Ondo Finance

Ondo Finance

Ondo Finance provides institutional-grade financial services on a blockchain platform, making advanced financial solutions accessible to a broader audience.

Diversified Financial Services
11-50
Founded 2021
$24M raised

Description

  • Drive threat modeling for new features, integrations, and architectural changes across the product surface.
  • Own secure code review for high-risk changes including authentication, sessions, cryptography, wallet and signing flows, RPC, and third-party integrations.
  • Expand, tune, and maintain the AppSec tooling stack, including reducing false positives and supporting AI-native integrations.
  • Design and evolve the secure SDLC, including review triggers, sign-off levels, and control validation.
  • Run the responsible disclosure and bug bounty program, including scoping, triage, payouts, and closure of findings.
  • Support intake, tracking, and remediation of findings from external audits and pentests with vendors and engineering owners.
  • Partner with engineering leads to create secure-by-default patterns, libraries, templates, and paved-road implementations.
  • Threat model blockchain-integrated components such as wallet flows, signing infrastructure, RPC integrations, and on-chain admin actions.
  • Contribute to hiring, mentoring, and raising the technical bar on the Security team.

Requirements

  • 5+ years of experience in Product Security or Application Security, including senior IC experience at a fast-moving product company.
  • Deep secure code review skills in at least one modern stack such as TypeScript/JavaScript, Python, or Go.
  • Strong threat modeling skills with the ability to drive practical engineering decisions.
  • Experience owning or contributing significantly to an AppSec tooling program, including shipping rules, tuning noise, and measuring impact.
  • Comfort running or building a bug bounty or responsible disclosure program end-to-end.
  • Strong working knowledge of modern web and API security, including session and auth flows, OAuth/OIDC, browser security, and common vulnerability classes.
  • Ability to read Terraform, cloud IAM policies, and CI/CD configuration well enough to identify infra risk from product vulnerabilities.
  • Strong engineering partnership skills, including constructive collaboration, risk judgment, and clear written communication.
  • Willingness to grow into blockchain-adjacent product security, including wallet, signing, and on-chain integration attack surfaces.
  • Prior experience in crypto, fintech, or other environments with high-value or irreversible actions (nice to have).
  • Familiarity with wallet, signing, or key-management flows (nice to have).
  • Reading-level familiarity with Solidity or Rust (nice to have).
  • Bug bounty history, including reports, CVEs, or published write-ups (nice to have).
  • Familiarity with browser-extension security, mobile app security, or account-abstraction wallet designs (nice to have).
  • Public technical output such as talks, blog posts, open-source tools, or CVEs (nice to have).

Benefits

  • The role is fully focused on a high-impact security function within the product engineering organization.
  • High-trust team environment with respect, candor, and positive intent.
  • Opportunity to work closely with engineering, AppSec, Infrasec, and SecOps on critical product security decisions.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Application Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a remote Application Security Engineer to triage and validate vulnerability submissions for large-scale bug bounty programs while coordinating with clients and security researchers.

Burp Suite Nmap
1 hour, 10 minutes ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI/ML security, secure architecture, and assurance practices across the product lifecycle.

CI/CD DevSecOps Encryption Java JavaScript Kubernetes Python SAML Secrets Management TLS
1 hour, 40 minutes ago

Product Security Engineer

Modern Health 251-1K Health Care Providers & Services

Modern Health is hiring a remote Product Security Engineer to strengthen security and compliance across its mental health platform, applications, cloud infrastructure, and software development lifecycle.

Agile AWS Bash CI/CD Cybersecurity Datadog Django Flask GitLab HashiCorp Vault Packer Penetration Testing PostgreSQL Python Redis Terraform
2 days, 1 hour ago

Application Security Engineer - Senior

Banco Plata, S.A., Institución de Banca Múltiple. 1001-5000 Banking / financial services

Plata is seeking an Application Security Engineer to join its Information Security team and embed security controls, testing, and practices throughout the software development lifecycle.

Burp Suite CI/CD Kubernetes Microservices OWASP Penetration Testing
4 days, 1 hour ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers