Member of Technical Staff, Security Operations

2 weeks, 6 days ago
Full-time
Mid Level
Software Development
Anchorage Digital

Anchorage Digital

Anchorage Digital is a regulated crypto platform that provides institutions with integrated financial services and infrastructure solutions. With the only federally chartered crypto bank in the US, as well as Anchorage Digital Singapore, which offers e...

Capital Markets
251-1K
Founded 2017
$487M raised

Description

  • Build and maintain security automation and tooling to detect vulnerabilities across code and live systems.
  • Conduct application security assessments, penetration tests, and code reviews to identify high-risk security issues.
  • Develop and operate vulnerability management workflows with engineering teams to prioritize and remediate findings.
  • Establish and test security guardrails for code, cloud resources, and infrastructure components.
  • Monitor and respond to security events and configuration anomalies, leading investigation and containment efforts.
  • Manage the full vulnerability lifecycle from discovery through remediation and ensure timely closure of findings.
  • Lead or substantially contribute to Security Operations initiatives with minimal oversight.
  • Deliver assurance artifacts and evidence to support regulated entity requirements, audits, and compliance efforts.
  • Document security processes, runbooks, and post-incident reviews to share knowledge and reduce single points of failure.
  • Partner cross-functionally with Engineering, Infrastructure, and Compliance teams to embed security into development and operations.

Requirements

  • 3+ years of hands-on experience in security engineering, application security, penetration testing, or security operations.
  • Experience building or maintaining security tools, integrations, or automation workflows using Python, Go, or similar languages.
  • Ability to identify and assess vulnerabilities in applications, APIs, and cloud infrastructure and communicate remediation strategies.
  • Experience with static and dynamic analysis tools such as Semgrep, CodeQL, Burp Suite, or equivalent.
  • Understanding of AWS security fundamentals, including IAM, VPCs, security groups, and CloudTrail/logging.
  • Ability to investigate security events, perform root cause analysis, and coordinate response efforts.
  • Strong computer science fundamentals, including concurrency, algorithms, and data structures.
  • Experience running or participating in bug bounty programs, such as HackerOne or Bugcrowd, is a plus.
  • Experience in regulated financial services, fintech, or crypto environments is preferred.
  • Relevant certifications such as OSCP, GWAPT, GCIH, or AWS Security Specialty are preferred.

Benefits

  • Remote-friendly role with the option to work in-office in New York City, Sioux Falls, Porto, Lisbon, or Singapore.
  • Quarterly in-person collaboration days for remote employees, sponsored by the company.
  • Opportunity to work at a federally chartered crypto bank with a regulated institutional platform.
  • A global team environment with cross-functional collaboration across engineering, infrastructure, and compliance.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Director of Security/GRC

Censys 51-250 IT Services

Censys is hiring a Director of Security & GRC to lead corporate security, risk, and compliance programs for a remote U.S. team supporting internet intelligence operations.

AWS Azure Cybersecurity GCP SIEM
1 hour, 13 minutes ago

Senior Information Security Specialist

Rush Street Interactive 251-1K Hotels, Restaurants & Leisure

Rush Street Interactive is hiring a Senior Information Security Specialist to support the protection of its online gaming platforms, infrastructure, and data through technical security leadership across multiple domains.

SIEM SOC
1 hour, 52 minutes ago

DevSecOps Engineer (TypeScript & Agentic AI)

Arize AI 51-250 IT Services

Arize AI is hiring a remote IT Support Specialist to support Mac-only endpoints, cloud systems, and compliance operations for a distributed team.

Confluence GitHub JIRA TypeScript
3 hours, 3 minutes ago

IT Infrastructure Security Operations Engineer

JMA Wireless 251-1K Wireless Telecommunication Services

JMA is hiring an IT Infrastructure Security Operations Engineer in Syracuse, NY to own the day-to-day security posture of its enterprise infrastructure and keep Windows and Linux environments continuously hardened and audit-ready.

Active Directory Ansible Bash Linux PowerShell Puppet Python SIEM
3 hours, 39 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers