411,951open jobs
14,442companies
73,805added this week
Browse all
Location
In office (Denver, New York)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
ether.fi is a decentralized, non-custodial liquid restaking protocol and crypto neobank platform. Headquartered in George Town, Cayman Islands, the company enables crypto investors to stake digital assets while retaining ownership of their private keys through liquid tokens like eETH and weETH. Its service ecosystem includes automated yield-generating Liquid Vaults, native restaking integrated with protocols like EigenLayer, borrowing services, and a crypto-native cash-back credit card (Ether.Fi Cash).

About the Role:

We're looking for a Security Engineer who is equally at home hardening a CI/CD pipeline, reviewing a change to the authentication system on the backend, and triaging a bug bounty submission before lunch.This is a hands-on, builder-first role - not a governance checkbox. You'll own security operations end-to-end, embedded directly into the engineering team and working closely with infrastructure, protocol and platform.

If you treat threat modeling as a design conversation and not a compliance exercise, you're our kind of person.You should only apply for this role if you are ready to come into the office every day and work in person with our team!

What You'll Do:

Security Operations

Own day-to-day security operations: monitoring, alerting, triage, and response

Manage and monitor endpoint security via an EDR system - tune detections, investigate alerts, and drive incidents to resolution

Lead identity lifecycle management, including employee onboarding and off boarding (access provisioning, key rotation, deprovisioning)

Bug Bounty & Vulnerability Management

Be the primary owner of our ImmuneFi program - triaging, reproducing, and responding to incoming submissions daily

Prioritize and track vulnerabilities through to remediation in close collaboration with protocol and engineering teams

Develop internal tooling and processes to make the bounty workflow faster and more consistent

DevSecOps & Pipeline Hardening

Audit and harden CI/CD pipelines - secrets management, supply chain integrity, SAST/DAST integration, build provenance

Own dependency security: identify and remediate vulnerable packages across repositories (yes, including the npm dependency hell)

Establish and enforce security standards across the SDLC

Infrastructure Security

Partner with the infrastructure team to review and harden cloud environments (access controls, network segmentation, least privilege, logging)

Contribute to threat modeling for new systems and architectural changes

Drive implementation of security tooling across the stack

Vendor & External Partner Management

Own relationships with external security vendors and service providers - holding them accountable toSLAs, managing scope, and ensuring findings are actioned

Evaluate and onboard new security tooling as the team and threat landscape evolve

What We're Looking For:

5-8+ years of experience in software and security engineering, with meaningful time in a DevSecOps or security operations context

Strong software engineering fundamentals - you're a builder who writes code, not just policy

Hands-on experience hardening CI/CD pipelines (GitHub Actions, CircleCI, or similar) and cloud infrastructure (AWS, GCP, or equivalent)

Proficiency with endpoint security tooling (CrowdStrike or equivalent EDR)

Comfort owning identity and access management processes, including onboarding/offboarding workflows

Strong communication skills - you can write a clear triage report, give direct feedback to a developer and explain risk to a non-technical stakeholder

Nice to Have:

You were a traditional software engineer before specializing in security

Prior experience at a DeFi protocol, crypto exchange, or blockchain infrastructure company

CTF/security competition background

Contributions to open-source security tooling

What Success Looks Like:

In your first 90 days, you've mapped our attack surface, established a daily rhythm on ImmuneFi, and shipped at least a few meaningful PRs across the full stack. Within six months, you've built enough trust in the team that engineers come to you before shipping sensitive PRs, not after.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
411,951 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Denver
In office • 5+ years exp • Bachelor's Degree
Ruby
TypeScript
Ruby
Ruby on Rails
Databases
ElasticSearch
Redis
DevOps
Amazon S3
AWS
AWS Lambda
CDKTF
CI/CD
CircleCI
Docker
GitHub
GitHub Actions
Jenkins
Terraform
Apply
$180k – $322k per year • In office • 15+ years exp • Bachelor's Degree • Herndon
Python
DevOps
Ansible
AWS
Azure
CI/CD
FinOps
GCP
Red Hat
Terraform
Cybersecurity
FedRAMP
SOC 2
Zero Trust
Management
Google Workspace
ServiceNow
Apply
$109k – $224k per year (Estimated) • Remote • 7+ years exp
AI/ML
Anomaly Detection
LLM
LLM Guardrails
DevOps
AWS
CI/CD
Cybersecurity
Threat Modeling
Apply
$120k – $135k per year • Remote • 5+ years exp • PhD
Python
Ruby
TypeScript
Ruby
Ruby on Rails
Databases
Amazon Aurora
DynamoDB
MySQL
OpenSearch
PostgreSQL
DevOps
Amazon EC2
Amazon ECS
AWS
AWS Fargate
AWS Lambda
CI/CD
Docker
FinOps
GitHub
IAM
Platform Engineering
Terraform
Terragrunt
Cybersecurity
Least Privilege
Apply
$128k – $214k per year • In office • 8+ years exp • Bachelor's Degree
Bash
C#
JavaScript
Python
Ruby
TypeScript
DevOps
AWS
CI/CD
Apply
Fraud Engineer 3 days ago
$84k – $215k per year (Estimated) • Remote/Hybrid • Full-Time • New York • Denver • Dubai
AI/ML
AI Agents
Web3
DeFi
EtherFi
Apply
$150k – $250k per year • In office • Full-Time • 3+ years exp • Denver • Dubai • New York
Web3
DeFi
EtherFi
Design
Figma
Apply
$120k – $180k per year • In office • Full-Time • 4+ years exp • Denver • Dubai • New York
SQL
Web3
DeFi
Ethereum
EtherFi
Liquid Staking
Smart Contracts
Staking
The Graph
Analytics
Tableau
Apply
Smart Contract Lead 4 months ago
$240k – $300k per year • In office • Contractor • Bachelor's Degree • New York • Denver • Dubai
Solidity
Web3
DeFi
Ethereum
EtherFi
Foundry
Hardhat
Liquid Staking
Smart Contracts
Staking
Apply
$170k – $200k per year • Remote/Hybrid • Full-Time • 5+ years exp • New York • Denver
DevOps
CI/CD
Web3
DeFi
EtherFi
Apply
$129k – $215k per year • In office • 7+ years exp • Bachelor's Degree • Denver
JavaScript
Perl
Python
DevOps
Kibana
Logstash
VMWare
Apply
$140k – $160k per year • In office • PhD • Denver
Apply
$145k – $175k per year • In office • 5+ years exp • Master's Degree • Denver
Apply
$143k – $180k per year • In office • 6+ years exp • PhD • Denver
Apply
$140k – $160k per year • In office • PhD • Denver
Apply
See all jobs
This is one of many
411,951 more open roles from verified company boards, updated every day.