Lead Security Engineer

PAXOS LAW P.C.
New York, NY, United States
5 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Key Management Network Security Security Software Systems Integration Cloud Platform System Build Management Vulnerability Analysis

Job description

  • Conduct internal audits of Cloud (Azure, AWS) platform security and implement best practices around key management, network security, monitoring, etc.
  • Create threat models for first party and third party software, research possible vulnerabilities and patch them.
  • Collaborate closely with infrastructure engineers to detect, fix, and prevent future exploits by creating resuable tools and processes.

Operational Security

  • Develop tooling and SOPs such as incident response manuals.
  • Conduct periodic incident response training for team members. Simulating hacks, alerts, and social engineering vectors.
  • Collaborate closely with both the technical and the non-technical staff to secure non-code related attack vectors and protect the weakest link i.e. the humans involved.

Smart Contract / DeFi Security

  • Collaborate closely with the Smart Contract team to conduct internal audits and to set up secure operational practices for the development and maintenance of smart contract protocols..
  • Build and deploy full stack tools for mitigating exploits and financial risks such as
  • Detecting malicious transactions in the mempool and automating pauses across the smart contracts deployed on multiple chains.
  • Defining invariants and detecting violations in realtime.
  • Integrating third party security software where necessary.

Requirements

  • Deep knowledge of cloud infrastructure and web2 security practices.
  • Deep knowledge of cybersecurity standards and social engineering defenses.
  • Experience building full stack applications.
  • Deep Knowledge of the EVM security tooling, testing, and best practices
  • Deep knowledge of common hacks and exploits in DeFi protocols.
  • Deep knowledge of financial attack vectors in DeFi protocols.
  • Experience with CTFs, bugbounties, whitehat activities.

Benefits & conditions

  • Build the Future: Play a critical role in transforming traditional enterprises with innovative crypto solutions.
  • Do Impactful Work: Contribute to projects that have a tangible impact on the global financial landscape.
  • Enable Personal Growth: Benefit from continuous learning and professional development in a rapidly evolving industry with an emphasis on personal career advancement.
  • Receive Competitive Compensation: Receive a competitive salary and participate in directly in ownership structures that provide top-of-the-line benefits.
  • Join A Dynamic Team: Thrive in a fast-paced, agile setting where your ideas are valued and your contributions are recognized.

About the company

Paxos Labs builds enterprise infrastructure that powers the next generation of trusted onchain financial products. We work with the largest financial enterprises in the world to build transparent and verifiable onchain infrastructure that works for end users and everyday financial use cases. If you believe in bringing DeFi and digital assets to the mainstream, consider building your career at Paxos Labs.

We believe security is critical to our culture and long term success. We are hiring a Lead Security Engineer to help take Paxos Labs’s security capabilities to the next level., Joining Paxos Labs means becoming part of a pioneering team at the forefront of financial innovation for the mass market. You will have the opportunity to

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:41 min

Protecting etcd databases using Key Management System plugins

Alex Soto Alex Soto · LIVE

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:03 min

Balancing robust code verification with user liability paradigms

John Woods John Woods · LIVE

Videos

See all

Related articles

See all