Senior Security Engineer (GRC)

Remote $112k–$188k senior 3 months ago full-time quality 8.3/10

Role in brief

Offchain Labs seeks a Senior Security Engineer specializing in Governance, Risk, and Compliance (GRC) to develop and enforce security policies, manage audits, and refine their information security program. This role is ideal for an experienced security professional with a strong background in regulatory frameworks and cloud security, who can translate complex requirements into clear internal processes.

NIST CSFInformation security conceptsAWSRegulatory frameworksRisk managementBlockchain technologySOC2Cloud vendorsSecurity engineeringRisk assessment toolsISO 27001

About the role

This role focuses on strengthening Offchain Labs' security posture through robust governance and risk management. The Senior Security Engineer will be responsible for developing and enforcing security policies, ensuring the company is prepared for audits, and communicating data privacy standards across the organization. This involves active participation in designing and refining the company's information security governance program.

A key aspect of the position is collaboration with various teams, including security, engineering, infrastructure, and product, to ensure that security controls align with both business objectives and technical realities. The engineer will also be instrumental in promoting security awareness and fostering a shared sense of risk responsibility through focused training and clear communication.

Success in this role means maintaining audit readiness, effectively tracking and reporting on security controls and compliance activities, and supporting internal and external audits by coordinating evidence and addressing findings. The ideal candidate will translate complex regulatory and technical obligations into actionable internal processes, contributing to a secure and compliant blockchain environment.

The salary for this position ranges from $112,000 to $188,000 annually.

Skills that matter here

  • NIST CSF: This framework is essential for understanding and implementing security controls and risk management practices.
  • AWS: Experience with AWS or other cloud vendors is necessary for securing cloud-based infrastructure and services.
  • Regulatory frameworks: A strong understanding of major regulatory frameworks is required to ensure compliance and audit readiness.
  • Risk management: This skill is central to identifying, assessing, and mitigating security risks across the organization.
  • SOC2: Knowledge of SOC2 is important for managing compliance and preparing for security audits.
  • Security engineering: This role involves applying engineering principles to design and implement security solutions and controls.

Who this role suits

  • Someone with at least five years of experience in security engineering, governance, or risk management.
  • A professional who can clearly communicate complex technical and regulatory information to diverse audiences.
  • An individual who is adept at drafting and updating security policies and translating obligations into actionable processes.
  • A candidate with hands-on experience in risk assessment tools and a solid understanding of cloud security.

From the employer

What you'll do:

  • Develop and enforce security policies, standards, and procedures organization-wide.
  • Ensure the company is audit-ready and responsive to any regulatory changes.
  • Establish and clearly communicate data privacy and data-handling standards to internal teams as well as external partners and stakeholders.
  • Track, document, and report on the status of security controls, ongoing audits, and all related compliance activities.
  • Play an active part in designing, launching, and continuously refining the company’s overall information security governance program.
  • Work closely with security, engineering, infrastructure, and product teams to make sure controls fit both business objectives and technical realities.
  • Promote security awareness and build a strong culture of shared risk responsibility through focused training and straightforward communication.
  • Support both internal and external audits by coordinating evidence gathering, preparing materials, and ensuring findings are addressed quickly and thoroughly.

What you'll need:

  • 5+ years of experience in a security engineering, governance, or risk management role.
  • Solid understanding of AWS or other cloud vendors.
  • Strong understanding of core information security concepts and major regulatory frameworks/standards (e.g. SOC2, ISO 27001, NIST CSF).
  • Hands-on experience with standard risk assessment approaches and supporting tools.
  • Direct experience drafting and updating security policies.
  • Ability to translate complex regulatory and technical obligations into straightforward, actionable internal processes.
  • Strong communication skills that work well with both technical and non-technical audiences.
  • Excellent written and verbal communication skills, with the ability to present complex technical details as clear, risk-focused recommendations.

Perks:

  • Remote-first global workforce + NY office.
  • Annual company offsite + team onsites.
  • Professional reimbursement program (facilitates industry conference attendance, certifications, and more).
  • Medical, dental & vision coverage (US + some other countries).
  • 401k retirement plan + company match (US only).
  • Wellness stipend.
  • Home office set up / ergonomic equipment program.

Questions about this role

What is the remote work policy for this role?

This is a remote position, and Offchain Labs operates with a remote-first global workforce, though they also have an office in New York.

What level of seniority is expected for this position?

This is a senior-level role, requiring at least 5 years of experience in a relevant security or risk management capacity.

What are the key technical skills required for this role?

Key technical skills include a strong understanding of information security concepts, AWS or other cloud vendors, major regulatory frameworks like SOC2, ISO 27001, and NIST CSF, and experience with risk assessment tools.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Offchainlabs.