GMI Jobs is currently showing this Lead Security Engineer role at Paxos Labs as an active listing from employer-controlled hiring sources. Always confirm final availability on the employer application page before applying.
How do I apply for this role?
Use the application link on this page to apply directly with Paxos Labs. GMI Jobs keeps the canonical job page, company context, and market links together so candidates can compare before leaving the site.
What should I compare before applying?
Compare the role location In-Person NYC, any listed pay signal, company profile, related crypto jobs, and salary context before applying. Listed pay signals are not guaranteed offers; confirm compensation with the employer.
Job Description
<h1><strong>Who we are</strong></h1><p style="min-height:1.5em">Paxos Labs builds enterprise infrastructure that powers the next generation of trusted onchain financial products. We work with the largest financial enterprises in the world to build transparent and verifiable onchain infrastructure that works for end users and everyday financial use cases. If you believe in bringing DeFi and digital assets to the mainstream, consider building your career at Paxos Labs.</p><p style="min-height:1.5em">We believe security is critical to our culture and long term success. We are hiring a Lead Security Engineer to help take Paxos Labs's security capabilities to the next level.</p><p style="min-height:1.5em"></p><h1><strong>Who we're looking for</strong></h1><p style="min-height:1.5em">The engineering team at Paxos Labs deploys production software across the web2 and web3 stack, from smart contract protocols, DeFi integrations, and cloud infrastructure to public API/SDKs that requires a comprehensive security posture. We are looking for a motivated developer that can <strong>not only develop, but aptly research and deploy extensive knowledge across TradFi and DeFi</strong> to secure mission critical software. </p><p style="min-height:1.5em"><em><strong>Most importantly, we are looking for developers with interest in the following overlap:</strong></em> </p><ol style="min-height:1.5em"><li><p style="min-height:1.5em"><strong>Smart Contract Security</strong></p></li><li><p style="min-height:1.5em"><strong>Cloud Security</strong></p></li><li><p style="min-height:1.5em"><strong>Operational Security</strong></p></li></ol><p style="min-height:1.5em"></p><h1><strong>Responsibilities</strong></h1><h2>Cloud Security</h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Conduct internal audits of Cloud (Azure, AWS) platform security and implement best practices around key management, network security, monitoring, etc.</p></li><li><p style="min-height:1.5em">Create threat models for first party and third party software, research possible vulnerabilities and patch them.</p></li><li><p style="min-height:1.5em">Collaborate closely with infrastructure engineers to detect, fix, and prevent future exploits by creating resuable tools and processes.</p></li></ul><h2>Operational Security</h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Develop tooling and SOPs such as incident response manuals.</p></li><li><p style="min-height:1.5em">Conduct periodic incident response training for team members. Simulating hacks, alerts, and social engineering vectors.</p></li><li><p style="min-height:1.5em">Collaborate closely with both the technical and the non-technical staff to secure non-code related attack vectors and protect the weakest link i.e. the humans involved.</p></li></ul><h2>Smart Contract / DeFi Security</h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Collaborate closely with the Smart Contract team to conduct internal audits and t