{"id":1400402,"url":"https://alion.io/job/nodeworthy-senior-security-engineer","title":"Senior Security Engineer","company":{"id":684264,"name":"Nodeworthy","domain":"nodeworthy.co","url":"https://alion.io/company/nodeworthy","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Recruitee","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"explicit","locations":["Singapore"],"countries":["SG"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":64000,"max_usd":115000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":18},"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":false},{"name":"DeFi","optional":false},{"name":"GCP","optional":false},{"name":"GitHub","optional":false},{"name":"Go","optional":false},{"name":"IAM","optional":false},{"name":"Java","optional":false},{"name":"Kubernetes","optional":false},{"name":"Least Privilege","optional":false},{"name":"Node JS","optional":false},{"name":"Python","optional":false},{"name":"Rust","optional":false},{"name":"Solana","optional":false},{"name":"TypeScript","optional":false},{"name":"JavaScript","optional":true}],"status":"live","first_seen_at":"2026-09-28T07:33:28Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-09-28T15:12:02Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Senior Security Engineer\nLocation: Singapore or Kuala Lumpur\nEmployment Type: Full-time\nAbout the Opportunity\nNodeworthy is supporting a leading Solana-based decentralized exchange in hiring a Senior Security Engineer.\nYou will own and continuously improve the security of the company’s engineering and production environment. The role spans cloud infrastructure, DevOps, SRE, backend services, frontend applications, CI/CD pipelines and internal engineering systems.\nThis is a deeply hands-on position. The successful candidate must be able to do more than review systems and recommend improvements-you should be comfortable investigating incidents, modifying code and infrastructure, deploying fixes, monitoring the results and taking responsibility for production outcomes.\nThe ideal profile is an experienced DevOps or infrastructure engineer with strong security instincts and solid backend engineering capabilities. You may investigate suspicious production activity, strengthen cloud controls and contribute directly to backend or DevOps work within the same week.\nSmart-contract auditing and protocol-level security reviews are handled by a separate internal team and are not part of this role.\nWhat You’ll Own\nSecurity Monitoring and Incident Response\nBuild and maintain security monitoring, logging, detection and alerting across infrastructure and applications.\n\nMonitor cloud resources, production services, databases, APIs, CI/CD systems and engineering environments for suspicious activity.\n\nEstablish processes for identifying, triaging, investigating and responding to security incidents.\n\nInvestigate unusual access patterns, authentication attempts, API activity, infrastructure changes and abnormal application behaviour.\n\nLead incident containment, remediation, root-cause analysis and post-incident reviews.\n\nDevelop and maintain practical incident-response playbooks.\n\nDefine security metrics and provide clear reporting to engineering leadership.\n\nContinuously improve the organisation’s detection and response capabilities.\n\nCloud and Infrastructure Security\nOwn the security posture of the company’s cloud and production infrastructure.\n\nSecure and monitor GCP environments, including IAM, service accounts, Kubernetes, networking, compute, storage, databases and managed services.\n\nImplement appropriate access controls and least-privilege policies.\n\nStrengthen the management of credentials, secrets, API keys, service accounts and privileged access.\n\nIdentify and remediate misconfigurations, unnecessary permissions, exposed services and other infrastructure risks.\n\nIntroduce network segmentation and additional controls around sensitive systems.\n\nEstablish secure infrastructure baselines and monitor environments for deviations.\n\nWork closely with DevOps and SRE engineers to incorporate security into infrastructure architecture and operational processes.\n\nCI/CD and Software-Supply-Chain Security\nSecure CI/CD pipelines, build systems, deployment infrastructure and engineering tooling.\n\nIdentify and reduce software-supply-chain risks.\n\nStrengthen the security of source-code repositories, build environments, deployment credentials and automation systems.\n\nImplement branch protections, access controls, secrets management and production deployment safeguards.\n\nIntroduce automated security checks into development and deployment workflows where appropriate.\n\nReview infrastructure-as-code and deployment configurations for security weaknesses.\n\nEnsure production deployments are auditable and have suitable approval, recovery and rollback controls.\n\nHelp developers adopt secure practices without unnecessarily slowing delivery.\n\nApplication and Engineering Security\nConduct security reviews of new products, services, APIs, features and infrastructure.\n\nIdentify vulnerabilities involving authentication, authorisation, injection, insecure configurations, data exposure and software dependencies.\n\nEstablish practical secure-coding and engineering standards.\n\nReview third-party services and dependencies for security risks.\n\nImprove API, endpoint, authentication and service-to-service security.\n\nPartner with frontend engineers to identify and mitigate client-side risks.\n\nDefine appropriate security requirements during technical and product design.\n\nBackend and DevOps Engineering\nContribute directly to backend services and APIs when required.\n\nReview backend architecture for security, scalability, reliability and maintainability.\n\nIdentify and fix vulnerabilities within backend systems.\n\nImplement controls such as authentication, authorisation, rate limiting and input validation.\n\nImprove API security and service-to-service authentication.\n\nDebug production incidents and performance issues.\n\nParticipate in architecture discussions and code reviews.\n\nProvide additional backend or DevOps engineering capacity when needed.\n\nWho You’ll Work With\nThis is a cross-functional role working closely with:\nBackend and frontend engineering.\n\nDevOps and SRE.\n\nProduct and operations.\n\nExternal security researchers and auditors, where appropriate.\n\nYou will have significant autonomy and direct responsibility for the security and reliability of production systems.\nRequirements\nWhat We’re Looking For\nEssential Experience\nAt least 7 years of hands-on experience across DevOps, cloud infrastructure and production systems.\n\nStrong knowledge of cloud security, particularly Google Cloud Platform and Kubernetes.\n\nDeep understanding of networking, IAM, authentication, authorisation and secrets management.\n\nExperience securing CI/CD pipelines and infrastructure-as-code.\n\nExperience building and operating security monitoring, logging and alerting systems.\n\nStrong incident-response capabilities, from initial investigation through containment, root-cause analysis and remediation.\n\nAbility to navigate large codebases, infrastructure configurations, logs and production environments independently.\n\nStrong backend engineering experience with the ability to contribute directly to backend and DevOps code.\n\nProficiency in at least one relevant backend language, such as Go, Python, TypeScript/Node.js, Java or Rust.\n\nStrong debugging, analytical and problem-solving skills.\n\nAbility to operate independently within a fast-moving engineering environment.\n\nWorking knowledge of cryptocurrency, blockchain, DeFi and exchange infrastructure.\n\nBonus Experience\nPrevious experience with a cryptocurrency, blockchain, DeFi, exchange or financial-technology company.\n\nSignificant production experience with Google Cloud Platform.\n\nExperience securing high-availability or high-throughput financial systems.\n\nExperience collaborating with external security researchers, penetration testers or auditors.\n\nDiploma or bachelor’s degree in Computer Science, Cloud Security, Infrastructure Security or a related discipline.\n\nScope Clarification\nThis position focuses on cloud, infrastructure, application, operational and engineering security. Smart-contract auditing and protocol-security reviews fall outside the scope of the role.\nLocation Requirement\nCandidates must be based in Singapore or Kuala Lumpur.\nApplication\nThis is a confidential search managed by Nodeworthy.\nTo apply, please submit:\nYour CV.\n\nA brief description of a security incident you investigated and how you resolved it.\n\nExamples of cloud, DevOps, SRE or backend systems you have built or secured.\n\nYour GitHub profile or technical portfolio, if available.\n\nShortlisted candidates will receive further information about the company and opportunity directly from Nodeworthy.","description_format":"text","description_chars":7574,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Singapore","iso":"SG","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Blockchain & Crypto"],"lifecycle":[{"event":"open","at":"2026-09-28T15:12:02Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":23,"reasons":["conf:11","win:early"],"computed_at":"2026-09-29T02:19:35Z"},"pay":null,"html_url":"https://alion.io/job/nodeworthy-senior-security-engineer","json_url":"https://alion.io/job/nodeworthy-senior-security-engineer.json","meta":{"generated_at":"2026-09-29T02:19:35Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1987,"day_limit":5000,"remaining_today":3013,"minute_limit":60,"resets_at":"2026-09-30T00:00:00Z"}}}