both mainstream users and crypto natives.

Learn more about Privy: Privy and the company: Bringing crypto to everyone

About the team

Engineering at Privy is distinguished by:

  • High urgency: Shipping very small iterations, very fast, to learn very quickly.
  • Product taste: Our customers are developers, and to build effective products for them requires technical knowledge - you will often be "the PM".
  • Security mindset: A great portion of our product is trust. While we have a dedicated security team, every engineer brings security to their designs from the start.

In practice, we use boring technology like Node, React, and AWS so we can focus our engineering energy entirely on pushing the boundaries of Privys core product, e.g. through hardware enclaves, multi-region low latency APIs, and blockchain abstractions that are accessible to mainstream developers.

What you'll do

As a Security Engineer at Privy, you will help keep a rapidly growing platform secure through hands-on investigation, operational ownership, and building real code to solve real problems. You'll work across security operations, incident response, application and infrastructure security, and internal tooling.

This is not a role limited to reviewing logs and designs or simply escalating findings. You will carry real ownership for the day-to-day work that protects Privys: investigating anomalies, improving security workflows, and building the automation that makes the team faster and more effective over time. You'll work closely with engineers across Privy and alongside specialists in cryptography, application security, offensive security, and infrastructure security to turn security expertise into practical, durable outcomes.

Responsibilities
  • Own security engineering work end to end: investigate alerts, findings, anomalies, and security requests; identify root causes; drive remediation; and clearly document outcomes.
  • Participate in Privys security on-call rotation, helping respond to incidents, triage alerts, support vulnerability workflows, complete access reviews, and handle security escalations.
  • Build and maintain production-quality tooling that reduces manual work, including alert enrichment, automated triage and routing, remediation workflows, access-review automation, and detection improvements.
  • Lead focused investigations into suspected security events or compromises, gathering evidence methodically and coordinating the appropriate response.
  • Proactively identify recurring sources of operational toil and engineer durable solutions that improve the team’s speed, consistency, and ability to scale.
  • Partner with product and engineering teams to assess security risks, review lower-complexity designs and implementation plans, and make practical security tradeoffs to deliver quickly with quality and soundness.
  • Contribute across Privys application, infrastructure, cloud, and product-security surface area, developing broad context while building deeper expertise over time.
Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements
  • Experience as a security engineer, detection engineer, or similarly hands-on engineer in a technically demanding environment.
  • Strong software-engineering skills in Python, Go, Ruby, or a similar language. You can build maintainable tooling and contribute directly to production fixes, not only one-off scripts.
  • Experience investigating security signals, incidents, vulnerabilities, suspicious activity, or other ambiguous technical problems through to resolution.
  • Familiarity with security operations, incident response, vulnerability management, detection engineering, access reviews, or related operational-security workflows.
  • A strong understanding of web, browser, infrastructure, or cloud security, with the ability to apply that understanding across a broad range of problems.
  • Good judgment under pressure, a methodical approach to investigation, and comfort working independently with agency despite incomplete information.
  • Strong communication and collaboration skills, including the ability to explain technical findings, risks, and recommended actions clearly to clients and internal stakeholders alike.
  • A self-directed approach to work: you notice gaps, make progress through ambiguity, and reliably close the loop.
Preferred qualifications
  • Experience with AWS, GCP, or other cloud-security environments.
  • Experience with detection engineering, security automation, incident-response tooling, or remediation pipelines.
  • Bug-bounty experience, offensive-security exposure, or a strong attacker-mind approach to investigation.
  • Experience with IAM, secrets management, secure production access, or secure CI/CD.
  • Background in application security, infrastructure security, cryptography, or privacy engineering.
  • Experience with fintech, payments, blockchain, or another diligence-forward financial product domain.
  • Experience helping shape security operations, incident-response practices, vulnerability-management workflows, or a bug-bounty program.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Privy
Security Engineer, Privy

Socket.dev • New York (NY)

On-site
USD 140,000 - 190,000
Security Engineer
Security Engineer

Stripe • New York (NY)

On-site
USD 120,000 - 160,000
S Security Engineer, Privy Stripe via Greenhouse NYC-Privy 9001 privy - r&d View role
S Security Engineer, Privy Stripe via Greenhouse NYC-Privy 9001 privy - r&d View role

Nubeero Limited • New York (NY)

On-site
USD 120,000 - 180,000
Security Engineer, Privy
Security Engineer, Privy

EngineersOfAI • New York (NY)

On-site
USD 140,000 - 190,000
Forward Deployed Engineer, Privy
Forward Deployed Engineer, Privy

Stripe • Town of Virgil (NY)

On-site
USD 100,000 - 130,000
Forward Deployed Engineer, Privy
Forward Deployed Engineer, Privy

Stripe • New York (NY)

On-site
USD 120,000 - 150,000
S Forward Deployed Engineer, Privy Stripe via Greenhouse New York Privy HQ 9001 privy - r&d View role
S Forward Deployed Engineer, Privy Stripe via Greenhouse New York Privy HQ 9001 privy - r&d View role

Nubeero Limited • New York (NY)

On-site
USD 120,000 - 170,000
Forward Deployed Engineer, Privy
Forward Deployed Engineer, Privy

Stripe • New York (NY)

On-site
USD 120,000 - 160,000
Security Engineer: Build Secure, Automated Crypto APIs
Security Engineer: Build Secure, Automated Crypto APIs

EngineersOfAI • New York (NY)

On-site
USD 140,000 - 190,000
Forward Deployed Engineer
Forward Deployed Engineer

Stripe • New York (NY)

On-site
USD 190,000 - 286,000
Equity
401(k) plan
Medical, dental, and vision benefits
+1