Senior Security Engineer - Infrastructure
Ondo Finance- Location
- US
- Workplace
- Remote
- Employment
- Full Time
- Salary
- —
Posted 1mo ago
The employer’s full description could not be read from their board. This is a summary of the posting — follow the apply link for the original.
Responsibilities
- Own cloud security posture across AWS and GCPs: IAM, network, encryption, logging, and account structure.
- Prioritize findings against real risk, drive remediation through engineering, and measure progress.
- Design and enforce IaC guardrails: pre-merge policy-as-code, required modules, and CI gates that make the secure path the default.
- Lead identity and access design across cloud, IdP, and developer platforms.
- Drive least-privilege as a continuously enforced property, not an annual project.
- Own secrets management strategy and migration off of long-lived credentials wherever feasible.
- Run focused offensive testing against our own infrastructure: cloud red-team scenarios, IAM privilege-escalation paths, CI/CD supply-chain attack paths, and lateral-movement chains.
- Translate findings into durable controls.
- Partner with SecOps on detection coverage for cloud control-plane abuse and with Product Security on the infra side of application threat models.
- Drive third-party and supply-chain risk for infra components: container base images, build pipelines, OSS dependencies in Terraform modules, and IaC providers.
- Lead incident response for infra-rooted incidents alongside the SecOps lead.
- Mentor engineers on threat modeling, secure-by-default infra patterns, and how to reason about blast radius.
Requirements
- 3-5+ years in security engineering with deep focus on cloud and/or infrastructure.
- Strong IaC skills — you have written, reviewed, and refactored real IaC at scale, and you can explain the failure modes of large IaC codebases.
- Production experience across AWS, GCP, or Azure.
- Hands-on experience with a cloud security platform
- Strong scripting skills in Python or Go.
- Working knowledge of Kubernetes security (RBAC, admission control, workload identity)
- Comfort owning a domain end-to-end: design, build, operate
Preferred
- Experience defending crypto, fintech, or other targeted environments.
- Experience with CI/CD security
- Adjacent experience in offensive security, application security, or other engineering disciplines welcome
- Familiarity with how on-chain operations interact with off-chain infrastructure
Skills
- Terraform
- AWS
- GCP
- Python
- Go
- Kubernetes
More jobs at Ondo Finance
All 15Similar roles
Staff AI Engineering - Enterprise Architecture
American Express · Phoenix, AZ, United States · USD 144,250–256,250/yr · today
Field Service Technician II
Toshiba America Business Solutions · East Syracuse, NY, United States · today
Field Service Technician I
Toshiba America Business Solutions · Rochester, NY, United States · today
Field Service Technician II
Toshiba America Business Solutions · Buffalo, NY, United States · today
Incentives Analyst
MicroStrategy · Tysons Corner, VIRGINIA, United States · USD 66,400–119,600/yr · today
Senior Azure Cloud Engineer
Vaxcyte · San Carlos, California, United States · today