Security Engineer
Role in brief
Ondo Finance, a leader in tokenized real-world assets, seeks a Security Engineer to strengthen the security of their blockchain products. This role involves architecture reviews, implementing security controls, and assessing smart contracts. It is ideal for a mid-level professional with a background in security engineering, blockchain, and DeFi, who is adept at integrating security best practices and responding to incidents.
About the role
This role focuses on enhancing the security posture of blockchain-based financial products. The Security Engineer will conduct architecture reviews, with an emphasis on smart contract security, key management, and Web3 integrations. Responsibilities also include implementing and refining security controls for both on-chain and off-chain systems, alongside performing security assessments of smart contracts and blockchain infrastructure using both manual and automated methods.
The successful candidate will collaborate closely with engineering teams to embed security best practices throughout the development lifecycle, from threat modeling to secure design reviews and pre-release checks. This involves ensuring security is considered at every stage of product development. Additionally, the role includes supporting third-party security assessments, coordinating with external auditors, and maintaining essential security documentation, runbooks, and training materials.
Success in this position means actively contributing to a robust security framework that protects digital assets and maintains the integrity of Ondo Finance's offerings. The Security Engineer will participate in on-call rotations and incident response, demonstrating the ability to quickly address security issues. This requires a proactive approach to identifying and mitigating risks, ensuring the continuous security of the platform.
The compensation for this role ranges from $150,000 to $250,000 USD, which includes salary, future token rights, or equity based on candidate preference.
Skills that matter here
- security engineering: This role requires a background in security engineering to support architecture reviews, implement controls, and assess systems for vulnerabilities.
- blockchain: The position involves securing blockchain-based financial products, necessitating an understanding of blockchain security principles.
- smart contracts: A core responsibility is performing security assessments of smart contracts and integrating security best practices for their development.
- DeFi: Experience assessing and securing DeFi protocols is essential for protecting the company's decentralized finance technology.
- cryptography: A working understanding of cryptography is needed to comprehend and apply blockchain security principles effectively.
Who this role suits
- A professional with at least three years of experience in security engineering or a related field with a strong security focus.
- Someone who understands cryptography and blockchain security principles, with practical experience in smart contract and DeFi protocol assessment.
- An individual familiar with security fundamentals for distributed systems, including authentication, authorization, and secrets management.
- A candidate who can read code to identify security risks and write code in scripting languages for security solutions and automation.
From the employer
- Support security architecture reviews for blockchain products, focusing on smart contract security, key management, and Web3 integrations
- Implement and iterate on security controls for both on-chain and off-chain systems
- Perform security assessments of smart contracts and blockchain infrastructure (manual review and tooling-assisted)
- Participate in on-call rotation and incident response support as needed
- Partner with engineering teams to integrate security best practices into the development lifecycle (threat modeling, secure design reviews, pre-release checks)
- Support third-party security assessments and coordination with external auditors
- Help maintain security documentation, runbooks, and training materials
- 3+ years of experience in security engineering or adjacent infrastructure/software engineering with a strong security focus
- Working understanding of cryptography and blockchain security principles
- Experience assessing and securing smart contracts and/or DeFi protocols (professional experience or meaningful open-source contributions)
- Familiarity with security fundamentals for distributed systems (authn/authz, secrets management, network segmentation, logging/monitoring)
- Exposure to incident response and security monitoring workflows
- Ability to read code to identify and assess security risks; ability to write code in common scripting languages to support security solutions and automation
- Strong communication skills with both technical and non-technical stakeholders
- Competitive compensation including salary, future token rights, and/or equity (according to your preferences) — we re well-funded and believe that great talent deserves great compensation
- Full benefits (medical, vision, and dental) and flexible vacation policy (PTO)
- Small remote-first team across many countries — you ll be an early team member helping shape our vision, culture, and design practices
- A+ colleagues — our team includes alumni from: Goldman Sachs, Blackrock, Two Sigma, Bridgewater, SpaceX, AWS, Meta, Google, Pinterest, McKinsey, Circle, Uniswap, Phantom
- Best-in-class investors — we are proud to be backed by leading crypto experts and VCs, including Pantera Capital, Founders Fund and Coinbase Ventures
Questions about this role
What is the remote work policy for this role?
This is a fully remote position, and the company has team members located across the U.S.
What is the expected seniority level for this position?
This role is for a middle-seniority Security Engineer.
What are the key technical skills required for this role?
Key technical skills include security engineering, blockchain, smart contracts, DeFi, and cryptography, along with experience in distributed systems security and incident response.