远程工作雷达

高级安全工程师 - 产品安全

Senior Security Engineer - Product Security

开发工程全球可投
公司Ondo Finance
薪资未公开
工作地点不限地点
地域资格全球可投
时区要求无特别要求
用工类型未标注
发布时间未知
数据来源CryptoJobsList
前往 CryptoJobsList 查看并投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

标签:Web3 职位 • 区块链安全职位 • 加密货币高级职位 • Web3 工程职位 • Web3 远程职位 • 加密货币全职职位 • 区块链 Web3 职位
关于 Ondo
Ondo Finance 正在为代币化的现实资产构建机构级金融基础设施。我们处于传统金融和链上系统的交汇点,这意味着我们的产品必须经受住任何高价值金融科技所面临的普通威胁,以及跟随价值上链的特定威胁。
关于该职位
我们正在招聘一名高级安全工程师 - 产品安全,负责我们在 Ondo 如何交付安全的产品。你将成为我们产品工程团队的安全合作伙伴,推动威胁建模,负责新产品的安全代码审查或功能扩展,维护和优化应用安全工具,改进现有的 SSDLC。你可以期望负责漏洞赏金计划、现有产品的新功能审查,以及与专门的 ProdSec 主管配对的关键功能的广泛责任。欢迎采用以 AI 为中心的方法,但应通过描述这样做的方式如何实现风险结果来加以证明。
这是一项实际操作的 IC 角色。你将阅读代码、运行威胁模型、审查架构提案、负责工具,推动工程团队构建默认安全的产品。你将与相邻的安全职能如应用安全(AppSec)、基础设施安全(Infrasec)和安全运营(SecOps)紧密合作。
你将负责
为产品范围内的新功能、集成和架构变更驱动威胁建模。将威胁模型从模板推导到工程团队实际实施的决策。
负责高风险变更的安全代码审查——认证、会话管理、加密路径、钱包和签名流程、RPC 和第三方集成、权限和同意界面。
扩展应用安全工具栈,并将“减少误报”作为首要交付成果。欢迎以 AI 为中心的集成。
设计并演进我们的安全 SDLC:安全在开发工作流中的位置,什么触发审查,轻量级安全签核与完整签核的区别,以及我们如何验证控制措施。
运行负责任的披露和漏洞赏金计划。设定范围,分类传入报告,决定支付,与工程团队协作推动发现的解决。
支持并负责外部审计和渗透测试发现的纳入和解决的适当范围——协调与审计方

查看英文原文

Tags: Web3 Jobs • Blockchain Security Jobs • Web3 Senior Jobs • Blockchain Engineering Jobs • Blockchain Remote Jobs • Blockchain Full Time Jobs • Blockchain Web3 JobsAbout OndoOndo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. We operate at the intersection of traditional finance and on-chain systems, which means our product surface has to hold up against both the ordinary threats that hit any high-value fintech and the specific ones that follow value on-chain.About the RoleWe are hiring a Senior Security Engineer - Product Security to own how we ship secure products at Ondo. You will be a security partner for our product engineering teams, driving threat modeling, owning secure code reviews for new products or feature expansions, maintaining and tuning AppSec tooling, and improving the existing SSDLC. You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native approach is welcome, paired with AI-driven approaches should expect to be justified by describing how doing so enables risk outcomes.This is a hands-on IC role. You will read code, run threat models, review architecture proposals, own tooling, and push engineering teams to build products that are secure by default. You partner closely with adjacent security function like AppSec, Infrasec, and SecOps.What You’ll DoDrive threat modeling for new features, integrations, and architectural changes across the product surface. Push threat models past templates into decisions that engineering teams actually implement.Own secure code review for high-risk changes — authentication, session management, cryptographic paths, wallet and signing flows, RPC and third-party integrations, permission and consent surfaces.Expand the AppSec tooling stack and treat “reducing false positives” as a first-class deliverable. AI-native integrations are welcome.Design and evolve our secure SDLC: where security fits in the dev workflow, what triggers a review, what a lightweight security sign-off looks like versus a full one, and how do we validate controls.Run our responsible disclosure and bug bounty program. Set scope, triage inbound reports, decide payouts, and drive findings to closure with engineering.Support and own appropriate scope for the intake and closure of findings from external audits and pentests — coordinate with audit vendors (Coinspect, Cantina, NCC Group, and others), organize findings into our internal risk register, and drive remediation with engineering owners.Partner with engineering leads to align o secure-by-default patterns - libraries, templates, sensible defaults, and paved-road implementations of anything security-relevant.Threat model blockchain-integrated components like wallet flows, RPC integrations, signing infrastructure, on-chain admin actions triggered from off-chain systems in partnership with engineers who own the on-chain code.Contribute to hiring, mentoring, and pushing the technical bar on the Security team.What We’re Looking For5+ years in Product Security or Application Security, including senior IC time at a fast-moving product company.Deep secure code review skills in at least one modern stack (TypeScript / JavaScript, Python, or Go). Ability to move across stacks at the level required to threat model.Strong threat modeling skills, appropriate to experience - you can drive a real threat model with an engineering team, not just fill in a template. In practice, we look for core understanding of industry-relevant TTPs and IoCs and strong intuitions on how to apply those lessons learned to our products.Practical experience owning or majorly contributing to an AppSec tooling program. You have shipped rules, tuned noise, and measured impact.Comfortable running or building a bug bounty / responsible disclosure program end-to-end assuming properly resourced to do so.Strong working knowledge of modern web and API security - session and auth flows, OAuth and OIDC, browser security model, common web/API vulnerability classes, and their less-common variants.Comfortable reading Terraform, cloud IAM policies, and CI/CD configuration well enough to reason about how a product vulnerability crosses into an infra risk.Strong engineering partnership skills - you engage constructively, understand the “why” before proposing risk controls, you know when to accept risk, and you write things down.Willing to grow into blockchain-adjacent product security on the job, including the specific attack surface introduced by wallet, signing, and on-chain-integration code.Blockchain Exposure NoteThis role firmly lives in Web2 prodsec. But, it also requires someone who understands what “Web2 vs Web3” terminology means. In other words, how our products interact with blockchains creates unique threat models that all product security teammates must grasp. At a minimum, by Day 1 you should have strong intuitions about how blockchains will make your prodsec experience unique, you should grasp the common terminologies, and you should be able to discuss with colleagues several incident post-mortems that demonstrate how Web2 compromises lead to Web3 funds losses.You do not need to be an expert in smart contract auditing, blockchain security architectures, or decentralized consensus-driven risk controls.Nice to HavePrior work at a crypto, fintech, or other company where products handle high-value or irreversible actions.Familiarity with wallet, signing, or key-management flows.Reading-level familiarity with Solidity or Rust, target: when ProdSec intersects with smart contracts or other on-chain applications, you can parse what the code is likely doing, and work with blockchain security subject matter experts from there.Bug bounty history - reports, CVEs, or published write-ups.Familiarity with browser-extension security, mobile app security, or account-abstraction wallet designs.Public output - talks, blog posts, open-source tools, CVEs.How We WorkThe Security team values a high trust team environment where respectful candor can thrive. We expect senior engineers to have an opinionated take on how to accomplish a task, accept feedback from the team and other external stakeholders and return it in kind, and to always assume positive intent. Professionalism, ethics, and enabling stakeholders towards common goals are important always.Apply here 👉 Senior Security Engineer - Product Security

本页面信息整理自 CryptoJobsList,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位