Search...

Cybersecurity Engineer

Grayscale logo
Grayscale

Grayscale is a digital-asset investment firm offering publicly traded and private investment funds, including crypto ETFs and trusts. It provides investment products, market research, and educational resources for investors and financial professionals.

Distributed
About Grayscale

Grayscale operates investment products providing exposure to digital assets and crypto sectors, including publicly traded funds, private funds, and exchange-traded products such as Bitcoin, Ethereum, Solana, Chainlink, XRP, and Hyperliquid offerings. The organization also publishes market commentary and research, provides regulatory and tax resources, and offers investor education through the Grayscale Institute. Its services are oriented toward investors and financial professionals seeking digital-asset investment exposure.

View jobs by Grayscale

Skills

About the Role

You will build, implement, and maintain security capabilities across cloud infrastructure, enterprise applications, AI-enabled systems, and modern engineering platforms. You will partner with engineering teams to implement security controls and secure design patterns, and you will build monitoring, detection, alerting, and incident response capabilities. You will integrate security tooling and automation into CI/CD pipelines using Infrastructure-as-Code and policy-as-code practices, participate in threat modeling and architecture reviews, and help embed secure-by-design principles into technology solutions. You will also partner with compliance, audit, and business stakeholders to ensure technology solutions meet regulatory requirements, contribute to security standards and automation best practices, and stay current on emerging security threats and technologies.

Requirements

  • 5+ years of experience in cybersecurity, security engineering, cloud security, application security, DevSecOps, or a related engineering discipline
  • Experience implementing security controls within cloud-native environments, preferably AWS
  • Strong understanding of security fundamentals including identity and access management, data protection, network security, vulnerability management, monitoring, and incident response
  • Experience integrating security into software development workflows, including CI/CD pipelines and Secure Software Development Lifecycle practices
  • Strong programming and scripting capabilities (e.g., Python, Terraform, Infrastructure-as-Code)
  • Experience with cloud infrastructure, Kubernetes, APIs, and modern application architectures
  • Experience with security tooling such as SIEM/SOAR, vulnerability management, cloud security, endpoint security, application security, or detection engineering platforms
  • Experience conducting threat modeling, security assessments, and architecture reviews for modern applications and cloud platforms
  • Familiarity with AI/ML systems, including LLMs and AI-enabled application architectures, is a plus
  • Experience operating in regulated environments with strong control, audit, and compliance requirements, preferably within financial services
  • Strong communication skills with the ability to collaborate effectively across engineering, infrastructure, product, and security teams

Responsibilities

  • Partner with engineering teams to implement security controls and secure design patterns across cloud infrastructure, enterprise applications, developer platforms, and AI-enabled systems
  • Build and operationalize security controls that protect sensitive data, including identity and access management, data protection, network security, logging, monitoring, and auditability
  • Participate in threat modeling, architecture reviews, and security assessments for applications, cloud platforms, and emerging technologies
  • Implement and maintain security controls for cloud platforms, APIs, developer tooling, and third-party technologies
  • Build monitoring, detection, alerting, and incident response capabilities in partnership with engineering and security operations teams
  • Integrate security tooling and automation into CI/CD pipelines and cloud-native engineering workflows using Infrastructure-as-Code and policy-as-code practices
  • Support secure software development by embedding security throughout the Secure Software Development Lifecycle
  • Assess and mitigate technical and operational risks associated with cloud platforms, enterprise applications, AI-enabled systems, and third-party providers
  • Partner with compliance, audit, and business stakeholders to ensure technology solutions meet regulatory, control, and governance requirements
  • Contribute to the development of security standards, engineering patterns, automation, and operational best practices
  • Stay current on emerging security threats, technologies, and industry best practices