Security Engineer at ether.fi

Company: ether.fi

Location: Cayman

Type: Full-time

Apply for this position

Frequently asked questions

Is this job still open?

GMI Jobs is currently showing this Security Engineer role at ether.fi as an active listing from employer-controlled hiring sources. Always confirm final availability on the employer application page before applying.

How do I apply for this role?

Use the application link on this page to apply directly with ether.fi. GMI Jobs keeps the canonical job page, company context, and market links together so candidates can compare before leaving the site.

What should I compare before applying?

Compare the role location Cayman, any listed pay signal, company profile, related crypto jobs, and salary context before applying. Listed pay signals are not guaranteed offers; confirm compensation with the employer.

Job Description

About the Role: We're looking for a Security Engineer who is equally at home hardening a CI/CD pipeline, reviewing a change to the authentication system on the backend, and triaging a bug bounty submission before lunch.This is a hands-on, builder-first role - not a governance checkbox. You'll own security operations end-to-end, embedded directly into the engineering team and working closely with infrastructure, protocol and platform. If you treat threat modeling as a design conversation and not a compliance exercise, you're our kind of person. You should only apply for this role if you are ready to come into the office every day and work in person with our team! What You'll Do: Security Operations Own day-to-day security operations: monitoring, alerting, triage, and response Manage and monitor endpoint security via an EDR system - tune detections, investigate alerts, and drive incidents to resolution Lead identity lifecycle management, including employee onboarding and off boarding (access provisioning, key rotation, deprovisioning) Bug Bounty & Vulnerability Management Be the primary owner of our ImmuneFi program - triaging, reproducing, and responding to incoming submissions daily Prioritize and track vulnerabilities through to remediation in close collaboration with protocol and engineering teams Develop internal tooling and processes to make the bounty workflow faster and more consistent DevSecOps & Pipeline Hardening Audit and harden CI/CD pipelines - secrets management, supply chain integrity, SAST/DAST integration, build provenance Own dependency security: identify and remediate vulnerable packages across repositories (yes, including the npm dependency hell) Establish and enforce security standards across the SDLC Infrastructure Security Partner with the infrastructure team to review and harden cloud environments (access controls, network segmentation, least privilege, logging) Contribute to threat modeling for new systems and architectural changes Drive implementation of security tooling across the stack Vendor & External Partner Management Own relationships with external security vendors and service providers — holding them accountable toSLAs, managing scope, and ensuring findings are actioned Evaluate and onboard new security tooling as the team and threat landscape evolve What We're Looking For: 5+ years of experience in software and security engineering, with meaningful time in a DevSecOps or security operations context Strong software engineering fundamentals - you're a builder who writes code, not just policy Hands-on experience hardening CI/CD pipelines (GitHub Actions, CircleCI, or similar) and cloud infrastructure (AWS, GCP, or equivalent) Proficiency with endpoint security tooling (CrowdStrike or equivalent EDR) Comfort owning identity and access management processes, including onboarding/offboarding workflows Strong communication skills - you can write a clear triage report, give direct feedback to a developer and e

More jobs at ether.fi

Browse More Jobs

Related searches for this role

Use these GMI Jobs search paths to compare similar openings before applying.

Popular job searches

Explore related crypto job pages with live listings and salary context.