远程工作雷达

资深产品安全工程师(安全)

Staff Product Security Engineer (Security)

开发工程限定地区(需当地身份)
公司Phantom
薪资未公开
工作地点Canada, UK, USA
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型Full-Time
发布时间今天
数据来源Jobicy
前往 Jobicy 查看并投递 →
注意地域限制:该职位明确限定在 Canada, UK, USA 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

Phantom 的使命是将世界连接到开放市场的自由。数以千万计的人在全球各地使用 Phantom 来访问永不关闭的全球市场,包括永续合约、预测市场、代币化资产、稳定币和表情包。Phantom 用户能够发现重要的市场和塑造这些市场的文化时刻,通过实时数据和顶级交易者的验证表现建立信心。以自我托管和对开放网络的访问为核心,Phantom 让他们在一个应用中掌控自己的财务决策,这个应用也用于安全地存储或花费全球货币。

Phantom 在 Google Play 的金融类应用中排名第一,并且在所有类别中持续位列前 50 名。Phantom 与 Hyperliquid、Stripe、Kalshi 和 Visa 等金融领域最值得信赖和有影响力的名字合作,让最受欢迎和创新的金融产品为每个人所用。

我们目前有大约 180 名员工,全部远程办公,由 a16z、Sequoia Capital 和 Paradigm 提供的 1.5 亿美元 C 轮融资支持。

安全是 Phantom 产品和数百万用户对我们信任的核心。我们正在打造一个以 AI 为核心的安全部门,积极利用 AI 来扩大我们工作的速度、深度和范围——从代码审查和威胁建模到漏洞发现和安全自动化。我们寻找具有高度自主性的安全工程师,他们能够识别关键风险,构建实际解决方案,并从初步发现到验证修复全程负责。

这是一个实践性强、影响深远的职位,涉及 Phantom 移动端、网页端和后端产品的架构、源代码、测试和生产系统。你将直接与工程和产品团队合作,领导复杂的安全部署,并构建可在公司范围内扩展的能力。在 Staff 级别,你将设定技术方向,并提高 Phantom 设计、构建和交付安全产品的标准。

该职位为全远程办公,面向美国、英国和加拿大的候选人开放。

职责

  • 产品安全责任:与工程团队合作,识别并解决 Phantom 移动应用、网页产品、API 和后端服务中的安全风险。
  • 架构与威胁建模:主导新产品的安全评审和重大架构变更,特别关注授权边界、敏感数据、交易完整性、密钥材料和
查看英文原文

Phantom is on a mission to connect the world to the freedom of open markets. Tens of millions of people all over the world use Phantom to access global markets that never close, including perpetuals, prediction markets, tokenized assets, stablecoins and memes. Phantom users are able to discover the markets that matter and the cultural moments that shape them, building conviction through real-time data and the verified performance of top traders. With self-custody and access to open networks at its core, Phantom lets them control their financial moves in the same app they use to safely store or spend money worldwide.

Phantom has reached #1 in Google Play's finance category and consistently ranks in the top 50 apps across all categories. Phantom partners with many of the most trusted and influential names in finance like Hyperliquid, Stripe, Kalshi and Visa, to make the most popular and innovative financial products accessible to everyone.

We are around 180 people, fully remote, backed by a $150M Series C investment from a16z, Sequoia Capital and Paradigm.

Security is core to Phantom’s product and the trust millions of users place in us. We’re building an AI-native security team that aggressively uses AI to expand the speed, depth, and reach of our work—from code review and threat modeling to vulnerability discovery and security automation. We’re looking for strong security engineers with high agency who can identify the risks that matter, build practical solutions, and take ownership from initial discovery through verified remediation.

This is a hands-on, high-impact role spanning architecture, source code, testing, and production systems across Phantom’s mobile, web, and backend products. You’ll work directly with engineering and product teams, lead complex security initiatives, and build capabilities that scale across the company. At the Staff level, you’ll set technical direction and raise the bar for how Phantom designs, builds, and ships secure products.

This role is fully remote and open to candidates based in the US, UK and Canada.

Responsibilities

  • Product Security Ownership: Partner with engineering teams to identify and address security risks across Phantom’s mobile applications, web products, APIs, and backend services.
  • Architecture and Threat Modeling: Lead security reviews for new products and major architectural changes, with particular attention to authorization boundaries, sensitive data, transaction integrity, key material, and third-party integrations.
  • Secure Product Development: Embed practical security controls into the software development lifecycle, from design and implementation through testing, release, and production operation.
  • Code Review and Security Testing: Perform AI assisted security code reviews and targeted testing of high-risk features. Build repeatable approaches that help find vulnerabilities before they reach production.
  • Security Tooling: Develop and improve tooling that gives engineers fast, actionable security feedback without creating unnecessary friction. Use automation and AI-assisted workflows where they materially improve coverage or speed.
  • Software Supply Chain Security: Harden CI/CD, build, and release systems against supply chain threats, including dependency risk, secrets exposure, build provenance, artifact integrity, and compromised developer or automation workflows.
  • Vulnerability Management: Triage findings from internal testing, researchers, bug bounty submissions, and third-party assessments. Work with owners to determine real-world impact and drive issues through verified remediation.
  • Incident Response: Support the investigation of product security incidents and suspicious activity. Turn lessons from incidents into durable improvements to product architecture, detection, and engineering standards.
  • Technical Leadership: Establish product security patterns and expectations across engineering. At the Staff level, lead ambiguous, cross-functional initiatives and influence architecture beyond any single product team.

Qualifications

  • 5+ years of experience in product security, application security, security engineering, or software engineering, including experience operating at a senior or staff level.
  • Strong understanding of web, mobile, API, and distributed-system security, including authentication, authorization, session management, cryptography, and common vulnerability classes.
  • Hands-on experience building or applying AI-assisted security tooling to test applications and APIs, combining automated analysis with source-code review and manual validation.
  • Demonstrated ability to review production code in one or more languages such as TypeScript, JavaScript, Rust, Python and Go.
  • Experience securing software supply chains and CI/CD systems, including dependencies, build infrastructure, secrets, artifacts, signing, and release integrity.
  • Experience threat modeling complex products and translating security risks into concrete engineering requirements.
  • Strong judgment when evaluating exploitability, business impact, and appropriate remediation.
  • Track record of partnering effectively with engineering and product teams while maintaining a high security bar.
  • Clear written and verbal communication, including the ability to explain technical risk to both engineers and non-security stakeholders.

Nice To Haves

  • Experience securing consumer financial products, wallets, payments, or other systems where client integrity and transaction safety are critical.
  • Familiarity with blockchain systems, smart-contract interactions, transaction simulation, signing workflows, or self-custodial wallet architecture.
  • Experience securing browser extensions or native mobile applications.
  • Experience building and integrating application-security tooling, static or dynamic analysis, security test infrastructure, or policy-as-code controls.
  • Familiarity with AWS, Kubernetes, CI/CD systems, and cloud-native service architectures.
  • Experience working with bug bounty programs or coordinating external security assessments.

Why Work with Us

Phantom is built by a team of experienced product and engineering leaders working to make crypto-powered finance safer and easier to use. Our products serve a large and rapidly growing global community, which makes security engineering here both technically challenging and directly consequential.

This role offers the opportunity to:

  • Protect products used by tens of millions of people.
  • Work on security problems spanning mobile, browser, backend, cloud, and blockchain systems.
  • Shape product architecture early rather than reviewing security only at the end.
  • Build durable security capabilities while the company and product surface continue to grow.
  • Work with engineers who care deeply about product quality, user experience, and security.

Benefits

  • Competitive salary and equity
  • Eligibility to participate in the company’s performance bonus program
  • Comprehensive medical, dental, and vision insurance with 100% coverage
  • Stipend for your ideal remote setup
  • Flexible hours and a supportive remote environment
  • Unlimited vacation—take time when you need it
  • 401(k) retirement plan
  • Monthly wellness benefit
  • Weekly meal benefit
  • Global off-sites

The target base salary for this role will range between $200,000 to $250,000 with the addition of equity and benefits. This is determined by a few factors including your skillset, prior relevant experience, quality of interviews and market factors (such as location) at the point in time of offer.

We strongly encourage candidates of all backgrounds to apply. We believe that our work is stronger with a variety of perspectives, and we’re eager to further diversify our company. If you have a background that you feel would make an impact at Phantom, please consider applying. We’re committed to building an inclusive, supportive place for you to do the best work of your career.

By submitting your resume and application materials, you acknowledge and agree that Phantom Technologies, Inc. ("Phantom") collects and processes your personal information (including application materials, interview records, and related data) to evaluate your candidacy. Phantom may use AI-powered tools and third-party service providers for transcription, note-taking, scheduling, and other administrative tasks. Phantom does not sell your information and your materials will be handled securely and in accordance with applicable data protection laws.

本页面信息整理自 Jobicy,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

资深产品安全工程师

PhantomUnited States、United Kingdom、Canada$200,000 - $250,000/年permanent今天
开发工程限定地区(需当地身份)日间重叠仅 1 小时,需熬夜配合

资深平台安全工程师

PhantomUnited States、Canadapermanent6 天前
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

资深机器学习工程师

PhantomUnited Statespermanent8 天前
AI开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位