Security Analyst at Aptos Labs answer
Is this job still open?
GMI Jobs is currently showing this Security Analyst role at Aptos Labs as an active listing from employer-controlled hiring sources. Always confirm final availability on the employer application page before applying.
How do I apply for this role?
Use the application link on this page to apply directly with Aptos Labs. GMI Jobs keeps the canonical job page, company context, and market links together so candidates can compare before leaving the site.
What should I compare before applying?
Compare the role location Remote, any listed pay signal, company profile, related crypto jobs, and salary context before applying. Listed pay signals are not guaranteed offers; confirm compensation with the employer.
Job Description
<div class="content-intro"><p><span style="font-weight: 400;">Aptos is a people-first blockchain on a mission to help billions of people achieve universal and fair access to decentralized assets in a safe and scalable way.</span></p>
<p><span style="font-weight: 400;">Founded by some of the original creators and maintainers that researched, designed, and built the Diem blockchain to serve this purpose, we have dedicated several years toward this mission. We believe the open-source Diem technology we have developed is an important foundation of a safe and scalable web3 world where everyone has more equitable opportunities to grow and access financial assets with lower fees and fewer intermediaries.&nbsp;&nbsp;</span></p>
<p><span style="font-weight: 400;">Aptos (Ohlone for "The People") encompasses our mission and ethos for why we build.</span></p></div><p>Aptos Foundation is seeking a Security Analyst to help operate and scale security across the organization. Reporting to the Security Lead, this role will support core security workflows spanning phishing response, bug bounty operations, access governance, and operational security hygiene. This is a hands-on, cross-functional role offering broad exposure across security operations, access governance, and threat response—ideal for someone looking to develop a wide view of security in a fast-moving organization.</p>
<h2><strong>Responsibilities</strong></h2>
<ul>
<li>Respond to and triage alerts relating to phishing attacks, impersonation, scams, and brand abuse (e.g. Sublime, Doppel), escalating credible threats where appropriate.</li>
<li>Coordinate day-to-day operation of the bug bounty program, including communication with researchers, issue tracking, reporting, and internal follow-up.</li>
<li>Conduct user access reviews and review security settings, access configurations, and administrative controls across business systems, SaaS platforms, and internal infrastructure, tracking remediation where required.</li>
<li>Support recurring operational security workflows, including documentation, process tracking, and follow-up.</li>
</ul>
<h2><strong>Requirements</strong></h2>
<ul>
<li>2+ years of experience in a security-focused role, such as security operations, IAM, application security support, operational security, or a similar domain.</li>
<li>Familiarity with core security concepts including phishing, authentication, access control, least privilege, and common vulnerability classes.</li>
<li>Ability to manage multiple concurrent workflows with strong attention to detail and reliable follow-through.</li>
<li>Clear written communication and confidence coordinating across technical and non-tec