Engineering Lead — Security
Somnia Network enables onchain applications through its own EVM-compatible blockchain. It aims to service mass consumer and real-time applications with a focus on gaming applications.
Projects
About Somnia Network
Somnia Network helps developers build mass consumer applications by providing an EVM-compatible Layer 1 blockchain. With it, you can deploy games, social platforms, and metaverse experiences requiring millions of concurrent users. Somnia eliminates blockchain scalability barriers through custom consensus mechanisms and database optimization.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will own security across the L1 infrastructure, products, services, policies, processes, multisig governance, and key management. You will harden hosts, networks, and pipelines; define security standards; secure applications and supply chains; operate signing and treasury workflows; lead incident response; conduct threat modeling and security reviews; and coordinate audits and bug bounties.
Requirements
- Extensive security engineering, infrastructure security, SecOps, and application-security experience
- Production systems experience with Linux internals, networking, containers, Kubernetes, and infrastructure as code
- Experience defining and implementing security policies
- Deep key-management experience with signing workflows, HSMs, secrets management, and key generation, rotation, and recovery
- Incident response leadership covering detection, containment, forensics, and postmortems
- Cryptography fundamentals applied to blockchain and key management
- Senior-level ownership, judgment, communication, and influence without authority
- Comfort working in high-stakes financial systems
- Genuine interest in crypto and on-chain systems
- Experience securing blockchain L1 or L2 node and validator infrastructure
- Experience with multisig governance and treasury operations
- EVM, smart contract security, and DeFi attack surfaces
- Experience coordinating external audits, bug bounties, and responsible disclosure
- Red teaming, offensive security, or detection engineering experience
- Experience with high-throughput or low-latency systems
Responsibilities
- Help define the engineering culture and bar with other technical leaders
- Own the security posture of L1 infrastructure, including validators, RPC, signing services, and supporting systems
- Harden hosts, networks, and pipelines
- Drive vulnerability management, patching, and security monitoring
- Define and roll out access control, secrets management, secure SDLC, change management, and compliance-readiness policies
- Drive application and supply-chain security for shipped products and services
- Implement secure-by-default patterns and dependency and build-pipeline scanning in CI
- Conduct security reviews for high-stakes work and secure agent-authored changes
- Design and operate multisig governance, signing ceremonies, and key lifecycles
- Build and lead security incident response, including detection, triage, containment, and postmortems
- Run security tabletop exercises
- Conduct threat modeling, security reviews, and red-team exercises
- Coordinate external audits and bug bounties
- Work with infrastructure and L1 teams to resist node and validator compromise and ship upgrades safely
Benefits
- Remote work
- Token incentives
