Senior Security Engineer - Product Security
Ondo helps institutions and individuals access traditional financial assets on blockchain through tokenized US Treasuries and investment products.
Maintainer signals as of 8/20/2026
Funding history
Projects
About Ondo
Ondo brings traditional financial assets onchain through institutional-grade platforms and infrastructure. The protocol offers tokenized US Treasuries and investment products with daily yield distributions, while developing Ondo Chain, a Layer 1 blockchain optimized for real-world assets. Products include USDY for non-US investors and OUSG for qualified purchasers, supported by regulated custodians and audited smart contracts.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will drive threat modeling, secure code reviews, AppSec tooling, and improvements to the secure software development lifecycle. You will own bug bounty and responsible disclosure activities, coordinate audit and penetration-test findings, establish secure-by-default patterns, and assess blockchain-integrated components such as wallet flows, RPC integrations, signing infrastructure, and on-chain administrative actions.
Requirements
- 5+ years in Product Security or Application Security
- Senior individual contributor experience
- Secure code review
- TypeScript
- JavaScript
- Python
- Go
- Threat modeling
- Threat intelligence
- AppSec tooling
- Web security
- API security
- Session management
- Authentication
- OAuth
- OIDC
- Browser security
- Terraform
- Cloud IAM
- CI/CD
- Bug bounty
- Responsible disclosure
- Audit
- Penetration testing
- Risk register
- Blockchain security
- Wallet security
- Signing
- Key management
- Solidity
- Rust
- Browser-extension security
- Mobile app security
Responsibilities
- Drive threat modeling for features, integrations, and architectural changes
- Own secure code reviews for high-risk changes
- Expand and tune the AppSec tooling stack
- Design and evolve the secure software development lifecycle
- Run the responsible disclosure and bug bounty program
- Triage reports and drive findings to closure
- Coordinate external audits and penetration tests
- Organize findings in the internal risk register
- Establish secure-by-default libraries, templates, defaults, and implementations
- Threat model wallet flows, RPC integrations, signing infrastructure, and on-chain administrative actions
- Contribute to hiring and mentoring
