Jobedly Post a Job

Senior Security Engineer - Product Security

Ondo Finance · Remote
RemoteFull-timeSecurityFinance & Insurance$153,000–$207,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Senior Security Engineer Product role

Senior Security Engineer Product positions focus on delivering results in their domain. This page aggregates open Senior Security Engineer Product roles and what employers typically expect.

About Ondo Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. We operate at the intersection of traditional finance and on-chain systems, which means our product surface has to hold up against both the ordinary threats that hit any high-value fintech and the specific ones that follow value on-chain. About the Role We are hiring a Senior Security Engineer - Product Security to own how we ship secure products at Ondo. You will be a security partner for our product engineering teams, driving threat modeling, owning secure code reviews for new products or feature expansions, maintaining and tuning AppSec tooling, and improving the existing SSDLC. You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native approach is welcome, paired with AI-driven approaches should expect to be justified by describing how doing so enables risk outcomes. This is a hands-on IC role. You will read code, run threat models, review architecture proposals, own tooling, and push engineering teams to build products that are secure by default. You partner closely with adjacent security function like AppSec, Infrasec, and SecOps. What You’ll Do Drive threat modeling for new features, integrations, and architectural changes across the product surface. Push threat models past templates into decisions that engineering teams actually implement. Own secure code review for high-risk changes — authentication, session management, cryptographic paths, wallet and signing flows, RPC and third-party integrations, permission and consent surfaces. Expand the AppSec tooling stack and treat “reducing false positives” as a first-class deliverable. AI-native integrations are welcome. Design and evolve our secure SDLC: where security fits in the dev workflow, what triggers a review, what a lightweight security sign-off looks like versus a full one, and how do we validate controls. Run our responsible disclosure and bug bounty program. Set scope, triage inbound reports, decide payouts, and drive findings to closure with engineering. Support and own appropriate scope for the intake and closure of findings from external audits and pentests — coordinate with audit vendors (Coinspect, Cantina, NCC Group, and others), organize findings into our internal risk register, and drive remediation with engineering owners. Partner with engineering leads to align o secure-by-default patterns - libraries, templates, sensible defaults, and paved-road implementations of anything security-relevant. Threat model blockchain-integrated components like wallet flows, RPC integrations, signing infrastructure, on-chain admin actions triggered from off-chain systems in partnership with engineers who own the on-chain code. Contribute to hiring, mentoring, and pushing the technical bar on the Security team. What We’re Looking For 5+ years in Product Security or Application Security, including senior IC time at a fast-moving product company. Deep secure code review skills in at least one modern stack (TypeScript / JavaScript, Python, or Go). Ability to move across stacks at the level required to threat model. Strong threat modeling skills, appropriate to experience - you can drive a real threat model with an engineering team, not just fill in a template. In practice, we look for core understanding of industry-relevant TTPs and IoCs and strong intuitions on how to apply those lessons learned to our products. Practical experience owning or majorly contributing to an AppSec tooling program. You have shipped rules, tuned noise, and measured impact. Comfortable running or building a bug bounty / responsible disclosure program end-to-end assuming properly resourced to do so. Strong working knowledge of modern web and API security - session and auth flows, OAuth and OIDC, browser security model, common web/API vulnerability…

Salary estimate

$153,000 – $207,000/yr
Provided by the employer.

Skills for this role

JavascriptTypescriptPythonGOSecurity

Resume tips for Senior Security Engineer Product applicants

Interview preparation

Prepare concrete STAR-format stories that show Senior Security Engineer Product outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Senior Security Engineer Product problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Ondo Finance

Ondo Finance is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles