Engineering Lead — Security
Summary
Lead security for a blockchain L1: harden infrastructure, define policies, manage keys, run audits, and respond to incidents across validators, RPC, and smart-contract systems.
You will own security across the L1 infrastructure, products, services, policies, processes, multisig governance, and key management. You will harden hosts, networks, and pipelines; define security standards; secure applications and supply chains; operate signing and treasury workflows; lead incident response; conduct threat modeling and security reviews; and coordinate audits and bug bounties.
Responsibilities
- Help define the engineering culture and bar with other technical leaders
- Own the security posture of L1 infrastructure, including validators, RPC, signing services, and supporting systems
- Harden hosts, networks, and pipelines
- Drive vulnerability management, patching, and security monitoring
- Define and roll out access control, secrets management, secure SDLC, change management, and compliance-readiness policies
- Drive application and supply-chain security for shipped products and services
- Implement secure-by-default patterns and dependency and build-pipeline scanning in CI
- Conduct security reviews for high-stakes work and secure agent-authored changes
- Design and operate multisig governance, signing ceremonies, and key lifecycles
- Build and lead security incident response, including detection, triage, containment, and postmortems
- Run security tabletop exercises
- Conduct threat modeling, security reviews, and red-team exercises
- Coordinate external audits and bug bounties
- Work with infrastructure and L1 teams to resist node and validator compromise and ship upgrades safely
Requirements
- Extensive security engineering, infrastructure security, SecOps, and application-security experience
- Production systems experience with Linux internals, networking, containers, Kubernetes, and infrastructure as code
- Experience defining and implementing security policies
- Deep key-management experience with signing workflows, HSMs, secrets management, and key generation, rotation, and recovery
- Incident response leadership covering detection, containment, forensics, and postmortems
- Cryptography fundamentals applied to blockchain and key management
- Senior-level ownership, judgment, communication, and influence without authority
- Comfort working in high-stakes financial systems
- Genuine interest in crypto and on-chain systems
- Experience securing blockchain L1 or L2 node and validator infrastructure
- Experience with multisig governance and treasury operations
- EVM, smart contract security, and DeFi attack surfaces
- Experience coordinating external audits, bug bounties, and responsible disclosure
- Red teaming, offensive security, or detection engineering experience
- Experience with high-throughput or low-latency systems
Benefits
- Remote work
- Token incentives