FalconX logo
FalconX

The most technologically advanced digital asset trading platform in the world.

Product Security Engineer – DeFi

Security EngineerSecurity EngineerOtherRemoteMid LevelTeam 51-200H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

81 days ago

Salary

$179K - $226K / year

Seniority

Mid Level

Job Description

Product Security Engineer – DeFi

FalconX

Who are we? FalconX is a pioneering team of operators, investors, and builders committed to revolutionizing institutional access to the crypto markets. Operating at the intersection of traditional finance and 
cutting-edge technology, FalconX addresses the industry's foremost challenges: Navigating the digital asset market can be complex and fragmented, with limited products and services that support trading strategies, structures, and liquidity found in conventional financial markets. As a comprehensive solution for all digital asset strategies from start to scale, FalconX operates as the connective tissue empowering clients with seamless navigation through the ever-
evolving cryptocurrency landscape. Location: Remote / Hybrid Role FalconX is seeking a Product Security Engineer to focus on DeFi product and application security. You will partner with engineering and product teams to review proposed strategies, assess smart contracts for security risks, and guide secure design decisions. This role reports into the FalconX Security Team, and in addition to DeFi-focused work, you’ll contribute to broader application security initiatives such as data security, identity and access management (IAM), secure development lifecycle (SDLC), and code review practices. Responsibilities - Review DeFi strategies, protocol designs, and smart contracts for security risks and failure modes. - Evaluate markets-related activities (e.g., liquidity provision, governance, cross-protocol integrations) for systemic vulnerabilities. - Provide secure design input for new features and applications. - Identify and mitigate threats including reentrancy, oracle manipulation, flash loan exploits, MEV, and governance exploits. - Partner with the security team to advance application security initiatives: - Threat modeling and design reviews. - Data security and access control design. - Identity and access management (IAM). - SDLC improvements and developer enablement. - Collaborate with external auditors and internal stakeholders to validate findings and track remediation. Requirements - 4+ years in application/product security, with strong exposure to DeFi protocols and markets. - Expertise in smart contract security (Solidity, EVM internals, known attack classes). - Experience with threat modeling and secure design reviews. - Familiarity with DeFi primitives (AMMs, lending, oracles, governance, bridges). - Understanding of cryptography, key management, and wallet security. - Strong ability to articulate risks and propose secure alternatives. Preferred - Contributions to security research, audits, or open-source tooling in DeFi. - Background in data security, IAM, or application-layer controls. - Experience in financial markets or risk assessment. The base pay for this role is expected to be between $179,000-226,000 USD for a Senior Associate level in the New York City and San Francisco Bay Area. This expected base pay range is based on information at the time this post was generated. This role will also be eligible for other forms of compensation such as a performance linked bonus, equity, and a competitive benefits package. Actual compensation for a successful candidate will be determined based on a number of factors such as location, skillset, experience, qualifications and the level at which the candidate is hired. Notice at Collection and Privacy Policy Applicants located in California and/or applying to a role based in California, please refer to our Notice at Collection and Privacy Policy here. Inclusivity Statement FalconX is committed to building a diverse, inclusive, equitable, and safe workspace for all people. Our roles are intended for people from all walks of life. We encourage all those interested in applying to our organization to submit an application regardless if you are missing some of the listed background requirements, skills, or experiences! As part of our commitment to inclusivity, FalconX would like to acknowledge that the EEOC survey has limited potential responses that you can select. For legal reasons, FalconX must use this language to align with federal requirements, however, we want to ensure that you are able to provide a response to our own voluntary survey questions about your identity that best aligns with your most true self. FalconX is an equal opportunity employer and will not discriminate against an applicant or employee based on race, color, religion, national origin, ancestry, ethnicity, sex (including gender, pregnancy, sexual orientation, and gender identity), age, physical or mental disability, veteran or military status, genetic information, citizenship, or any other legally-recognized protected basis under federal, state, or local law. Applicants with disabilities may be entitled to reasonable accommodation under the Americans with Disabilities Act and other applicable state or local laws. A reasonable accommodation is a change in the way things are normally done which will ensure an equal employment opportunity without imposing undue hardship on FalconX. Please inform FalconX’s People team at recruiting@falconx.io, if you need assistance with participating in the application process.

Job Requirements

  • 4+ years in application/product security, with strong exposure to DeFi protocols and markets.
  • Expertise in smart contract security (Solidity, EVM internals, known attack classes).
  • Experience with threat modeling and secure design reviews.
  • Familiarity with DeFi primitives (AMMs, lending, oracles, governance, bridges).
  • Understanding of cryptography, key management, and wallet security.
  • Strong ability to articulate risks and propose secure alternatives.
  • Preferred contributions to security research, audits, or open-source tooling in DeFi.
  • Background in data security, IAM, or application-layer controls.
  • Experience in financial markets or risk assessment.

Benefits

  • The base pay for this role is expected to be between $179,000-226,000 USD for a Senior Associate level in the New York City and San Francisco Bay Area.
  • This expected base pay range is based on information at the time this post was generated.
  • This role will also be eligible for other forms of compensation such as a performance linked bonus, equity, and a competitive benefits package.
  • Actual compensation for a successful candidate will be determined based on a number of factors such as location, skillset, experience, qualifications, and the level at which the candidate is hired.

Related Categories

Related Job Pages

More Security Engineer Jobs

Inspira Financial logo

Sr. Security Engineer (Customer Identity) (Remote)

Inspira Financial

Inspira Financial provides health, wealth, retirement, and benefits solutions that strengthen and simplify the health and wealth journey. With more than 7 million clients, representing over $62 billion in assets, Inspira works with thousands of employers, plan sponsors, recordkeepers, TPAs, and other institutional partners — helping the people they care about plan, save, and invest for a brighter future. Inspira relentlessly pursues better outcomes for all with our automatic rollover services, health savings accounts, emergency savings funds, custody services, and more. Learn more at inspirafinancial.com.

OtherRemoteTeam 1,537Since 2000

Join Us! Take the next step in your journey at Inspira Financial. You will help businesses and individuals thrive today, tomorrow, and into retirement. Become part of a company that is people centric and client obsessed in every interaction; a community of forward-thinking individuals focused on driving results to deliver our mission with an unwavering commitment to integrity. Join us as we strengthen and simplify the health and wealth journey -- relentlessly pursuing better outcomes for all. We believe in finding the best talent! While some roles are based at one of our office locations, remote roles can sit in any of the following states: AL, AZ, FL, GA, IA, IL, IN, MI, MN, MO, NC, NE, PA, SC, TN, TX, UT, VA and WV. Remote status and role locations are subject to change. Relocation is not provided. Employees within a 90-minute radius of our Oak Brook, IL headquarters are required to adhere to the company in-office work guidelines of 4 days per month minimum from 10 am to 2 pm (1 of the 4 days must be a Monday or Friday). This requirement does not apply to support specialist positions. Don't meet every single requirement? Here at Inspira Financial, we believe there is no "perfect" candidate and want to encourage applying even if all the requirements listed aren't met. Our goal is to build an authentic workplace by valuing diversity in our candidates. We work to ensure that our team reflects the diversity of the businesses and clients we serve. We are always looking to expand our growing team with dynamic and enthusiastic individuals. If you enjoy a collaborative, fun environment that champions career development, Inspira Financial is the place for you! We look forward to receiving your application! Check out this Inspira Financial video to learn more about our company! Inspira Financial provides health, wealth, retirement, and benefits solutions that strengthen and simplify the health and wealth journey. With more than 7 million clients, representing over $62 billion in assets, Inspira works with thousands of employers, plan sponsors, recordkeepers, TPAs, and other institutional partners -- helping the people they care about plan, save, and invest for a brighter future. Inspira relentlessly pursues better outcomes for all with our automatic rollover services, health savings accounts, emergency savings funds, custody services, and more. Learn more at inspirafinancial.com . We have been recognized for our remarkable growth on lists such as Crain's Fast 50 and Inc. 5000, and for our outstanding workplace culture and benefits with Built In's 2025 Best Places to Work and Gallagher's 2022 Best-In-Class Employer awards. Job Summary & Responsibilities The Customer Identity Senior Engineer is responsible for building, maintaining , and operating the company's customer identity platform. This role ensures secure, reliability , and scalable authentication and access services across multiple customer-facing products. The Customer Identity Senior Engineer serves as the technical owner for customer identity lifecycle, authentication policies, and platform integrations. This position requires strong troubleshooting skills, scripting capability, and a service-oriented mindset to support business requirements, uptime, compliance, and product team enablement. Duties & Responsibilities: - Implement, configure, and maintain enterprise customer identity and access management (CIAM) services. - Support onboarding of new applications, APIs, and services into the customer identity ecosystem. - Manage platform lifecycle activities including patching, maintenance, and capacity planning. - Develop and maintain operational runbooks, standards, and procedures for identity services. - Build and maintain automation for customer account lifecycle and access provisioning workflows. - Partner with product and development teams to establish secure integration patterns using OAuth2, OIDC, and SAML. - Monitor and optimize authentication performance and error handling through data-driven insights. - Serve as the escalation point for complex authentication and customer access issues. - Lead incident, problem, and change management activities related to CIAM systems. - Devise and propose CIAM strategy through stakeholder information gathering , monitoring of metrics , analysis of emerging threats, and understanding of best practice trends . Preferred Qualifications Education & Experience: - 5+ years of experience in Identity and Access Management, with at least 2 years focused on customer identity (CIAM) or authentication systems. - Bachelor's degree in computer science , Software/Computing Engineering, Applied Mathematics or related field - Technical Certifications a plus Skills & Abilities: - Strong understanding of modern identity protocols: OIDC, OAuth2, SAML, SCIM. - Hands-on experience with PingOne identity platforms . - Proven scripting and automation skills (PowerShell, Python, or comparable). - Demonstrated troubleshooting ability across complex cloud and hybrid authentication environments. - Excellent communication, documentation, and cross-functional collaboration skills. - Experience with adaptive MFA, risk-based access, or passkey authentication. - Familiarity with CI/CD pipelines, version control, and infrastructure-as-code (e.g., GitHub, Terraform). - Exposure to service management frameworks (ITIL) and compliance-driven operations (SOC 2, HIPAA, PCI DSS). - Understanding of cloud security and API integration principles. - Experience with compliance frameworks (SOC 2, HIPAA, PCI) and audit support. - Experience with version control systems (Git) and CI/CD pipelines for automation code. - Proven troubleshooting and analytical skills, with a methodical approach to problem solving. - Familiarity with APIs, REST/JSON, and automation frameworks. - Ability to communicate complex technical issues clearly to both technical and non-technical audiences. Compensation & Benefits $106,000-$134,000 per year

Illinois
$62K - $134K / year

Cybersecurity Specialist 2

COLSA Corporation

COLSA Corporation provides commercial and government clients with high-quality information technology (IT), programmatic, and engineering services. As an employ

Role Description COLSA is seeking a Cybersecurity Specialist to deliver and sustain capabilities in a fast-paced SAFe Agile development environment, while providing cybersecurity direction and supporting the consolidation of NASA’s enterprise IT systems. This is a remote position. Candidates must reside in a state where COLSA currently conducts business or is authorized to employ staff. - Apply knowledge of concepts, processes, practices, and procedures on technical assignments. - Support enterprise Cybersecurity standards. - Develop and implement Cybersecurity standards and procedures in accordance with government regulations. - Coordinate, develop, and recommend security processes. - Recommend Cybersecurity solutions to support customers’ requirements. - Identify and report security violations. - Recommend and satisfy Cybersecurity requirements based upon the analysis of CSPP, policy, regulatory, and resource demands. - Support customers at the highest levels in the development and implementation of processes and policies. - Apply know-how to government and commercial common user systems, as well as to dedicated special purpose systems requiring specialized security features and procedures. - Support design and development of security features for system architecture requirements. - Analyze and make recommendations of security requirements for computer systems which may include mainframes, workstations, and personal computers. - Support design, development, engineering, and implementation of solutions that meet CSPP requirements. - Provide integration and implementation of the computer system security solution. - Analyze general Cybersecurity-related technical problems and provide basic engineering and technical support in solving these problems. - Support vulnerability/risk analyses of computer systems and applications during all phases of the system development life cycle. - Perform all procedures necessary to ensure the safety of information systems data assets and to protect systems from intentional or inadvertent access, theft, or destruction. - Ensure that all information systems are functional and secure. - Ensure cyber monitoring is performed timely and cyber responses occur within established processes/procedures. - Support efforts for critical processes outside of normal hours to include nights, weekends, and holidays. - Deploy rapid response to quickly resolve cyber events. - Communicate with senior customer stakeholders on reporting metrics (e.g., number of events, average time to respond, affected applications or platforms, etc.). - Prepare and distribute cyber/IA required reporting. Company Description At COLSA, people are our most valuable resource and centered at our core value. We invite you to unite your talents with opportunity and be a part of our “Family of Professionals!” Learn about our employee-centric culture and benefits here.

United States
$99K / year
Job Closed
ECS Tech Inc logo

Engineer

ECS Tech Inc

All candidates must meet the following criteria: Must be a US Citizen, no dual Citizenships. Must be able to secure a Public trust clearance. Must be able to work across multiple programs across the Federal and DOD space. The core values that ECS looks for in an engagement manager include: Teamwork, Respect, Accountability, Integrity, and Leadership.

OtherRemoteH1B No Sponsor

Role Description ECS is seeking an experienced Engineer to serve as the subject matter expert (SME). This is a critical backfill position aimed at stabilizing and improving the AESS (Army Endpoint Security Solutions) footprint. - Act as the primary McAfee SME - Administer and configure McAfee ePO, including agent deployment, policy development, and system compliance - Provide engineering and endpoint security support to an onsite customer team - Serve as the point of contact for AESS services and liaise with the U.S.-based Ops team - Provide direct support to the local customer team and CONUS-based Ops team - Assist in detection, monitoring, and troubleshooting of endpoint security events - Collaborate with security, IT, and engineering teams to refine enterprise endpoint strategy and deployment methods Qualifications - Experience deploying and managing ePO - 8570 Level II certification (e.g., Security+) - Active Secret clearance with ability to obtain TS/SCI - Comfortable working independently - 6+ years experience Requirements - Experience with ePO (deployment, configuration) - Background in AESS - Understanding of Tychon for endpoint visibility, vulnerability assessment, configuration hygiene, and operational remediation tasks - Windows Administration experience - Must be self-driven and able to learn/adapt on the job, learn new technologies, and operate with minimal oversight - Work independently to manage assigned tasks, document procedures, and contribute to process improvements Benefits - General Description of Benefits

United States
Job Closed
ServiceTitan logo

Senior Cloud Security Engineer

ServiceTitan

The operating system for the trades

OtherRemoteTeam 1,001-5,000Since 2012H1B Sponsor

• Integrate robust security controls directly into CI/CD platforms such as GitHub, GitLab, Jenkins, or Azure DevOps. • Evaluate and implement pipeline-based security Infrastructure as Code (IaC) scanning. • Build and optimize developer feedback loops and automated remediation workflows. • Build and maintain IAM security controls across cloud platforms, assessing policies to enforce the principle of least privilege. • Develop and implement secure infrastructure baselines, vulnerability management processes, and hardening standards across AWS, Azure, or GCP environments. • Guide engineering teams on secure architecture design for cloud apps, microservices, serverless services, and PaaS workloads. • Secure in-house and public AI/ML systems against cyber threats, adversarial attacks, and unauthorized access.

United States
$137.9K - $184.5K / year