Senior Security Engineer - Infrastructure
Ondo Finance- Location
- US
- Workplace
- Remote
- Employment
- Full Time
- Salary
- —
Posted 1mo ago
The employer’s full description could not be read from their board. This is a summary of the posting — follow the apply link for the original.
Responsibilities
- Own cloud security posture across AWS and GCPs: IAM, network, encryption, logging, and account structure.
- Prioritize findings against real risk, drive remediation through engineering, and measure progress.
- Design and enforce IaC guardrails: pre-merge policy-as-code, required modules, and CI gates that make the secure path the default.
- Lead identity and access design across cloud, IdP, and developer platforms.
- Drive least-privilege as a continuously enforced property, not an annual project.
- Own secrets management strategy and migration off of long-lived credentials wherever feasible.
- Run focused offensive testing against our own infrastructure: cloud red-team scenarios, IAM privilege-escalation paths, CI/CD supply-chain attack paths, and lateral-movement chains.
- Translate findings into durable controls.
- Partner with SecOps on detection coverage for cloud control-plane abuse and with Product Security on the infra side of application threat models.
- Drive third-party and supply-chain risk for infra components: container base images, build pipelines, OSS dependencies in Terraform modules, and IaC providers.
- Lead incident response for infra-rooted incidents alongside the SecOps lead.
- Mentor engineers on threat modeling, secure-by-default infra patterns, and how to reason about blast radius.
Requirements
- 3-5+ years in security engineering with deep focus on cloud and/or infrastructure.
- Strong IaC skills — you have written, reviewed, and refactored real IaC at scale, and you can explain the failure modes of large IaC codebases.
- Production experience across AWS, GCP, or Azure.
- Hands-on experience with a cloud security platform
- Strong scripting skills in Python or Go.
- Working knowledge of Kubernetes security (RBAC, admission control, workload identity)
- Comfort owning a domain end-to-end: design, build, operate
Preferred
- Experience defending crypto, fintech, or other targeted environments.
- Experience with CI/CD security
- Adjacent experience in offensive security, application security, or other engineering disciplines welcome
- Familiarity with how on-chain operations interact with off-chain infrastructure
Skills
- Terraform
- AWS
- GCP
- Python
- Go
- Kubernetes
More jobs at Ondo Finance
All 16Site Reliability Engineer - Low-Latency Trading Systems
Ondo Finance · US · today
IT Engineer
Ondo Finance · US · yesterday
Blockchain Engineer
Ondo Finance · United States · 8d ago
Senior Backend Engineer (Trading Infrastructure)
Ondo Finance · Remote · 17d ago
Senior Product Manager, Growth
Ondo Finance · US · 29d ago
Similar roles
IT Support Lead
Nadia Care · Philadelphia, Pennsylvania, United States · USD 70–80/hr · today
Computing Undergraduate Student Intern: DevOps Internship Program - Summer 2027
Llnl · Livermore, CA, United States · USD 23–32/hr · today
IT Support Assistant (Onsite - Phoenix, AZ)
Intelligent Technical Solutions · Phoenix, AZ · USD 15–16/hr · today
Senior Cloud Infrastructure Engineer
Anduril Industries · Washington · District of Columbia · United States · USD 146,000–194,000/yr · today
Senior AI Infrastructure Engineer, Physical Infrastructure
Anduril Industries · Costa Mesa, California, United States · USD 166,000–220,000/yr · today
Network Engineer, Factory Systems and Operational Technology
Anduril Industries · Costa Mesa, California, United States · USD 120,000–170,000/yr · today