Ondo Finance

Ondo Finance

Ondo Finance provides institutional-grade financial services on a blockchain platform, making advanced financial solutions accessible to a broader audience.

Diversified Financial Services
11-50
Founded 2021
$24M raised

Description

  • Drive threat modeling for new features, integrations, and architectural changes across the product surface.
  • Own secure code review for high-risk changes including authentication, sessions, cryptography, wallet and signing flows, RPC, and third-party integrations.
  • Expand, tune, and maintain the AppSec tooling stack, including reducing false positives and supporting AI-native integrations.
  • Design and evolve the secure SDLC, including review triggers, sign-off levels, and control validation.
  • Run the responsible disclosure and bug bounty program, including scoping, triage, payouts, and closure of findings.
  • Support intake, tracking, and remediation of findings from external audits and pentests with vendors and engineering owners.
  • Partner with engineering leads to create secure-by-default patterns, libraries, templates, and paved-road implementations.
  • Threat model blockchain-integrated components such as wallet flows, signing infrastructure, RPC integrations, and on-chain admin actions.
  • Contribute to hiring, mentoring, and raising the technical bar on the Security team.

Requirements

  • 5+ years of experience in Product Security or Application Security, including senior IC experience at a fast-moving product company.
  • Deep secure code review skills in at least one modern stack such as TypeScript/JavaScript, Python, or Go.
  • Strong threat modeling skills with the ability to drive practical engineering decisions.
  • Experience owning or contributing significantly to an AppSec tooling program, including shipping rules, tuning noise, and measuring impact.
  • Comfort running or building a bug bounty or responsible disclosure program end-to-end.
  • Strong working knowledge of modern web and API security, including session and auth flows, OAuth/OIDC, browser security, and common vulnerability classes.
  • Ability to read Terraform, cloud IAM policies, and CI/CD configuration well enough to identify infra risk from product vulnerabilities.
  • Strong engineering partnership skills, including constructive collaboration, risk judgment, and clear written communication.
  • Willingness to grow into blockchain-adjacent product security, including wallet, signing, and on-chain integration attack surfaces.
  • Prior experience in crypto, fintech, or other environments with high-value or irreversible actions (nice to have).
  • Familiarity with wallet, signing, or key-management flows (nice to have).
  • Reading-level familiarity with Solidity or Rust (nice to have).
  • Bug bounty history, including reports, CVEs, or published write-ups (nice to have).
  • Familiarity with browser-extension security, mobile app security, or account-abstraction wallet designs (nice to have).
  • Public technical output such as talks, blog posts, open-source tools, or CVEs (nice to have).

Benefits

  • The role is fully focused on a high-impact security function within the product engineering organization.
  • High-trust team environment with respect, candor, and positive intent.
  • Opportunity to work closely with engineering, AppSec, Infrasec, and SecOps on critical product security decisions.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Manager, Product Security

Tines 51-250 Construction & Engineering

Tines is seeking a Senior Manager, Product Security to lead and scale its product security program for cloud-native, AI-forward products while partnering with engineering and product leaders to manage risk and support growth.

AWS CI/CD DevSecOps Docker Kubernetes Penetration Testing Ruby Rust TypeScript
2 days, 17 hours ago

Application Security Engineer

Glean 11-50 Internet Software & Services

Glean is hiring a remote Application Security Engineer to lead vulnerability management and strengthen software supply-chain security across its Work AI platform.

AWS Burp Suite CI/CD Cybersecurity GCP Kubernetes Microservices
2 days, 18 hours ago

Lead Application Security Engineer

Remofirst 11-50 Professional Services

RemoFirst is hiring an application and cloud security engineer to secure its global Employer of Record platform, customer identity systems, infrastructure, and emerging AI initiatives across a distributed engineering organization.

AWS Django FastAPI Java Kafka Kubernetes MongoDB OpenID Connect Penetration Testing PostgreSQL Python RabbitMQ REST API SAML Secrets Management Spring Boot Terraform
2 days, 18 hours ago

Application Security Engineer II

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring an Application Security Engineer to triage and validate vulnerability submissions for major clients, communicate with researchers and customers, and support incident response across diverse security programs.

Burp Suite Nmap
3 days, 18 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers