Trusted institutional partner in crypto and first federally chartered crypto bank
Member of Technical Staff – Security Engineering
Location
United States
Posted
60 days ago
Salary
0
Seniority
Lead
Job Description
Member of Technical Staff – Security Engineering
Anchorage Digital
• Develop and implement high-quality, secure code for cryptographic controls throughout our infrastructure. • Review code throughout the technology stack and help engineering teams resolve issues related to security guardrails. • Foster an efficient testing culture while reducing technical debt and unnecessary processes. • Build robust, resilient components that are easily integrated by other teams to ensure asset and data security. • Develop and maintain threat models for cryptosystem guarantees, both internal and external. Monitor technical debt and proactively identify areas for improvement. • Lead or substantially contribute to medium and large Security Team initiatives with minimal oversight. Coordinate team members across engineering boundaries and drive projects from inception to completion. • Break complex projects into manageable tasks with accurate time and scope estimates. Present options clearly, analyze tradeoffs thoroughly, and provide well-reasoned priority recommendations. • Deliver work that aligns with departmental objectives, subject to review upon completion. Take ownership of tactical business targets that affect team performance. • Understand and help implement the company's strategy by participating in planning and defining the Security Team's strategic goals in alignment with Anchorage Digital's overall objectives. • Stay alert to emerging company objectives and industry trends that could affect organizational success. • Consider security holistically across the entire product ecosystem while fostering a security-first company culture. • Balance speed of delivery with careful planning and precision. • Share knowledge broadly across the team while preventing single points of failure. • Mentor and guide engineers throughout the Engineering team. Help them understand security's impact on Anchorage Digital's strategic goals, enabling them to develop new technologies and services safely with appropriate oversight. • Collaborate across teams to solve problems, review specifications, and engage in technical discussions. Communicate insights and recommendations clearly to improve processes and address technical debt. • Demonstrate empathy by understanding others' context, needs, motivations, and concerns—adapting communication style to maximize effectiveness.
Job Requirements
- Deep understanding of modern cryptography: Proficiency in symmetric and asymmetric encryption, hashing algorithms, key management, and cryptographic protocols. Blockchain protocols experience is a plus.
- Secure coding expertise: Demonstrated ability to write secure, efficient, and well-documented code in Go, C++, C, and Rust, with a focus on cryptographic implementations.
- Systems thinking: Ability to analyze complex systems, identify potential vulnerabilities, and design robust security solutions within a distributed architecture. Experience with Hardware Security Modules is a plus.
- Strong problem-solving skills: Capacity to troubleshoot cryptographic issues, analyze security threats, and develop effective mitigation strategies.
- Excellent communication and collaboration: Ability to clearly explain complex cryptographic concepts to both technical and non-technical audiences.
- Cryptography: You possess a strong foundation in applied cryptography, including symmetric/asymmetric encryption, hashing algorithms, digital signatures, key exchange protocols, and common cryptographic libraries.
- Security Architecture and Implementation: You can contribute to the design and implementation of secure systems, with a focus on security best practices and industry standards.
- Hardware Security Modules (HSMs): You have experience with the configuration and use of HSMs for secure key generation, storage, and management, and understand their role in protecting sensitive cryptographic operations.
- Authentication and Authorization: You understand and can implement various authentication and authorization mechanisms, including multi-factor authentication, OAuth 2.0, and role-based access control (RBAC).
- Threat Modeling: You can identify and assess potential threats to systems and applications, and effectively prioritize mitigation strategies.
- You have developed “computer science fundamentals”, i.e. concurrency, algorithms, and data structures
- You genuinely care about code quality and test infrastructure.
- You prioritize security, end-user experience, and business value over “cool tech.”
- You self-describe as some combination of the following: creative, humble, ambitious, detail-oriented, hardworking, trustworthy, eager to learn, methodical, action-oriented, and tenacious.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Design Architect
Control RisksThe global specialist risk consultancy - Helping organisations succeed in a volatile world
• Lead daily operations and direct the implementation of guidelines and processes that ensures a cohesive, consistent, and uniformed global program. • Manage end-to-end protective design scope (pre-lease, planning, design, construction, quality assurance) ensuring on-time delivery while driving execution. • Partner with other project specialists responsible for similar processes to collaborate and consolidate project work. • Manage builds of existing and new construction and retrofits, protective design consultant selection, and third-party vendor recommendations. • Act as the liaison and point of contact for both internal and external cross-functional partners, third party vendors, and protective design consultants. • Foster strong cross-functional partnerships and provide clear, concise communication to both technical and non-technical stakeholders. • Meet regularly with stakeholders and project design teams to provide status updates and coordinate project specific requirements. • Provide ongoing communication of planning, project status, issues and risks in a timely fashion to internal global security team members and cross functional partners. • Support continual improvement efforts through evaluation of current practices; investigation of new products; development of presentation materials, forms, and guidance documents; coordination and execution of pilots for programs; and present recommendations and provide business justification to relevant partners.
Security Engineer – Cloud Security
SRM TechnologiesHelping automotive, healthcare, logistics & consumer sectors thrive with integrated Digital & Engineering solutions!
• Implement secure configurations across AWS, GCP, Azure, Oracle Cloud • Manage IAM policies and least privilege access • Monitor alerts from CSPM tools • Handle phishing analysis and response • Monitor alerts across SIEM, EDR, CSPM
• Work closely with engineering teams to design secure solutions • Serve as a security subject matter expert • Lead threat modeling discussions • Empower engineering teams with automation and security guidance • Drive high-impact, cross-team security initiatives • Understand Stripe’s security primitives and frameworks • Mentor teammates
Security Compliance Analyst – Regulatory Affairs
TwilioTwilio is a Platform-as-a-Service (PaaS) company established in 2007. In support of a flexible workplace, Twilio has previously posted freelance, flexible schedule, part-time, hybr
• Support the SCRA Lead in executing Twilio’s global security regulatory strategy • Independently interpret complex and ambiguous regulatory frameworks • Support the development and maintenance of regulatory repositories and systems of record • Execute and continuously improve the Cyber Regulation Intake & Triage process • Map regulatory requirements to internal control frameworks • Develop regulator-ready and high-quality artifacts • Identify, analyze, and escalate regulatory risks and audit obligations • Partner cross-functionally with teams • Drive execution of process improvements, tooling enhancements, and automation initiatives • Operate with high ownership and accountability




