Crossmint
Senior Security Engineer
NYC or MiamiFull-timeGlobal
š° USD 180,000 - 210,000/yr
š Midš Hybrid
ActivePosted within the last 30 days
Job Description
[AI-summarized by JobStash]
You will own and operate day-to-day security for cloud infrastructure and applications. You will design, maintain, and monitor security controls, secure CI/CD and software supply chain, perform secure code reviews, manage access and credential rotation, drive vulnerability remediation, and support incident response and audit evidence collection.
Requirements
- ā4-8 years of experience as a security engineer
- ā3+ years hands-on experience securing AWS environments including IAM, Security Hub, CloudTrail, GuardDuty, and KMS
- āStrong understanding of CI/CD security including GitHub Actions, secrets scanning, and dependency management
- āExperience with secure code review or application security fundamentals
- āExperience working with at least one compliance framework, preferably SOC 2
- āHighly organized with strong attention to detail
- āComfort operating in a fast-paced startup environment and communicating security concepts to non-technical stakeholders
- āExperience using AI-assisted tools such as Claude or GitHub Copilot
- āAbility to work flexible hours if an incident arises
- āNice to have: fintech or payments experience
- āNice to have: exposure to DORA or MiCA compliance requirements
- āNice to have: familiarity with crypto or blockchain security considerations
Responsibilities
- āOwn and operate cloud security across AWS and other cloud environments
- āDesign, maintain, and monitor engineering security controls including IAM, logging, monitoring, and key management
- āSecure CI/CD pipelines, GitHub Action environments, secrets management, and software supply chain
- āManage security-related access controls, privileged access, service accounts, and credential rotation
- āPerform secure code reviews and provide application security support
- āReview authentication flows, payment logic, and API security and partner with engineers on remediation
- āCoordinate external security reviews with third-party auditor firms
- āOwn vulnerability management workflows including prioritization, remediation tracking, and verification
- āSupport incident response through triage, investigation, and remediation
- āCollect evidence and document controls to support SOC 2 and other compliance audits
Benefits & Perks
- āExtensive access to leading AI tools and subscriptions
- āStock options program
- āTwo performance reviews annually
- āUnlimited flexible PTO
- āFlexible work schedule
- āCompany laptop and allowance for home equipment
- āDaily stipend for commuting to the office
- āCompany-paid trips for annual off-sites and onsites
- āInsurance covered by Crossmint
- ā401(k) Plan
Tech Stack
Secrets managementmonitoringClaudevulnerability managementIAMauthenticationcompliancePAMcloud securitykey management