Security Analyst

Aptos, Inc
United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$120,000.0 - $180,000.0
Working hours
Regular working hours
Job source

Tech stack

User Authentication Business Systems Software as a Service Cyber Security Identity and Access Management Issue Tracking Systems Local Security Policy Open Web Application Security Role-Based Access Control Phishing Web Applications Large Language Models
+3 more
Software Security Spoofing Web3.js

Job description

Aptos Foundation is seeking a Security Analyst to help operate and scale security across the organization. Reporting to the Security Lead, this role will support core security workflows spanning phishing response, bug bounty operations, access governance, and operational security hygiene. This is a hands-on, cross-functional role offering broad exposure across security operations, access governance, and threat response-ideal for someone looking to develop a wide view of security in a fast-moving organization., * Respond to and triage alerts relating to phishing attacks, impersonation, scams, and brand abuse (e.g. Sublime, Doppel), escalating credible threats where appropriate.

  • Coordinate day-to-day operation of the bug bounty program, including communication with researchers, issue tracking, reporting, and internal follow-up.
  • Conduct user access reviews and review security settings, access configurations, and administrative controls across business systems, SaaS platforms, and internal infrastructure, tracking remediation where required.
  • Support recurring operational security workflows, including documentation, process tracking, and follow-up.

Requirements

Do you have experience in Cross-functional communication?, * 2+ years of experience in a security-focused role, such as security operations, IAM, application security support, operational security, or a similar domain.

  • Familiarity with core security concepts including phishing, authentication, access control, least privilege, and common vulnerability classes.
  • Ability to manage multiple concurrent workflows with strong attention to detail and reliable follow-through.
  • Clear written communication and confidence coordinating across technical and non-technical stakeholders.
  • Self-motivated, organized, and comfortable operating independently in a remote-first environment with minimal supervision.

Nice to Have

  • Experience automating operational workflows using LLMs or AI tooling (e.g. Claude).
  • Familiarity with common web application vulnerabilities (e.g. OWASP Top 10).
  • Exposure to vulnerability disclosure / bug bounty workflows.
  • Experience with SaaS administration, access reviews, or IAM processes.
  • Experience in web3 environments or familiarity with common web3 threat patterns.

The base salary range for this full-time position is $120k - $180k. The range displayed on each job posting reflects the minimum and typical maximum target for new hire salaries for the position of a candidate based in the Bay Area at any level. We do hire exceptionally talented professionals with decades of experience in their field. As such, our range may be higher than what is displayed. Our base salary ranges are determined by experience and location, and we hire at all levels for multiple roles. Within the range, individual pay is determined by work location, job-related skills demonstrated during the interviews, working experience, and relevant education or training. Please note that the compensation details listed in role postings reflect the base salary only and do not include equity, tokens, or benefits.

Benefits & conditions

$120,000 - $180,000 a year - Full-time, Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Vision insurance
  • Dental insurance, Our Benefits
  • 100% insurance premium coverage for medical, dental, and vision for you and your dependents (US Employees)
  • Equipment of your choice
  • Flexible vacation time, 11 holidays, and floating company days off
  • Competitive Salary
  • Protocol Token Grants
  • 401k matching (US Employees)
  • Fun and inclusive in-person and digital events

About the company

Aptos is a people-first blockchain on a mission to help billions of people achieve universal and fair access to decentralized assets in a safe and scalable way.

Founded by some of the original creators and maintainers that researched, designed, and built the Diem blockchain to serve this purpose, we have dedicated several years toward this mission. We believe the open-source Diem technology we have developed is an important foundation of a safe and scalable web3 world where everyone has more equitable opportunities to grow and access financial assets with lower fees and fewer intermediaries.

Aptos (Ohlone for “The People”) encompasses our mission and ethos for why we build.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

44 sec

Blocking container spoofing attacks by removing raw network access

Mathias Tausig · WWC 2023

3:26 min

Automating programmable logic using smart contracts and JavaScript tools

Ryan Arndt · WWC 2023

3:24 min

Evaluating remote software roles and compensation structures

Nacho Iacovino · WWC 2021

1:26 min

Spear phishing IT administrators with malicious VoIP spoofing

Mauro Verderosa · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

Videos

See all

Related articles

See all