Member of Technical Staff, Security Operations

5 months, 3 weeks ago
Full-time
Mid Level
Software Development
Anchorage Digital

Anchorage Digital

Anchorage Digital is a regulated crypto platform that provides institutions with integrated financial services and infrastructure solutions. With the only federally chartered crypto bank in the US, as well as Anchorage Digital Singapore, which offers e...

Capital Markets
251-1K
Founded 2017
$487M raised

Description

  • Build and maintain security automation and tooling to detect vulnerabilities across code and live systems.
  • Conduct application security assessments, penetration tests, and code reviews to identify high-risk security issues.
  • Develop and operate vulnerability management workflows with engineering teams to prioritize and remediate findings.
  • Establish and test security guardrails for code, cloud resources, and infrastructure components.
  • Monitor and respond to security events and configuration anomalies, leading investigation and containment efforts.
  • Manage the full vulnerability lifecycle from discovery through remediation and ensure timely closure of findings.
  • Lead or substantially contribute to Security Operations initiatives with minimal oversight.
  • Deliver assurance artifacts and evidence to support regulated entity requirements, audits, and compliance efforts.
  • Document security processes, runbooks, and post-incident reviews to share knowledge and reduce single points of failure.
  • Partner cross-functionally with Engineering, Infrastructure, and Compliance teams to embed security into development and operations.

Requirements

  • 3+ years of hands-on experience in security engineering, application security, penetration testing, or security operations.
  • Experience building or maintaining security tools, integrations, or automation workflows using Python, Go, or similar languages.
  • Ability to identify and assess vulnerabilities in applications, APIs, and cloud infrastructure and communicate remediation strategies.
  • Experience with static and dynamic analysis tools such as Semgrep, CodeQL, Burp Suite, or equivalent.
  • Understanding of AWS security fundamentals, including IAM, VPCs, security groups, and CloudTrail/logging.
  • Ability to investigate security events, perform root cause analysis, and coordinate response efforts.
  • Strong computer science fundamentals, including concurrency, algorithms, and data structures.
  • Experience running or participating in bug bounty programs, such as HackerOne or Bugcrowd, is a plus.
  • Experience in regulated financial services, fintech, or crypto environments is preferred.
  • Relevant certifications such as OSCP, GWAPT, GCIH, or AWS Security Specialty are preferred.

Benefits

  • Remote-friendly role with the option to work in-office in New York City, Sioux Falls, Porto, Lisbon, or Singapore.
  • Quarterly in-person collaboration days for remote employees, sponsored by the company.
  • Opportunity to work at a federally chartered crypto bank with a regulated institutional platform.
  • A global team environment with cross-functional collaboration across engineering, infrastructure, and compliance.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

DevSecOps Engineer

Sparksoft 51-250 Internet Software & Services

Sparksoft is hiring a DevOps and Cloud Infrastructure professional to support government clients by managing AWS infrastructure, deployment pipelines, configuration controls, and software release activities.

Agile AWS CI/CD Git GitHub Jenkins SonarQube SVN
16 hours, 32 minutes ago

Staff Information Security Engineer - AI First

Rithum Internet Software & Services

Rithum is hiring a Staff AI-First Information Security Engineer to secure its AI-powered products and workforce by building automated controls, guardrails, and workflows across cloud and enterprise environments.

AWS Cybersecurity Python SIEM Terraform
17 hours, 17 minutes ago

Cybersecurity & Software Engineering Specialist (AI Projects)

Gramian Consultancy Group Professional Services

Gramian Consultancy is seeking remote Cybersecurity and Software Engineering Specialists to debug code, identify vulnerabilities, improve backend systems, and provide technical insights for an AI training project.

C++ Cybersecurity Go Java Penetration Testing Python Rust TypeScript
17 hours, 47 minutes ago

Security Operations Engineer - PCI DSS

teamified.com Hotels, Restaurants & Leisure

A three-month contract Security Engineer will own the PCI DSS v4.0.1 compliance cycle for a cloud-hosted payments platform, implementing controls, preparing evidence, and completing executive sign-off alongside engineering and operations teams.

AWS Encryption JIRA Penetration Testing Secrets Management SIEM
17 hours, 47 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers