Senior Security Engineer @Agora Finance
All Others
Salary unspecified
Employment Type full-time
Posted 1mth ago

[Hiring] Senior Security Engineer @Agora Finance

1mth ago - Agora Finance is hiring a remote Senior Security Engineer. πŸ’Έ Salary: unspecified πŸ“Location: EST (UTC-5), PST (UTC-8), MST (UTC-7), CST (UTC-6), PRT (UTC-4)

Role Description

We are looking for a Senior Security Engineer to help secure the products and services Agora builds and operates.

  • You will be the Security team's primary technical partner to Engineering.
  • Work alongside engineers from initial design through production operation:
    • Building and reviewing controls, architectures, code, infrastructure, and configuration.
    • Identifying meaningful risks.
    • Helping teams implement practical solutions.
  • Play a hands-on role in Agora's security monitoring program:
    • Identify the telemetry and detections needed to protect our systems.
    • Implement and tune alert rules.
    • Investigate security events.
    • Work closely with our SOC and internal teams during incident response.
  • This is a broad ownership role. You should be equally comfortable:
    • Reviewing an API authorization model.
    • Reasoning about an AWS or Kubernetes deployment.
    • Tuning a security scanner.
    • Investigating suspicious production activity.
    • Driving a vulnerability through remediation.
  • Agora's environment includes:
    • TypeScript and Node.js services.
    • React applications.
    • REST APIs.
    • Relational databases.
    • Docker, Kubernetes on AWS.
    • Pulumi infrastructure as code.
    • Argo CD and GitOps.
    • Cloudflare and blockchain infrastructure.
  • You do not need to arrive as an expert in every part of the stack, but you should be able to learn unfamiliar systems quickly and evaluate them from first principles.
  • We prefer candidates located close to Eastern Time, while welcoming exceptional engineers across Pacific Time through ET+2.
  • Your working hours will need to have a majority overlap with ET business hours.

Qualifications

  • 5+ years of hands-on experience in product security, application security, cloud security or a closely related security engineering role.
  • Strong software engineering fundamentals and the ability to review application code.
  • Experience with TypeScript, Node.js, JavaScript, or another modern language is especially relevant.
  • Experience reviewing web applications, backend services, REST APIs, authentication and authorization systems, and relational database designs.
  • Practical knowledge of common application and API vulnerabilities, threat-modeling techniques, secure design principles, and modern identity patterns.
  • Experience securing AWS environments, containerized workloads, Kubernetes, infrastructure as code, and CI/CD or GitOps workflows.
  • Hands-on experience implementing or administering security tools such as SAST, DAST, SCA, CSPM, container scanning, secrets detection, infrastructure-as-code scanning, SIEM, or cloud-native detection platforms.
  • Experience developing or tuning security detections using application, cloud, identity, network, and infrastructure telemetry.
  • Strong investigation skills, including the ability to analyze logs and system activity, develop and test hypotheses, establish timelines, and determine the scope and impact of suspicious behavior.
  • Experience working with SOC, including alert escalation, investigation handoffs, runbook development, and detection-quality improvement.
  • Experience participating in security incident response and coordinating effectively with engineering and operational teams under time pressure.
  • Experience operating a vulnerability management process and driving remediation across multiple engineering teams.
  • Ability to evaluate findings and detections based on exploitability, confidence, and business impact rather than relying exclusively on automated severity.
  • Experience working with external penetration testers, auditors, or specialist security reviewers.
  • Strong written and verbal communication skills, including the ability to explain technical risk and incident status clearly to technical and non-technical stakeholders.
  • High autonomy and sound judgment.
  • A collaborative, low-ego approach to security.

Requirements

  • Experience securing fintech, payments, digital-assets or other high-assurance financial platforms.
  • Familiarity with blockchain systems, smart-contract integrations, transaction flows, custody models, signing infrastructure, or cryptographic key management.
  • Experience with TypeScript, Pulumi, AWS, Argo CD, Cloudflare, PostgreSQL, Prometheus, or Grafana.
  • Experience with incident-response tooling, security data pipelines, log normalization, detection-as-code, or automated enrichment and response.
  • Experience defining operational metrics such as detection coverage, false-positive rate, investigation time, and mean time to contain.
  • Experience designing security controls for distributed, event-driven, multi-tenant, or high-availability systems.
  • Ability to create security automation, internal tools, or CI/CD integrations using code.
  • Experience applying AI-assisted tools to security investigations, detection engineering, or secure development.
  • Relevant offensive-security, incident-response and cloud-security experience or certifications.

Benefits

  • Agora operates a centralized USD-pegged stablecoin platform with robust compliance, security, and governance.
  • We are equally committed to fostering a diverse, inclusive, and equitable workplace.
Before You Apply
️
remote Be aware of the location restriction for this remote position: EST (UTC-5), PST (UTC-8), MST (UTC-7), CST (UTC-6), PRT (UTC-4)
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Engineer @Agora Finance
All Others
Salary unspecified
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: EST (UTC-5), PST (UTC-8), MST (UTC-7), CST (UTC-6), PRT (UTC-4)
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,870+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later