Chicago, ILremote

Salary
$160,000–$200,000from the description
Posted
Jul 20, 2026
Location
Chicago, IL
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A security-focused engineering role at an early-stage fintech/blockchain startup, responsible for embedding security across the full development lifecycle — from CI/CD pipeline tooling (SAST, DAST, SCA) and cloud infrastructure hardening on AWS or GCP, to smart contract security reviews and on-chain threat monitoring. The position suits an experienced DevSecOps engineer with at least some Web3 or blockchain exposure who is comfortable owning security architecture in a small, fast-moving team.

Senior level · 4+ years · Remote · Full-time

Must have (11)
CI/CDSASTDASTAWS or GCPDockerKubernetesIAMPython, Go or SoliditySlither, Mythx or EchidnaSOC 2GDPR
Nice to have (2)
Gnosis SafeCISSP, Ceh or Aws Security Specialty

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 1,900 people nationally plausibly meet what this posting asks for (information security analysts). range 790–2,800

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
GDPR12%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Docker53%Python51%CI/CD45%IAM45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The role is titled 'Security / DevSecOps Engineer' with no seniority level in the title; advertised seniority is Unspecified. The 4+ years requirement and end-to-end ownership of security architecture at an early-stage startup support a Senior classification.

SOC code is a close call: the role blends hands-on security engineering (15-1212) with significant software/scripting work and DevSecOps pipeline building (15-1252). 15-1212 was chosen as primary because threat modeling, vulnerability assessment, smart contract auditing, and compliance (SOC 2, GDPR) are the dominant framing.

No work location is stated in the posting. The role is at a stealth-mode startup with no office mentioned; remote is inferred but not explicitly confirmed.

Smart contract auditing tools (Slither, MythX, Echidna) are listed in Requirements but softened with 'or willingness to ramp quickly.' They are still in the hard-requirements section, so they are marked required; the softening language only signals the hiring bar is flexible on which specific tool is known.

Gnosis Safe and multi-sig wallet infrastructure are explicitly called 'a major plus,' placing them under preferred.

Certifications (CISSP, CEH, AWS Security Specialty) are explicitly called 'nice to have, not required' — marked preferred.

Python, Go, and Solidity are presented as interchangeable options for scripting and tooling ('Python, Go, or Solidity'); emitted as one skill with alternatives.

This posting reads as a fully-remote role, so it was scored against the national candidate pool rather than a single metro.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗