вчера

security engineer for crypto-powered finance

выше рынка на 327,1%
вакансия 1 403 292 ₽
в среднем 328 556 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Phantom connects people to open financial markets through a self-custodial platform for accessing perpetuals, prediction markets, tokenized assets, stablecoins, and other crypto-powered financial products. Its platform is used by tens of millions of people worldwide and supports the secure storage and spending of money.

задачи

  • Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails;
  • Secure production Kubernetes environments running on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation;
  • Design least-privilege access models for engineers, services, and automation;
  • Build scoped, auditable, and time-bound access paths for sensitive production systems;
  • Protect infrastructure supporting products and services that handle sensitive data and high-value operations;
  • Lead security design for new infrastructure, platform services, and major architectural changes;
  • Build reusable security controls using Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation;
  • Harden build, deployment, and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and access to production environments;
  • Build tools that identify and remediate cloud and Kubernetes risks at scale;
  • Apply AI-assisted workflows where they materially improve analysis, coverage, or response speed;
  • Partner with Infrastructure, SRE, Developer Experience, and product engineering teams;
  • Establish practical platform-security standards and help teams adopt them;
  • Secure AWS and Kubernetes systems supporting products used by millions of people;
  • Build controls directly in the platform rather than operating as an advisory or review-only security function;
  • Influence architecture early and own improvements through implementation and production verification;
  • Help shape an AI-native security team with a strong engineering and automation culture.

требования

  • 7+ Years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role;
  • Deep hands-on experience securing production AWS environments, including IAM, resource policies, workload identity, network security, secrets management, logging, and organization-level controls;
  • Deep experience securing Kubernetes in production, preferably Amazon EKS, including RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening;
  • Experience designing or securing mission-critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business impact;
  • Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across human and machine access;
  • Experience securing CI/CD and software supply chains, including GitHub Actions or similar systems, build runners, workload federation, artifacts, and production deployment paths;
  • Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools;
  • Ability to write production-quality code or automation in TypeScript, Python, Go, or Rust;
  • High agency and ownership, with the ability to take an ambiguous platform-security problem from initial investigation through implementation and verified remediation;
  • Clear communication and a strong track record of partnering with infrastructure and engineering teams while maintaining a high security bar;
  • Nice to have: Experience with AWS Nitro Enclaves or other trusted execution environments, financial, payments, wallet, custody, or other high-value transaction systems, key-management infrastructure, AWS KMS, CloudHSM, cryptographic signing systems, or secrets-management platforms, multi-region Kubernetes and AWS environments at significant scale, service meshes and cloud-native networking technologies such as Istio, PrivateLink, Transit Gateway, or eBPF-based controls, GitHub OIDC, Argo CD, Helm, Crossplane, or Kubernetes-based infrastructure delivery, cloud-security and observability platforms such as Wiz, Datadog, GuardDuty, Security Hub, or CloudTrail, policy-as-code, automated remediation, or security tooling used by a large engineering organization, blockchain infrastructure or self-custodial wallet architecture.

условия

  • Competitive salary and equity;
  • Eligibility to participate in the company’s performance bonus program;
  • Comprehensive medical, dental, and vision insurance with 100% coverage;
  • Stipend for an ideal remote setup;
  • Flexible hours;
  • Unlimited vacation;
  • 401(K) retirement plan;
  • Monthly wellness benefit;
  • Weekly meal benefit;
  • Global off-sites;
  • Candidates must be based in the US or Canada.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.