Senior Security Engineer
Agora Finance issues AUSD, a fully reserved dollar stablecoin, and provides stablecoin APIs to mint, move, and earn money.
Maintainer signals as of 9/25/2026
Funding history
Projects
About Agora Finance
Agora Finance, branded publicly as Agora, is a stablecoin issuer and infrastructure platform building a monetary network for global settlement. Its current offering includes AUSD, stablecoin APIs for institutional money movement, and related stablecoin swap infrastructure.
Skills
About the Role
The Senior Security Engineer will serve as the primary technical security partner to Engineering, reviewing designs, code, APIs, infrastructure, cloud environments, Kubernetes workloads, and production systems. The role combines application and cloud security, security tooling, detection engineering, incident response, SOC collaboration, vulnerability management, and security automation in a crypto-native financial infrastructure environment.
Requirements
- 5+ years of hands-on experience in product security, application security, cloud security, or a closely related security engineering role.
- Strong software engineering fundamentals and application code review experience, especially with TypeScript, Node.js, JavaScript, or another modern language.
- Experience reviewing web applications, backend services, REST APIs, authentication and authorization systems, and relational databases.
- Knowledge of application and API vulnerabilities, threat modeling, secure design, and modern identity patterns.
- Experience securing AWS, containers, Kubernetes, infrastructure as code, and CI/CD or GitOps workflows.
- Hands-on experience with security tools such as SAST, DAST, SCA, CSPM, container scanning, secrets detection, infrastructure-as-code scanning, SIEM, or cloud-native detection platforms.
- Experience developing or tuning detections using application, cloud, identity, network, and infrastructure telemetry.
- Strong investigation skills, including log analysis, hypothesis development, timeline construction, and scope and impact assessment.
- Experience working with a SOC, participating in incident response, operating vulnerability management, and coordinating remediation across engineering teams.
- Ability to evaluate findings based on exploitability, confidence, and business impact.
- Experience with external penetration testers, auditors, or specialist security reviewers.
- Strong written and verbal communication, autonomy, judgment, and collaborative stakeholder management.
- Familiarity with fintech, payments, digital assets, blockchain systems, smart-contract integrations, custody, signing infrastructure, or cryptographic key management is preferred.
- Experience with TypeScript, Pulumi, AWS, Argo CD, Cloudflare, PostgreSQL, Prometheus, Grafana, security automation, detection-as-code, or AI-assisted security tools is preferred.
- Working hours must have a majority overlap with Eastern Time business hours; candidates near Eastern Time are preferred, with exceptional engineers welcomed through Pacific Time up to ET+2.
Responsibilities
- Partner with Engineering and Product across design, threat modeling, development, launch, and ongoing operations.
- Review application code, APIs, architectures, infrastructure as code, cloud environments, Kubernetes workloads, deployment pipelines, and production configurations.
- Identify vulnerabilities and design weaknesses and drive pragmatic remediation.
- Develop security guidance, secure patterns, review checklists, and engineering standards.
- Administer and improve SAST, DAST, SCA, CSPM, container scanning, infrastructure-as-code scanning, monitoring, and related security tooling.
- Integrate security controls into developer workflows and CI/CD pipelines and tune rules for coverage and signal quality.
- Design, implement, test, document, and tune security alert rules and detection logic.
- Investigate security detections and incidents, coordinate with the SOC, and improve escalation criteria, runbooks, and response procedures.
- Participate in incident response, post-incident reviews, and durable security improvements.
- Own vulnerability management intake, prioritization, remediation tracking, exceptions, verification, and reporting.
- Support penetration tests, code reviews, architecture assessments, and external security engagements.
- Assess security risks from vendors, technologies, integrations, and architectural changes.
- Build automation and metrics to improve visibility, investigation speed, remediation time, and risk reporting.
- Contribute to product security, platform security, detection engineering, vulnerability management, and incident-readiness roadmaps.
