Senior Security Engineer - Infrastructure
Ondo Finance
—
Jul 25, 2026
—
Jul 26, 2026
What this job asks for AI summary
A senior individual-contributor role focused on securing cloud and infrastructure at a blockchain-based asset management firm. The engineer will own cloud posture across AWS and GCP, design and enforce infrastructure-as-code guardrails, lead identity and secrets management, and conduct offensive testing against internal infrastructure. The role bridges platform engineering and security, with additional responsibility for supply-chain risk, cloud incident response, and mentoring peers.
Senior level · 3+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 1,650 people nationally plausibly meet what this posting asks for (information security analysts). range 980–2,450
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The role sits explicitly between platform/infrastructure engineering and security — it involves writing Terraform and IaC guardrails (infrastructure-building work) as much as threat modeling, offensive testing, and cloud posture management (security analysis work). 15-1212 was chosen because the primary framing is security ownership (CNAP, red-teaming, incident response, detection coverage), but 15-1244 is a genuine runner-up given the heavy IaC and cloud infrastructure build-and-operate responsibilities.
AWS and GCP are both named explicitly in the requirements section ('Production experience across AWS, GCP, or Azure'), so they are treated as a single interchangeable gate with Azure as the third alternative.
Python and Go are listed as interchangeable scripting options in the requirements section; Python is emitted as the primary with Go as the alternative.
Kubernetes is listed in the requirements section but qualified with 'if our stack uses it; bonus if you can operate it' — this conditional/bonus framing makes it preferred rather than a hard gate.
CI/CD security and secrets management appear under 'Nice to Have' or in narrative context and are marked preferred accordingly.
No compensation figures are provided — only a qualitative description of competitive salary, token rights, and equity.
The role is fully remote across the U.S.; no specific metro or state is given.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secrets management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.