SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
EtherFi is seeking a hands-on Security Engineer to own security operations end-to-end, embedded directly into the engineering team. This is a builder-first role focused on practical security hardening rather than compliance checkboxes.
You will manage day-to-day security operations including monitoring, alerting, triage, and incident response. You'll own endpoint security via EDR systems, tuning detections and investigating alerts. Identity lifecycle management—employee onboarding, offboarding, access provisioning, key rotation, and deprovisioning—falls under your purview.
As primary owner of the ImmuneFi bug bounty program, you'll triage and reproduce submissions daily, prioritize vulnerabilities, and drive remediation in collaboration with protocol and engineering teams. You'll develop internal tooling and processes to streamline the bounty workflow.
On the DevSecOps side, you'll audit and harden CI/CD pipelines, manage secrets, ensure supply chain integrity, and integrate SAST/DAST tooling. You'll own dependency security across repositories and establish security standards throughout the software development lifecycle.
You'll partner with infrastructure teams to review and harden cloud environments, contribute to threat modeling for new systems, and drive implementation of security tooling. You'll also manage relationships with external security vendors, hold them accountable to SLAs, and evaluate new security tools as the threat landscape evolves.
This role requires you to come into the office every day and work in person with the team.
REQUIREMENTS:
- 5+ years of experience in software and security engineering, with meaningful time in DevSecOps or security operations
- Strong software engineering fundamentals; you write code, not just policy
- Hands-on experience hardening CI/CD pipelines (GitHub Actions, CircleCI, or similar)
- Cloud infrastructure hardening experience (AWS, GCP, or equivalent)
- Proficiency with endpoint security tooling (CrowdStrike or equivalent EDR)
- Comfort owning identity and access management processes, including onboarding/offboarding workflows
- Strong communication skills: clear triage reporting, direct developer feedback, risk explanation to non-technical stakeholders
NICE TO HAVE:
- Background as a traditional software engineer before specializing in security
- Prior experience at a DeFi protocol, crypto exchange, or blockchain infrastructure company
- CTF/security competition background
- Open-source security tooling contributions