Matter Labs
Senior Infrastructure Security Engineer
United States · Senior
Sponsorship not specifiedDetected 49 days ago
GitKubernetesCI/CDDevOpsCybersecuritySIEMSOARDetection EngineeringIncident ResponseComplianceSupply ChainCommunicationCollaboration
About the role
- Join Matter Labs as a Senior Infrastructure Security Engineer and help secure the corporate and production infrastructure that powers ZKsync.
- Matter Labs runs a deliberately lean, high-leverage security organization.
- You won't be one of fifty detection engineers.
Responsibilities
- Identity & Collaboration Security Own the security configuration of our identity and collaboration stack: identity and access policies, third-party app governance, DLP, context-aware access, and admin audit.
- Drive least-privilege and phishing-resistant MFA across the org.
- Detection & Response Build, tune, and maintain detections. Design response playbooks for high-signal alerts, onboard new log sources, and own the detection-as-code pipeline. Reduce mean-time-to-detect and mean-time-to-respond on real incidents.
- Cloud & Infrastructure Security Harden our cloud footprint, Kubernetes clusters, and CI/CD pipelines. Review Infrastructure as Code for security regressions, embed guardrails, and partner with DevOps on secrets management and supply-chain controls.
- Endpoint Security Own the security posture of the endpoint estate, including MDM configuration, baseline hardening, EDR tuning, and endpoint telemetry. Make sure the controls hold up without making engineers' machines miserable to use.
- Incident Response Lead and participate in security incident investigations end-to-end: containment, forensics, root cause, remediation, and post-mortem. Improve runbooks and detections after every incident.
- Secure Systems Design Run threat models and architecture reviews for new internal systems and infrastructure changes. Translate findings into concrete, prioritized work, not lists of concerns.
Requirements
- 5+ years of hands-on infrastructure or detection-and-response security experience.
- Production experience securing a cloud-based identity and collaboration platform at scale, beyond default settings.
- You can speak to specific policies you've implemented, third-party app governance you've run, and incidents you've worked.
- Hands-on experience with a modern SIEM and SOAR: writing detections, onboarding log sources, building response playbooks, and tuning to reduce false positives.
- Comfort reasoning about Mac-specific attack paths and telemetry.
- Familiarity with Infrastructure as Code, secrets management, and security automation.
Nice to have
- Blockchain / Web3 exposure.
- Familiarity with the security considerations of decentralized infrastructure, validator/sequencer operations, key management for on-chain systems, or hot/cold wallet ops.
- Compliance framework experience with SOC 2 and ISO 27001.
- Comfort translating compliance requirements into real engineering work, without letting compliance dictate the engineering.
- Kubernetes security (admission control, runtime detection, supply chain).
- Detection engineering as code: Git-based rule management, CI for detections, purple-team validation.
- Experience in lean security teams where you've owned a domain end-to-end rather than a narrow slice.
- optional travel to team or industry events.
Skills
- Incident
Company info
- one party proves a transaction is valid without revealing any underlying data to the counterparty.
- The only private settlement infrastructure built on zero-knowledge cryptography.
- Founded in 2018.
- Backed by a16z and Union Square Ventures.
- A fully remote team of around 90 with eight years of production zero-knowledge infrastructure behind us, now pointed at the biggest problem in institutional finance.
- no time tracking, minimum bureaucracy-only results matter.
Apply directly at Matter Labs →Create a free account for alerts like thisView Matter Labs immigration profile
This listing is sourced directly from Matter Labs's careers page and normalized into a canonical job model.