Security Analyst - Aptos

Remote $120k–$180k 2 months ago full-time quality 7.8/10

Role in brief

Aptos, a blockchain company, is hiring a Security Analyst to manage security operations. This role focuses on responding to phishing incidents, coordinating the bug bounty program, and overseeing access governance. Candidates with experience in security operations, strong organizational skills, and an ability to work independently in a remote setting should consider applying.

About the role

This role is central to maintaining security operations within Aptos, a blockchain platform focused on decentralized assets. The Security Analyst will be responsible for addressing immediate threats like phishing attacks and brand impersonation, requiring prompt triage and escalation of credible risks. A key part of the work involves managing the bug bounty program, which includes communicating with security researchers, tracking reported issues, and ensuring internal teams follow up on resolutions.

The position also involves significant work in access governance. This includes conducting regular reviews of user access, scrutinizing security settings, and evaluating access configurations across various business systems, SaaS platforms, and internal infrastructure. The analyst will track and ensure the remediation of any identified security weaknesses. This work is critical for maintaining a secure operational environment.

Success in this role means effectively managing multiple security workflows concurrently, demonstrating strong attention to detail, and ensuring reliable follow-through on all tasks. The ideal candidate will be self-motivated and comfortable operating independently within a remote-first work structure, contributing to the overall security posture of the organization by supporting recurring operational security processes and documentation.

The salary for this position ranges from $120,000 to $180,000 annually.

Skills that matter here

  • security operations: This role directly involves responding to security incidents and managing ongoing security processes.
  • IAM: The analyst will conduct user access reviews and manage access configurations across various platforms.
  • application security support: The role involves reviewing security settings across business systems and SaaS platforms.
  • phishing: A primary responsibility is to respond to and triage alerts related to phishing attacks.
  • access control: The analyst will review and manage access configurations and administrative controls.
  • least privilege: Understanding this concept is important for conducting effective access reviews and managing configurations.

Who this role suits

  • Someone with at least two years of experience in a security-focused role, such as security operations or IAM.
  • A person who can manage multiple tasks simultaneously while maintaining strong attention to detail.
  • An individual who communicates clearly in writing and can coordinate with both technical and non-technical stakeholders.
  • A self-motivated and organized professional comfortable working independently in a remote setting.

From the employer

  • Respond to and triage alerts relating to phishing attacks, impersonation, scams, and brand abuse (e.g. Sublime, Doppel), escalating credible threats where appropriate.
  • Coordinate day-to-day operation of the bug bounty program, including communication with researchers, issue tracking, reporting, and internal follow-up.
  • Conduct user access reviews and review security settings, access configurations, and administrative controls across business systems, SaaS platforms, and internal infrastructure, tracking remediation where required.
  • Support recurring operational security workflows, including documentation, process tracking, and follow-up.
  • 2+ years of experience in a security-focused role, such as security operations, IAM, application security support, operational security, or a similar domain.
  • Familiarity with core security concepts including phishing, authentication, access control, least privilege, and common vulnerability classes.
  • Ability to manage multiple concurrent workflows with strong attention to detail and reliable follow-through.
  • Clear written communication and confidence coordinating across technical and non-technical stakeholders.
  • Self-motivated, organized, and comfortable operating independently in a remote-first environment with minimal supervision.
  • 100% insurance premium coverage for medical, dental, and vision for you and your dependents (US Employees)
  • Equipment of your choice
  • Flexible vacation time, 11 holidays, and floating company days off
  • Competitive Salary
  • Protocol Token Grants
  • 401k matching (US Employees)
  • Fun and inclusive in-person and digital events

Questions about this role

What is the remote work policy for this role?

This is a remote position, and the company operates in a remote-first environment.

What level of experience is required?

Candidates should have at least 2 years of experience in a security-focused role.

What are the key responsibilities of this Security Analyst role?

Key responsibilities include responding to phishing and brand abuse, managing the bug bounty program, and conducting user access reviews.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Aptos.