Ondo Finance

Ondo Finance

Ondo Finance provides institutional-grade financial services on a blockchain platform, making advanced financial solutions accessible to a broader audience.

Diversified Financial Services
11-50
Founded 2021
$24M raised

Description

  • Drive threat modeling for new features, integrations, and architectural changes across the product surface.
  • Own secure code review for high-risk changes including authentication, sessions, cryptography, wallet and signing flows, RPC, and third-party integrations.
  • Expand, tune, and maintain the AppSec tooling stack, including reducing false positives and supporting AI-native integrations.
  • Design and evolve the secure SDLC, including review triggers, sign-off levels, and control validation.
  • Run the responsible disclosure and bug bounty program, including scoping, triage, payouts, and closure of findings.
  • Support intake, tracking, and remediation of findings from external audits and pentests with vendors and engineering owners.
  • Partner with engineering leads to create secure-by-default patterns, libraries, templates, and paved-road implementations.
  • Threat model blockchain-integrated components such as wallet flows, signing infrastructure, RPC integrations, and on-chain admin actions.
  • Contribute to hiring, mentoring, and raising the technical bar on the Security team.

Requirements

  • 5+ years of experience in Product Security or Application Security, including senior IC experience at a fast-moving product company.
  • Deep secure code review skills in at least one modern stack such as TypeScript/JavaScript, Python, or Go.
  • Strong threat modeling skills with the ability to drive practical engineering decisions.
  • Experience owning or contributing significantly to an AppSec tooling program, including shipping rules, tuning noise, and measuring impact.
  • Comfort running or building a bug bounty or responsible disclosure program end-to-end.
  • Strong working knowledge of modern web and API security, including session and auth flows, OAuth/OIDC, browser security, and common vulnerability classes.
  • Ability to read Terraform, cloud IAM policies, and CI/CD configuration well enough to identify infra risk from product vulnerabilities.
  • Strong engineering partnership skills, including constructive collaboration, risk judgment, and clear written communication.
  • Willingness to grow into blockchain-adjacent product security, including wallet, signing, and on-chain integration attack surfaces.
  • Prior experience in crypto, fintech, or other environments with high-value or irreversible actions (nice to have).
  • Familiarity with wallet, signing, or key-management flows (nice to have).
  • Reading-level familiarity with Solidity or Rust (nice to have).
  • Bug bounty history, including reports, CVEs, or published write-ups (nice to have).
  • Familiarity with browser-extension security, mobile app security, or account-abstraction wallet designs (nice to have).
  • Public technical output such as talks, blog posts, open-source tools, or CVEs (nice to have).

Benefits

  • The role is fully focused on a high-impact security function within the product engineering organization.
  • High-trust team environment with respect, candor, and positive intent.
  • Opportunity to work closely with engineering, AppSec, Infrasec, and SecOps on critical product security decisions.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
1 day, 14 hours ago

Staff Product Security Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Staff Product Security Engineer to embed security into its cloud-native product and delivery pipelines for hardened open source software.

AWS CI/CD GCP GitHub Actions Go Kubernetes OWASP Penetration Testing Python Secrets Management Tekton
2 days, 13 hours ago

Staff Product Security Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Staff Product Security Engineer to embed security into its cloud-native software delivery and product infrastructure, with a focus on securing pipelines, hardening workloads, and reducing supply chain risk.

AWS CI/CD GCP GitHub Actions Go Kubernetes OWASP Penetration Testing Python Secrets Management Tekton
2 days, 13 hours ago

Staff Product Security Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Staff Product Security Engineer to embed security into cloud-native product development and protect open source software delivered through hardened, production-ready builds.

AWS GCP GitHub Actions Go Kubernetes OWASP Penetration Testing Python Secrets Management Tekton
2 days, 13 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers