Member of the Technical Staff, Security Operations
Anchorage Digital offers institutions secure and regulated crypto custody, trading, staking, and financing services.
Funding history
About Anchorage Digital
Anchorage Digital is a regulated crypto platform that provides institutions with integrated financial services and infrastructure solutions. Founded in 2017, Anchorage offers custody, trading, staking, and other services for digital assets, serving banks, fintechs, and investment funds. Anchorage aims to make it simple and secure for institutions to participate in the digital asset space.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
Build and maintain security automation and tooling to detect vulnerabilities across code and live systems. Conduct application security assessments, penetration tests, and code reviews; operate vulnerability management workflows; respond to security events; produce assurance artifacts; document runbooks and post-incident reviews; and collaborate with engineering, infrastructure, and compliance teams.
Requirements
- 3+ years of hands-on experience in security engineering, application security, penetration testing, or security operations
- Experience building or maintaining security tools, integrations, or automation using Python, Go, or similar languages
- Ability to identify and assess vulnerabilities in applications, APIs, and cloud infrastructure
- Experience with static and dynamic analysis tools such as Semgrep, CodeQL, or Burp Suite
- Knowledge of AWS security fundamentals including IAM, VPCs, security groups, and CloudTrail logging
- Incident response experience including investigation and root cause analysis
- Computer science fundamentals including concurrency, algorithms, and data structures
- Care about code quality and operational excellence
- Prioritize security outcomes, end-user experience, and business value
Responsibilities
- Build and maintain security automation and tooling
- Conduct application security assessments
- Perform penetration tests and code reviews
- Develop and operate vulnerability management workflows
- Establish and test security guardrails for code, cloud resources, and infrastructure
- Monitor and respond to security events and configuration anomalies
- Lead investigation and containment efforts
- Manage the full vulnerability lifecycle from discovery through remediation
- Deliver assurance artifacts and evidence for regulated requirements
- Document runbooks and post-incident reviews
- Communicate security risks and remediation approaches to engineering teams
Benefits
- Remote friendly work policy
- Option to work in-office in New York City, Sioux Falls, Porto, Lisbon, and Singapore
- Sponsored quarterly in-person collaboration days
