Search...

Security Researcher

Galoy logo
Galoy

Galoy builds Bitcoin-native banking infrastructure for regulated financial institutions. Its platform supports Bitcoin and stablecoin lending, payments, exchange, custody orchestration, and digital-asset wallet capabilities.

Distributed
About Galoy

Galoy is a Bitcoin-native banking software company serving regulated financial institutions. Its API-first, event-sourced platform integrates alongside existing banking cores, custody providers, and compliance systems, enabling institutions to offer Bitcoin-backed lending, Bitcoin and Lightning payments, stablecoin payments, Bitcoin exchange, custody orchestration, and digital-asset wallet features. Galoy emphasizes compliance tooling, audit trails, role-based access, and custody-independent integrations.

View jobs by Galoy

Skills

About the Role

You will lead threat-modeling sessions, identify and mitigate security risks, and promote secure coding practices. You will review Rust code, hunt for vulnerabilities, support responsible disclosure, and improve cloud and Kubernetes security. You will integrate security checks into CI/CD, respond to incidents, track emerging exploits, mentor engineers, and contribute security improvements to open-source repositories.

Requirements

  • 5+ years of application or cloud security experience with documented vulnerability discoveries
  • Rust fluency or strong willingness to master it
  • Bitcoin and Lightning protocol knowledge
  • Cloud-native expertise with AWS, GCP, Azure, Kubernetes, Terraform, and CI/CD
  • Familiarity with SAST, DAST, fuzzing, and CodeQL
  • Threat modeling and penetration testing capability
  • Strong written and verbal English communication
  • Ability to work in remote and asynchronous environments

Responsibilities

  • Lead threat-modeling sessions for new features
  • Design mitigations and champion security by design
  • Perform manual and automated security analysis of Rust codebases
  • Conduct vulnerability hunting and responsible disclosure
  • Harden GCP, Azure, and Kubernetes deployments
  • Manage IAM, network segmentation, and secrets management
  • Integrate SAST, DAST, secret scanning, and dependency checks into CI/CD pipelines
  • Maintain detection rules, triage security alerts, and conduct post-mortems
  • Track emerging exploits and share findings with upstream open-source projects
  • Guide engineers on secure coding practices
  • Publish security enhancements to community repositories

Benefits

  • Optional Bitcoin compensation
  • Remote-first work
  • Optional El Salvador relocation assistance with visa support