技术员工,安全
Member of Technical Staff, Security
开发工程限定地区(需当地身份)
公司Anchorage
薪资未公开
工作地点United States
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型Full-Time - Remote
发布时间未知
数据来源Lever
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
技术技能:
- 构建和维护安全自动化工具,通过静态和动态分析在代码和实时系统中检测漏洞。
- 进行应用安全评估、渗透测试和代码审查,识别高风险安全问题并提供安全开发指导。
- 开发和运营漏洞管理流程,与工程团队合作优先处理并修复发现的问题。
- 在Anchorage平台的整个过程中建立并测试针对代码、云资源和基础设施组件的安全控制措施。
工作的复杂性与影响:
- 监控并响应组织内的安全事件和配置异常,领导调查和遏制工作。
- 管理从发现到修复的完整漏洞生命周期,跟踪进度并确保及时关闭发现的问题。
- 在最少监督的情况下领导或实质性参与安全项目,协调跨团队边界推动项目完成。
- 将复杂的安全问题分解为可管理的工作流,提供准确的范围和时间估算。清晰地呈现选项并提供经过深思熟虑的优先级建议。
- 提供符合监管机构要求的保证文档和证据,支持审计和合规工作。
- 平衡响应速度与调查的彻底性,根据风险和业务影响调整方法。
组织知识:
- 理解并协助实施公司的安全策略,通过参与规划和定义与Anchorage Digital总体目标一致的安全目标。
- 保持对新兴威胁、漏洞和行业趋势的警觉,这些可能会影响组织的安全态势。
- 在整个产品生态系统(应用程序、基础设施和第三方集成)中全面考虑安全,同时培养以安全为先的文化。
- 与工程、基础设施和合规团队跨职能协作,将安全嵌入开发和运营流程中。
沟通与影响力
- 通过文档、操作手册和事后回顾在团队中广泛分享知识,防止单一故障点。
- 与工程团队合作解释安全风险和修复方法,将技术发现转化为可操作的指导。
- 跨团队协作审查安全配置,进行优先级排序
查看英文原文
Technical Skills:
- Build and maintain security automation and tooling to detect vulnerabilities through static and dynamic analysis across code and live systems.
- Conduct application security assessments, penetration tests, and code reviews to identify high-risk security issues and provide secure development guidance.
- Develop and operate vulnerability management workflows, partnering with engineering teams to prioritize and remediate findings.
- Establish and test security guardrails for code, cloud resources, and infrastructure components throughout the Anchorage platform.
Complexity and Impact of Work:
- Monitor and respond to security events and configuration anomalies across the organization, leading investigation and containment efforts.
- Manage the full vulnerability lifecycle from discovery through remediation, tracking progress and ensuring timely closure of findings.
- Lead or substantially contribute to Security initiatives with minimal oversight, coordinating across team boundaries to drive projects to completion.
- Break complex security problems into manageable workstreams with accurate scope and time estimates. Present options clearly and provide well-reasoned priority recommendations.
- Deliver assurance artifacts and evidence for regulated entity requirements, supporting audit and compliance efforts.
- Balance speed of response with thoroughness of investigation, adapting approach based on risk and business impact.
Organizational Knowledge:
- Understand and help implement the company's security strategy by participating in planning and defining Security goals in alignment with Anchorage Digital's overall objectives.
- Stay alert to emerging threats, vulnerabilities, and industry trends that could affect organizational security posture.
- Consider security holistically across the product ecosystem—applications, infrastructure, and third-party integrations—while fostering a security-first culture.
- Collaborate cross-functionally with Engineering, Infrastructure, and Compliance teams to embed security into development and operational processes.
Communication and Influence
- Share knowledge broadly across the team through documentation, runbooks, and post-incident reviews, preventing single points of failure.
- Partner with engineering teams to explain security risks and remediation approaches, translating technical findings into actionable guidance.
- Collaborate across teams to review security configurations, triage findings, and engage in technical discussions. Communicate insights and recommendations clearly to improve processes.
- Demonstrate empathy by understanding others' context, priorities, and constraints—adapting communication style to maximize effectiveness with both technical and non-technical audiences.
You may be a fit for this role if you have:
- Security or AppSec experience: You have 3+ years of hands-on experience in security engineering, application security, penetration testing, or security.
- Security tooling and automation: You have built or maintained security tools, integrations, or automation workflows using Python, Go, or similar languages.
- Vulnerability assessment: You can identify and assess security vulnerabilities in applications, APIs, and cloud infrastructure, and effectively communicate remediation strategies.
- Static and dynamic analysis: You have experience with tools like Semgrep, CodeQL, Burp Suite, or equivalent for identifying security issues in code and running systems.
- Cloud security: You understand AWS security fundamentals including IAM, VPCs, security groups, and CloudTrail/logging.
- Incident response: You can investigate security events, perform root cause analysis, and coordinate response efforts.
- You have developed "computer science fundamentals," i.e. concurrency, algorithms, and data structures.
- You genuinely care about code quality and operational excellence.
- You prioritize security outcomes, end-user experience, and business value over "cool tech."
- You self-describe as some combination of the following: creative, humble, ambitious, detail-oriented, hardworking, trustworthy, eager to learn, methodical, action-oriented, and tenacious.
Although not a requirement, bonus points if:
- You have experience running or participating in bug bounty programs (HackerOne, Bugcrowd, etc.).
- You have worked in a regulated financial services, fintech, or crypto environment.
- You have exposure to blockchain security, smart contract auditing, or Web3 technologies.
- You have built or contributed to open-source security tools.
- You hold relevant certifications (OSCP, GWAPT, GCIH, AWS Security Specialty, etc.).
- You read blockchain protocol white papers for fun, and stay up to date with the proliferation of crypto-asset innovations.
- You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system. :)
本页面信息整理自 Lever,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。
本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。
该公司其他在招职位
亚太区负责人,稳定币解决方案
其他限定地区(需当地身份)
衍生品交易员
其他未标注地域
工程负责人,安全
开发工程限定地区(需当地身份)
机构销售代表 - 全球市场
市场运营限定地区(需当地身份)
客户运营成员,ACH
职能支持限定地区(需当地身份)