Senior Security Engineer - Product Security

Ondo Finance
United States
Workplace: RemoteFull timeFunction: CybersecuritySkills: ["Engineering partnership","Mentoring","Threat modeling intuition","Risk communication","Collaboration"]

Own product security at Ondo by partnering with product engineering teams on threat modeling, secure architecture reviews, and high-risk secure code reviews. Expand and tune AppSec tooling to reduce false positives, and design/evolve the secure SDLC with lightweight vs full security sign-offs. Run responsible disclosure and bug bounty programs, coordinate audit/pentest findings, and drive secure-by-default patterns across product surfaces.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Ondo Finance
Ondo Finance
14 hours ago

Senior Security Engineer - Product Security

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 hours agoStatus: Live

Job Summary

Own product security at Ondo by partnering with product engineering teams on threat modeling, secure architecture reviews, and high-risk secure code reviews. Expand and tune AppSec tooling to reduce false positives, and design/evolve the secure SDLC with lightweight vs full security sign-offs. Run responsible disclosure and bug bounty programs, coordinate audit/pentest findings, and drive secure-by-default patterns across product surfaces.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Drive threat modeling for new features, integrations, and architectural changes across the product surface.
  • •Own secure code reviews for high-risk changes including auth/session management, cryptographic paths, wallet and signing flows, RPC/third-party integrations, and permission/consent surfaces.
  • •Expand and tune the AppSec tooling stack, reducing false positives as a first-class deliverable.
  • •Design and evolve a secure SDLC, defining where security fits in the dev workflow and how controls are validated.
  • •Run the responsible disclosure and bug bounty program end-to-end, including triage, payouts decisions, and driving findings to closure with engineering.

Key Requirements

  • •5+ years in product security or application security, including senior IC experience at a fast-moving product company.
  • •Deep secure code review skills across at least one modern stack (TypeScript/JavaScript, Python, or Go) and ability to move across stacks to threat model.
  • •Proven threat modeling skills with an ability to drive real threat models with engineering teams.
  • •Experience owning or majorly contributing to an AppSec tooling program (shipped rules, tuned noise, measured impact).
  • •Strong web and API security knowledge (auth/session, OAuth/OIDC, vulnerability classes) plus ability to reason about infra risk via Terraform, cloud IAM, and CI/CD.
Experience:Product securityApplication securityFintechCryptographyAppSecBug bountyResponsible disclosureBlockchain-adjacent
Skills:Engineering partnershipMentoringThreat modeling intuitionRisk communicationCollaboration
Languages:English
Tech Stack:TypeScriptJavaScriptPythonGoTerraformOAuthOIDCCI/CDAppSecSDLCAppSec tooling

Company Brief

Ondo Finance
Develops tokenized investment products and infrastructure to bring institutional-grade digital asset exposure to investors, combining on-chain protocols with regulated fund structures for yields, custody, and liquidity solutions.
Industry: Asset Management
Company Size: Small (11 to 50 employees)
Growth: Growth Stage Startup
Funding: Series A
Headquarters: New York, United States
Founded: 2020
WebsiteLinkedIn