Senior Security Engineer
Join Gauntlet as a Senior Security Engineer, partnering with the Head of Security to build, operate and scale our security program. You'll work at the intersection of capital, risk and technology: securing the systems that power some of the largest and most sophisticated activities in DeFi. You'll own security projects across product, infrastructure and operations, designing controls, automation and detection capabilities that can withstand one of the most adversarial environments in software: billions of dollars in assets on-chain on public blockchains.
About Gauntlet
Gauntlet builds the financial systems of the future. While much of onchain finance is focused on point solutions, we operate across the entire stack to offer best-in-class vault products. Today we serve over $1.5B in client TVL across some of the largest fintechs/neobanks, protocols, exchanges, and capital allocators in crypto — and, increasingly, traditional asset management. Our team brings together traditional finance and crypto-native expertise to deliver durable, sophisticated products for institutional clients moving onchain.
What you'll do;
- Threat model new product features and integrations and harden systems with effective controls.
- Operate and evolve the application security toolchain and keep it high-signal for developers.
- Own day-to-day security operations across the detection stack (EDR, SIEM, on-chain monitoring, identity, cloud): triage what fires, resolve what matters, and reduce noise.
- Triage vulnerability and bug-bounty findings by real exposure, drive remediation, and support incident response end to end.
- Take security tooling and projects from evaluation through org-wide rollout, collaborating across engineering, infra and other teams.
- Automate repetitive, judgment-light security work with AI: vulnerability and AppSec workflows, access reviews, SOC 2 and audit evidence collection, vendor due diligence, and recurring reporting.
- Build reusable AI components, Claude skills, and agents that engineering and other functions can adopt.
What you Bring;
- 5+ years in hands-on security engineering spanning product or application security and security operations.
- Track record of technical security assessments of software and systems, including system hardening, security policy analysis and implementing effective controls.
- An adversarial mindset: you think like an attacker and pressure-test assumptions, including your own.
- Proficiency in Python, TypeScript, or JavaScript, working with Claude Code, Codex or similar AI tools.
- Hands-on experience applying AI and LLMs to automation and building reusable tooling or components that other engineers adopted.
- Experience owning security projects end to end, from vendor selection through org-wide rollout, across multiple teams.
- Experience securing high-value or high-throughput transaction systems.
- Clear communication: you explain risk plainly and drive findings to closure.
Bonus Points
- Crypto/blockchain security experience.
Benefits & Perks;
- Remote first - work from anywhere in the US & CAN!
- Regular in-person company retreats and cross-country "office visit" perk
- 100% paid medical, dental and vision premiums for employees
- $1,000 WFH stipend
- Monthly reimbursement for home internet, phone, and cellular data
- Unlimited vacation
- 100% paid parental leave of 12 weeks
- Fertility benefits
- Opportunity for incentive compensation
Skills
As published by lever · 3 questions · 1 written answer
Basics
Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website, I identify my ethnicity asSelect all that apply, I identify my gender as, If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. Classification of protected categories is as follows: A "disabled veteran" is one of the following; a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability. A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service. An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense. An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Pick from a list (2)
- We currently support remote work from the United States & Canada. Which of these two locations will you be working from?
- Will you now or in the future require sponsorship for employment visa / work authorization status?
Written answers (1)
- Bonus points for linking your Github or portfolio: