Staff KMS Security Engineer (Security)

Phantom

3mo ago 2 views 0 applications
Remote Remote
Competitive
Full-time
Security Engineer

Job Description

Join Phantom: Secure the Future of Self-Custody Crypto

Phantom is revolutionizing the crypto experience, empowering millions to seamlessly manage their digital assets across Solana, Bitcoin, Ethereum, and Polygon. We're not just a wallet; we're building a next-generation, safe, and user-friendly gateway to the decentralized world. With over 15 million monthly active users and a #1 ranking in the Google Play Store finance category, we're experiencing rapid growth and setting new standards for self-custodial crypto wallets.

At Phantom, security isn't an afterthought—it's the foundation of everything we do. We're looking for a passionate and experienced Security Engineer to join our team and help us protect our users' assets and shape the future of crypto.

Your Mission:
As a Security Engineer, you'll be at the forefront of identifying, exploiting, and mitigating security vulnerabilities in our software applications. You'll conduct in-depth security assessments, lead investigations, and collaborate closely with development teams to integrate security into every stage of the software development lifecycle.

What You'll Do:
Own Critical Security Infrastructure: Manage and maintain key management services for our wallet infrastructure, ensuring the highest levels of security and availability.
Conduct Security Assessments: Perform regular security assessments on new projects, infrastructure, and code, identifying potential weaknesses and vulnerabilities.
Vulnerability Management: Identify and mitigate security vulnerabilities in code, systems, and networks using a combination of manual testing, automated tools, threat modeling, and threat intelligence.
Stay Ahead of the Curve: Keep up-to-date with the latest offensive security techniques, application security threats, and best practices in the blockchain space, and recommend improvements to our security posture.
Communicate Effectively: Write detailed reports of your findings and present them to management and technical teams, providing actionable insights to prevent real-world attacks.
Secure Coding Advocate: Work with development teams to implement secure coding practices and ensure the integrity of cryptographic functions.
Collaborate Across Teams: Partner with development and platform teams to integrate security throughout the organization.
Incident Response: Participate in incident response and incident management activities, helping to contain and remediate security incidents.
Lead the Way: Lead large cross-team projects, driving security initiatives across the organization.

What You'll Bring:
Proven Experience: 7+ years of experience in offensive security techniques, with a strong focus on blockchain technology and cryptography.
Key Management Expertise: Experience working with Key Management Services is essential.
Security Fundamentals: Strong understanding of security risks, vulnerabilities, and concepts in web and mobile applications.
Coding Proficiency: Proficient in code review for JavaScript & Typescript with a strong understanding of application security threats and offensive security techniques.
Hands-on Skills: Ability to write PoCs to demonstrate vulnerabilities and ensure that patch code meets the standards set by repository owners and maintainers.
Analytical Prowess: Strong analytical and problem-solving skills.
Communication Skills: Excellent verbal and written communication skills.

Bonus Points:
Experience working as a security software engineer at crypto companies.
Experience developing key management solutions.
Experience working with HSM, trust computing, TEEs (AWS Nitro Enclave or Intel SGX).

Why Phantom?

We're not just building a wallet; we're building the future of self-custody crypto. Join us and:
Shape the Future: Be at the forefront of innovation in the crypto space, focusing on the wallet experience.
Make an Impact: Help onboard new users to crypto and make it easier to navigate the decentralized world.
Work on Cutting-Edge Technology: Work with Solana, Ethereum, Polygon, Bitcoin, and other leading blockchain networks.

Perks & Benefits:
Competitive salary and equity
Comprehensive insurance (medical/dental/vision) — 100% covered
Stipend for your ideal remote set-up
Flexible hours and a supportive remote environment
Unlimited vacation: Take time when you need it (and we really mean it!)
401(k) retirement plan
Monthly wellness benefit
Weekly meal benefit
Global off-sites

We believe in creating a diverse and inclusive environment where everyone can thrive. We strongly encourage candidates of all different backgrounds to apply.

The target base salary for this role will range between $250,000 to $285,000 with the addition of equity and benefits. This is determined by a few factors including your skillset, prior relevant experience, quality of interviews and market factors (such as location) at the point in time of offer.

Ready to secure the future with us? Apply now!