Senior Security Engineer - Product Security @Ondo Finance
All Others
Salary unspecified
Remote Location
๐Ÿ‡บ๐Ÿ‡ธ USA Only
Employment Type full-time
Posted Today

[Hiring] Senior Security Engineer - Product Security @Ondo Finance

Today - Ondo Finance is hiring a remote Senior Security Engineer - Product Security. ๐Ÿ’ธ Salary: unspecified ๐Ÿ“Location: USA

Role Description

We are hiring a Senior Security Engineer - Product Security to own how we ship secure products at Ondo. You will be a security partner for our product engineering teams, driving threat modeling, owning secure code reviews for new products or feature expansions, maintaining and tuning AppSec tooling, and improving the existing SSDLC. You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native approach is welcome, paired with AI-driven approaches should expect to be justified by describing how doing so enables risk outcomes.

This is a hands-on IC role. You will read code, run threat models, review architecture proposals, own tooling, and push engineering teams to build products that are secure by default. You partner closely with adjacent security functions like AppSec, Infrasec, and SecOps.

What Youโ€™ll Do

  • Drive threat modeling for new features, integrations, and architectural changes across the product surface.
  • Own secure code review for high-risk changes โ€” authentication, session management, cryptographic paths, wallet and signing flows, RPC and third-party integrations, permission and consent surfaces.
  • Expand the AppSec tooling stack and treat โ€œreducing false positivesโ€ as a first-class deliverable.
  • Design and evolve our secure SDLC: where security fits in the dev workflow, what triggers a review, what a lightweight security sign-off looks like versus a full one, and how do we validate controls.
  • Run our responsible disclosure and bug bounty program. Set scope, triage inbound reports, decide payouts, and drive findings to closure with engineering.
  • Support and own appropriate scope for the intake and closure of findings from external audits and pentests.
  • Partner with engineering leads to align on secure-by-default patterns - libraries, templates, sensible defaults, and paved-road implementations of anything security-relevant.
  • Threat model blockchain-integrated components like wallet flows, RPC integrations, signing infrastructure, on-chain admin actions triggered from off-chain systems.
  • Contribute to hiring, mentoring, and pushing the technical bar on the Security team.

Qualifications

  • 5+ years in Product Security or Application Security, including senior IC time at a fast-moving product company.
  • Deep secure code review skills in at least one modern stack (TypeScript / JavaScript, Python, or Go).
  • Strong threat modeling skills, appropriate to experience.
  • Practical experience owning or majorly contributing to an AppSec tooling program.
  • Comfortable running or building a bug bounty / responsible disclosure program end-to-end.
  • Strong working knowledge of modern web and API security.
  • Comfortable reading Terraform, cloud IAM policies, and CI/CD configuration.
  • Strong engineering partnership skills.
  • Willing to grow into blockchain-adjacent product security on the job.

Blockchain Exposure Note

This role firmly lives in Web2 prodsec. But, it also requires someone who understands what โ€œWeb2 vs Web3โ€ terminology means. At a minimum, by Day 1 you should have strong intuitions about how blockchains will make your prodsec experience unique, you should grasp the common terminologies, and you should be able to discuss with colleagues several incident post-mortems that demonstrate how Web2 compromises lead to Web3 funds losses.

Nice to Have

  • Prior work at a crypto, fintech, or other company where products handle high-value or irreversible actions.
  • Familiarity with wallet, signing, or key-management flows.
  • Reading-level familiarity with Solidity or Rust.
  • Bug bounty history - reports, CVEs, or published write-ups.
  • Familiarity with browser-extension security, mobile app security, or account-abstraction wallet designs.
  • Public output - talks, blog posts, open-source tools, CVEs.

How We Work

The Security team values a high trust team environment where respectful candor can thrive. We expect senior engineers to have an opinionated take on how to accomplish a task, accept feedback from the team and other external stakeholders and return it in kind, and to always assume positive intent. Professionalism, ethics, and enabling stakeholders towards common goals are important always.

Before You Apply
๏ธ
๐Ÿ‡บ๐Ÿ‡ธ Be aware of the location restriction for this remote position: USA Only
โ€ผ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Engineer - Product Security @Ondo Finance
All Others
Salary unspecified
Remote Location
๐Ÿ‡บ๐Ÿ‡ธ USA Only
Employment Type full-time
Posted Today
Apply for this position
Did not apply โœ“
Applied โœ“
Sent Follow-Up โœ“
Interview Scheduled โœ“
Interview Completed โœ“
Offer Accepted โœ“
Offer Declined โœ“
Application Denied โœ“
Unlock 120,000+ Remote Jobs
๏ธ
๐Ÿ‡บ๐Ÿ‡ธ Be aware of the location restriction for this remote position: USA Only
โ€ผ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply โœ“
Applied โœ“
Sent Follow-Up โœ“
Interview Scheduled โœ“
Interview Completed โœ“
Offer Accepted โœ“
Offer Declined โœ“
Application Denied โœ“
Unlock 120,000+ Remote Jobs
ร—

Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 โ˜…โ˜…โ˜…โ˜…โ˜… from 500+ reviews
Unlock All Jobs Now

Maybe later