Skip to main content
Ondo Finance

Senior Security Engineer - Product Security

RemoteUnited States only
Published
Role
Security
Experience
Senior
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior product/application security IC with 5+ years, strong secure code review, threat modeling, AppSec tooling, and bug bounty ownership. Must be US-based remote and comfortable with Web2 product security for blockchain-integrated products.

Core skills

Threat modelingSecure code reviewAppSec tooling

Required skills

TypeScript/JavaScript/Python/GoOAuthOIDCTerraformCI/CD

Optional skills

SolidityRust

What you'll do

  • Drive threat modeling for new features, integrations, and architectural changes across the product surface, turning threat models into engineering decisions.
  • Own secure code review for high-risk changes including authentication, session management, cryptographic paths, wallet and signing flows, RPC and third-party integrations, permission and consent surfaces.
  • Expand the AppSec tooling stack and reduce false positives as a first-class deliverable.
  • Design and evolve the secure SDLC, including review triggers, lightweight versus full security sign-off, and control validation.
  • Run the responsible disclosure and bug bounty program, including scope, triage, payouts, and driving findings to closure.
  • Support and own appropriate intake and closure of findings from external audits and pentests, coordinate with audit vendors, organize findings into the internal risk register, and drive remediation with engineering owners.
  • Partner with engineering leads to align on secure-by-default patterns such as libraries, templates, sensible defaults, and paved-road implementations.
  • Threat model blockchain-integrated components such as wallet flows, RPC integrations, signing infrastructure, and on-chain admin actions triggered from off-chain systems.
  • Contribute to hiring, mentoring, and raising the technical bar on the Security team.
  • Read code, run threat models, review architecture proposals, own tooling, and push engineering teams to build secure-by-default products.
  • Partner closely with adjacent security functions such as AppSec, Infrasec, and SecOps.

What they require

  • 5+ years in Product Security or Application Security, including senior IC time at a fast-moving product company.
  • Deep secure code review skills in at least one modern stack: TypeScript / JavaScript, Python, or Go.
  • Ability to move across stacks at the level required to threat model.
  • Strong threat modeling skills appropriate to experience, with ability to drive a real threat model with an engineering team rather than just fill in a template.
  • Core understanding of industry-relevant TTPs and IoCs and strong intuition for applying lessons learned to products.
  • Practical experience owning or majorly contributing to an AppSec tooling program, including shipping rules, tuning noise, and measuring impact.
  • Comfortable running or building a bug bounty / responsible disclosure program end-to-end assuming proper resourcing.
  • Strong working knowledge of modern web and API security, including session and auth flows, OAuth and OIDC, browser security model, common web/API vulnerability classes, and less-common variants.
  • Comfortable reading Terraform, cloud IAM policies, and CI/CD configuration well enough to reason about how a product vulnerability crosses into infrastructure risk.
  • Strong engineering partnership skills, including constructive engagement, understanding the reason before proposing risk controls, knowing when to accept risk, and writing things down.
  • Willing to grow into blockchain-adjacent product security on the job, including attack surfaces introduced by wallet, signing, and on-chain-integration code.
  • Understands what Web2 vs Web3 terminology means.
  • By Day 1, should have strong intuitions about how blockchains make product security experience unique, grasp common terminology, and be able to discuss incident post-mortems showing how Web2 compromises lead to Web3 funds losses.
  • Does not need to be an expert in smart contract auditing, blockchain security architectures, or decentralized consensus-driven risk controls.
  • Expected to have an opinionated take on how to accomplish a task, accept and return feedback, assume positive intent, act professionally and ethically, and enable stakeholders toward common goals.
  • Preferred: Prior work at a crypto, fintech, or other company where products handle high-value or irreversible actions.
  • Preferred: Familiarity with wallet, signing, or key-management flows.
  • Preferred: Bug bounty history such as reports, CVEs, or published write-ups.
  • Preferred: Familiarity with browser-extension security, mobile app security, or account-abstraction wallet designs.
  • Preferred: Public output such as talks, blog posts, open-source tools, or CVEs.

Ondo Finance provides institutional-grade, blockchain-enabled investment products and services, with a technology arm developing decentralized finance technology and an asset management arm creating and managing tokenized funds.

CryptoStartupondo.finance

Details

Apply routeGreenhouse
Salary not disclosed