Senior Infrastructure Security Engineer

Matter Labs is the engineering company behind Prividium, an Ethereum-secured private blockchain platform for banks and financial institutions, and ZKsync, a public zero-knowledge blockchain network.

Maintainer signals as of 9/2/2026

George Town, Cayman Islands
About Matter Labs

Matter Labs builds Prividium for regulated institutions to issue, settle, and manage digital assets with privacy, compliance, and control of institutional data. Its technology stack includes ZK Stack, ZKsync Connect, Airbender, and the public ZKsync network of Ethereum-secured chains.

View jobs by Matter Labs

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

Secure Matter Labs' corporate and production infrastructure across identity, endpoint, detection and response, cloud and infrastructure security, incident response, secure systems design, and cross-team collaboration. The role supports open-source decentralized infrastructure and Ethereum L2 systems.

Requirements

  • 5+ years of hands-on infrastructure or detection-and-response security experience.
  • Production experience securing cloud-based identity and collaboration platforms at scale.
  • Hands-on experience with modern SIEM and SOAR tools, detections, log sources, response playbooks, and false-positive reduction.
  • Strong cloud security background including IAM, network controls, workload identity, and organization-level guardrails.
  • Experience securing macOS-dominant endpoint fleets with MDM, endpoint hardening, and EDR.
  • Familiarity with Infrastructure as Code, secrets management, and security automation.
  • Real incident response and security on-call experience.
  • Clear technical communication across engineering and non-engineering stakeholders.
  • Blockchain or Web3 exposure.
  • Compliance framework experience with SOC 2 and ISO 27001.
  • Kubernetes security.
  • Detection engineering as code.
  • Experience working in lean security teams.

Responsibilities

  • Own identity and collaboration security configuration, including access policies, third-party app governance, DLP, context-aware access, and admin audit.
  • Drive least privilege and phishing-resistant MFA across the organization.
  • Build and maintain detections, response playbooks, log-source integrations, and the detection-as-code pipeline.
  • Reduce mean time to detect and respond to real incidents.
  • Harden cloud infrastructure, Kubernetes clusters, and CI/CD pipelines.
  • Review infrastructure as code, embed security guardrails, and partner on secrets management and supply-chain controls.
  • Own endpoint security through MDM, baseline hardening, EDR tuning, and endpoint telemetry.
  • Lead end-to-end security incident investigations covering containment, forensics, root cause, remediation, and post-mortems.
  • Run threat models and architecture reviews for internal systems and infrastructure changes.
  • Collaborate with Protocol Security, DevOps, IT Ops, and Product Engineering to raise risks and influence security outcomes.