368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$123k – $248k per year (Estimated)
Location
In office (New York)
Seniority
Senior · 5+ years exp
Employment
Contractor
Overview
Company
Impact
Profile match
Ondo Finance is building a DeFi protocol providing a suite of decentralized investment banking products and services to connect institutional investors and token issuers. We have just scratched the surface of opportunity in DeFi with services like lending, trading, and basic derivatives. We see a huge opportunity to bring a wider array of products from traditional finance to DeFi and create new financial primitives.

About Ondo

Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. We operate at the intersection of traditional finance and on-chain systems, which means our product surface has to hold up against both the ordinary threats that hit any high-value fintech and the specific ones that follow value on-chain.

About the Role

We are hiring a Senior Security Engineer - Product Security to own how we ship secure products at Ondo. You will be a security partner for our product engineering teams, driving threat modeling, owning secure code reviews for new products or feature expansions, maintaining and tuning AppSec tooling, and improving the existing SSDLC. You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native approach is welcome, paired with AI-driven approaches should expect to be justified by describing how doing so enables risk outcomes.

This is a hands-on IC role. You will read code, run threat models, review architecture proposals, own tooling, and push engineering teams to build products that are secure by default. You partner closely with adjacent security function like AppSec, Infrasec, and SecOps.

What You'll Do

  • Drive threat modeling for new features, integrations, and architectural changes across the product surface. Push threat models past templates into decisions that engineering teams actually implement.
  • Own secure code review for high-risk changes - authentication, session management, cryptographic paths, wallet and signing flows, RPC and third-party integrations, permission and consent surfaces.
  • Expand the AppSec tooling stack and treat "reducing false positives" as a first-class deliverable. AI-native integrations are welcome.
  • Design and evolve our secure SDLC: where security fits in the dev workflow, what triggers a review, what a lightweight security sign-off looks like versus a full one, and how do we validate controls.
  • Run our responsible disclosure and bug bounty program. Set scope, triage inbound reports, decide payouts, and drive findings to closure with engineering.
  • Support and own appropriate scope for the intake and closure of findings from external audits and pentests - coordinate with audit vendors (Coinspect, Cantina, NCC Group, and others), organize findings into our internal risk register, and drive remediation with engineering owners.
  • Partner with engineering leads to align o secure-by-default patterns - libraries, templates, sensible defaults, and paved-road implementations of anything security-relevant.
  • Threat model blockchain-integrated components like wallet flows, RPC integrations, signing infrastructure, on-chain admin actions triggered from off-chain systems in partnership with engineers who own the on-chain code.
  • Contribute to hiring, mentoring, and pushing the technical bar on the Security team.

What We're Looking For

  • 5+ years in Product Security or Application Security, including senior IC time at a fast-moving product company.
  • Deep secure code review skills in at least one modern stack (TypeScript / JavaScript, Python, or Go). Ability to move across stacks at the level required to threat model.
  • Strong threat modeling skills, appropriate to experience - you can drive a real threat model with an engineering team, not just fill in a template. In practice, we look for core understanding of industry-relevant TTPs and IoCs and strong intuitions on how to apply those lessons learned to our products.
  • Practical experience owning or majorly contributing to an AppSec tooling program. You have shipped rules, tuned noise, and measured impact.
  • Comfortable running or building a bug bounty / responsible disclosure program end-to-end assuming properly resourced to do so.
  • Strong working knowledge of modern web and API security - session and auth flows, OAuth and OIDC, browser security model, common web/API vulnerability classes, and their less-common variants.
  • Comfortable reading Terraform, cloud IAM policies, and CI/CD configuration well enough to reason about how a product vulnerability crosses into an infra risk.
  • Strong engineering partnership skills - you engage constructively, understand the "why" before proposing risk controls, you know when to accept risk, and you write things down.
  • Willing to grow into blockchain-adjacent product security on the job, including the specific attack surface introduced by wallet, signing, and on-chain-integration code.

Blockchain Exposure Note

  • This role firmly lives in Web2 prodsec. But, it also requires someone who understands what "Web2 vs Web3" terminology means. In other words, how our products interact with blockchains creates unique threat models that all product security teammates must grasp. At a minimum, by Day 1 you should have strong intuitions about how blockchains will make your prodsec experience unique, you should grasp the common terminologies, and you should be able to discuss with colleagues several incident post-mortems that demonstrate how Web2 compromises lead to Web3 funds losses.
  • You do not need to be an expert in smart contract auditing, blockchain security architectures, or decentralized consensus-driven risk controls.

Nice to Have

  • Prior work at a crypto, fintech, or other company where products handle high-value or irreversible actions.
  • Familiarity with wallet, signing, or key-management flows.
  • Reading-level familiarity with Solidity or Rust, target: when ProdSec intersects with smart contracts or other on-chain applications, you can parse what the code is likely doing, and work with blockchain security subject matter experts from there.
  • Bug bounty history - reports, CVEs, or published write-ups.
  • Familiarity with browser-extension security, mobile app security, or account-abstraction wallet designs.
  • Public output - talks, blog posts, open-source tools, CVEs.

How We Work

The Security team values a high trust team environment where respectful candor can thrive. We expect senior engineers to have an opinionated take on how to accomplish a task, accept feedback from the team and other external stakeholders and return it in kind, and to always assume positive intent. Professionalism, ethics, and enabling stakeholders towards common goals are important always.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
New York
$84k – $178k per year (Estimated) • In office • Full-Time • 10+ years exp • Wellington
Java
Python
DevOps
Ansible
AWS
Azure
CI/CD
Docker
GCP
Helm
Kubernetes
Platform Engineering
Prometheus
Service Mesh
Terraform
GitLab
IAM
Apply
$98k – $195k per year (Estimated) • In office • Full-Time • 7+ years exp • Wellington
Java
Python
SQL
Java
Spring Boot
Databases
Apache Kafka
Databricks
Neo4j
AI/ML
Flink
Spark
Frontend
GraphQL
DevOps
Azure
CI/CD
Datadog
Dynatrace
Kibana
Kubernetes
OpenShift
Platform Engineering
Splunk
Amazon ECS
Apply
$28k – $58k per year (Estimated) • Remote/Hybrid • Full-Time • 7+ years exp • Moscow
DevOps
Ansible
CI/CD
FinOps
Kubernetes
OpenStack
SLI/SLO/SLA
Terraform
VMWare
Apply
Platform Engineer 1 day ago
$87k – $140k per year • In office • Full-Time • 3+ years exp • Berlin
Databases
PostgreSQL
Redis
DevOps
AWS
Azure
Bicep
CI/CD
Docker
GCP
GitHub Actions
Kubernetes
OpenShift
Terraform
GitHub
Apply
$123k – $251k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Dallas • Denver • Birmingham
Java
SQL
Java
Gradle
Hibernate
Maven
Spring Boot
Spring Framework
Databases
Apache Kafka
MySQL
Redis
DevOps
CI/CD
Dynatrace
Jenkins
Kubernetes
OpenShift
Cybersecurity
SonarQube
Apply
$120k – $263k per year (Estimated) • Remote • Contractor • 4+ years exp • Bachelor's Degree • New York
JavaScript
Node JS
Solidity
TypeScript
Frontend
React.js
DevOps
AWS
Web3
Aptos
Arbitrum
DeFi
Ethereum
Smart Contracts
Solana
Sui
Uniswap
Apply
$122k – $227k per year (Estimated) • Remote • 5+ years exp • New York
Go
Python
DevOps
AWS
Azure
CI/CD
GCP
Kubernetes
Platform Engineering
Terraform
IAM
Cybersecurity
Threat Modeling
Least Privilege
Web3
Uniswap
Apply
$136k – $233k per year (Estimated) • Remote • Full-Time • 5+ years exp • New York
DevOps
AWS
Web3
DeFi
Smart Contracts
Uniswap
Apply
$122k – $266k per year (Estimated) • Remote • Contractor • 5+ years exp • Bachelor's Degree • New York
Python
Solidity
TypeScript
DevOps
AWS
Web3
DeFi
Smart Contracts
Solana
Uniswap
Apply
$143k – $238k per year (Estimated) • Remote • Contractor • 6+ years exp • New York
C++
Go
Python
Solidity
TypeScript
Solidity
Moralis
DevOps
AWS
Web3
Alchemy
DeFi
Smart Contracts
The Graph
Uniswap
Apply
$155k per year • In office • Full-Time • New York
Apply
$220k – $350k per year • Remote/Hybrid • Full-Time • 15+ years exp • New York • Princeton
AI/ML
AI Agents
LLM Guardrails
Model Context Protocol
DevOps
Azure
Azure DevOps
CI/CD
GitHub
Platform Engineering
Design
Figma
Management
Jira
QA
Playwright
Apply
$160k – $283k per year • Equity • In office • 5+ years exp • New York
AI/ML
AI Agents
Apply
$80k – $115k per year • In office • Full-Time • PhD • New York
Apply
$60k – $116k per year (Estimated) • Remote/Hybrid • Bachelor's Degree • New York
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.