Security Engineer

GALAXY, INC.
United States
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Bash Shell Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Collaborative Software CompTIA Security+ Cyber Security Databases
+24 more
Information Leak Prevention Email Filtering Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) PCI Data Security Standards Windows PowerShell Cloud Services Phishing Zero Trust Network Access Software Deployment Software Vulnerability Management Data Logging Scripting Google Cloud Enterprise Software Applications Cloud Platform System Software Troubleshooting Spoofing Kubernetes Information Technology Malware Detection CIS Benchmarks Network Server

Job description

This role is primarily responsible for the administration, engineering, and continuous improvement of the organization’s enterprise email security, email-based Data Loss Prevention (DLP), and Privileged Access Management (PAM) capabilities. The Security Engineer will play a critical role in protecting business communications, sensitive data, privileged accounts, and critical systems while helping strengthen the organization’s overall security posture.

In addition to owning these core security platforms, the Security Engineer will support broader security operations, infrastructure security, incident response, cloud security, and security engineering initiatives. This role works closely with Security Operations, Infrastructure, Cloud Engineering, IT, and Engineering teams to implement security best practices, improve operational resilience, and support ongoing security projects.

The ideal candidate has strong experience securing enterprise communications, protecting sensitive data, managing privileged access, and implementing practical security controls across modern enterprise environments.

What You’ll Do:

Email Security & Data Protection

  • Administer and support enterprise email security platforms and threat protection technologies.
  • Configure, tune, and maintain anti-phishing, anti-spam, malware detection, impersonation protection, and email filtering controls.
  • Administer and optimize email-based Data Loss Prevention (DLP) policies, monitoring, and enforcement capabilities.
  • Investigate email security alerts, phishing incidents, business email compromise attempts, and DLP events, coordinating remediation efforts as needed.
  • Collaborate with business and security stakeholders to identify, classify, and protect sensitive information.
  • Support data protection initiatives across email, SaaS platforms, cloud services, endpoints, and collaboration tools.
  • Develop and maintain security controls that reduce the risk of data exposure through business communications and user workflows.

Privileged & Infrastructure Access Security

  • Administer, maintain, and enhance enterprise privileged access management and infrastructure access security platforms.
  • Support secure access solutions for administrators, internal users, contractors, and third parties.
  • Manage identity-aware access controls for infrastructure, cloud environments, administrative systems, and critical resources.
  • Partner with Infrastructure and Identity teams to support authentication, authorization, and least-privilege access models.
  • Support secure access controls across cloud and on-premises environments, including servers, databases, Kubernetes clusters, and other critical infrastructure.
  • Participate in access reviews, entitlement validation, and privileged account governance initiatives.
  • Assist with the implementation and continuous improvement of Zero Trust access controls and infrastructure access security practices.

Security Platform Engineering & Operations

  • Administer and support enterprise security technologies including identity, endpoint, monitoring, logging, and cloud security platforms.
  • Support onboarding, configuration, integration, and troubleshooting of security tools and services.
  • Monitor platform health, operational performance, and security control effectiveness.
  • Collaborate with Infrastructure and IT teams to ensure security controls remain properly configured and maintained.
  • Assist with implementation and operationalization of new security technologies and security initiatives.

Security Operations & Incident Response

  • Support the Security Operations team in monitoring, detecting, investigating, and responding to security incidents.
  • Participate in incident investigations, root cause analysis, containment, and remediation activities.
  • Assist with threat detection, vulnerability remediation, and continuous monitoring efforts.
  • Support investigations involving identity systems, cloud environments, enterprise applications, and business-critical platforms.

Security Engineering & Continuous Improvement

  • Assist with automation of operational and security processes using scripting, APIs, or workflow automation tools.
  • Participate in platform evaluations, security assessments, and infrastructure hardening initiatives.
  • Work closely with Engineering, Infrastructure, and IT teams to improve enterprise security controls.
  • Contribute to security projects and operational initiatives as business needs evolve.
  • Evaluate emerging security technologies and opportunities to improve operational efficiency and security effectiveness.

Compliance & Governance

  • Support compliance initiatives related to SOC 2, ISO 27001, PCI-DSS, and other applicable regulatory frameworks.
  • Assist with maintaining security documentation, standards, procedures, and operational runbooks.
  • Participate in audit preparation, evidence collection, and remediation activities.
  • Support governance efforts related to identity security, privileged access controls, and data protection requirements.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
  • 6+ years of experience in cybersecurity, security engineering, infrastructure security, or related roles.
  • Experience administering or supporting enterprise email security, data protection, privileged access management, infrastructure access management, or related security technologies.
  • Experience working with enterprise security controls including identity and access management, endpoint security, security monitoring, and incident response.
  • Familiarity with cloud platforms such as AWS, Azure, or Google Cloud.
  • Understanding of Zero Trust principles, least privilege access models, identity security, email security, infrastructure access security, and data protection concepts.
  • Experience with scripting or automation using PowerShell, Python, Bash, or similar technologies.
  • Security certifications such as Security+, CISSP, GIAC, cloud security certifications, or equivalent experience are a plus.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Excellent written and verbal communication skills.

Bonus Points:

  • Experience with privileged access management (PAM) technologies.
  • Experience supporting cloud security and SaaS environments.
  • Familiarity with AI governance, AI security frameworks, or secure AI deployment practices.
  • Familiarity with compliance frameworks such as NIST, SOC 2, ISO 27001, or CIS benchmarks.
  • Security certifications such as Security+, CISSP, GIAC, CEH, or cloud security certifications.

Benefits & conditions

  • Competitive base salary and discretionary bonus
  • Hybrid/Flexible Working Arrangements
  • Flexible Time Off (paid)
  • 3% 401(k) company contribution
  • Company-paid health and protective benefits for employees, partners, and other dependents
  • Generous paid Parental Leave
  • Competitive family planning benefits for US employees
  • Opportunities to learn about the Crypto industry
  • Smart, entrepreneurial, and fun colleagues
  • Free daily snacks and weekly breakfasts/lunches
  • Employee Resource Groups
  • Free coaching and counseling sessions through Headspace

About the company

Who We Are: Galaxy is a global leader in digital assets and data center infrastructure, delivering solutions that accelerate progress in finance and artificial intelligence. We believe that blockchain and digital asset innovation will transform how value moves through the world - and we’re building the products and services to make that future a reality.

Our institutional digital assets platform spans trading, investment banking, asset management, staking, self-custody, and tokenization technology. We also invest in and operate cutting-edge data center infrastructure to power AI and high-performance computing, addressing the growing demand for scalable energy and compute in the U.S.

We work at the intersection of finance and technology, helping institutions, startups, and developers navigate a digitally native economy. Led by CEO and Founder Michael Novogratz, our team blends deep crypto expertise with institutional experience and a shared commitment to shaping the future of Web3 and AI.

Galaxy is headquartered in New York City, with offices across North America, Europe, the Middle East, and Asia.

To learn more about our businesses and products, visit

What We Value:

We are a diverse team of free thinkers, and fast movers united to help investors and creators energize the global economy. We are looking for individuals who thrive in a culture of builders and overachievers and embrace high performance, transparent feedback, and a mission-first approach. Our culture shapes our way of working and gets us where we want to be.

  • Seek Excellence.
  • Be Selective To Be Effective.
  • Be Highly Aligned, Loosely Coupled.
  • Disagree Transparently.
  • Encourage Independent Decision-Making.
  • Build Dream Teams.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

44 sec

Blocking container spoofing attacks by removing raw network access

Mathias Tausig · WWC 2023

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:26 min

Spear phishing IT administrators with malicious VoIP spoofing

Mauro Verderosa · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

Videos

See all

Related articles

See all