Anchorage Digital

Anchorage Digital

Member of Technical Staff, Security Operations

United States · Staff+

Sponsorship not specifiedDetected 594 days ago
PythonGoAlgorithmsCode ReviewAWSCloud PlatformsPenetration TestingSOC OperationsIncident ResponseAuditingCommunication

About the role

  • - Build and maintain security automation and tooling to detect vulnerabilities through static and dynamic analysis across code and live systems.
  • - Conduct application security assessments, penetration tests, and code reviews to identify high-risk security issues and provide secure development guidance.

Responsibilities

  • Manage the full vulnerability lifecycle from discovery through remediation, tracking progress and ensuring timely closure of findings.
  • Lead or substantially contribute to Security Operations initiatives with minimal oversight, coordinating across team boundaries to drive projects to completion.
  • Deliver assurance artifacts and evidence for regulated entity requirements, supporting audit and compliance efforts.
  • Understand and help implement the company's security strategy by participating in planning and defining Security Operations goals in alignment with Anchorage Digital's overall objectives.
  • Collaborate cross-functionally with Engineering, Infrastructure, and Compliance teams to embed security into development and operational processes.
  • Partner with engineering teams to explain security risks and remediation approaches, translating technical findings into actionable guidance.
  • Collaborate across teams to review security configurations, triage findings, and engage in technical discussions. Communicate insights and recommendations clearly to improve processes.

Requirements

  • You have 3+ years of hands-on experience in security engineering, application security, penetration testing, or security operations.
  • You have built or maintained security tools, integrations, or automation workflows using Python, Go, or similar languages.
  • You have experience with tools like Semgrep, CodeQL, Burp Suite, or equivalent for identifying security issues in code and running systems.
  • You have developed "computer science fundamentals," i.e. concurrency, algorithms, and data structures.

Nice to have

  • You have experience running or participating in bug bounty programs (HackerOne, Bugcrowd, etc.).
  • You have worked in a regulated financial services, fintech, or crypto environment.
  • You have exposure to blockchain security, smart contract auditing, or Web3 technologies.
  • You have built or contributed to open-source security tools.
  • You hold relevant certifications (OSCP, GWAPT, GCIH, AWS Security Specialty, etc.).
  • You read blockchain protocol white papers for fun, and stay up to date with the proliferation of crypto-asset innovations.
  • You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system.:)

Skills

  • Establish and test security guardrails for code, cloud resources, and infrastructure components throughout the Anchorage platform.
  • Complexity and Impact of Work:
  • Monitor and respond to security events and configuration anomalies across the organization, leading investigation and containment efforts.
  • Balance speed of response with thoroughness of investigation, adapting approach based on risk and business impact.
  • Organizational Knowledge:
  • Stay alert to emerging threats, vulnerabilities, and industry trends that could affect organizational security posture.
  • Communication and Influence
  • You may be a fit for this role if you have:

This listing is sourced directly from Anchorage Digital's careers page and normalized into a canonical job model.