About The Position

Ondo Finance is seeking a Senior Security Engineer to secure its cloud, network, and infrastructure-as-code environments. This role involves setting standards for production security, including identity management, network segmentation, secrets management, infrastructure-as-code (IaC) guardrails, runtime security, and offensive testing. The position bridges platform engineering and security, requiring hands-on IaC development (Terraform), policy creation, and testing to ensure security measures are effective. The engineer will collaborate with Operations/Incident Response on cloud detection and with Product Security on application and infrastructure boundaries.

Requirements

  • 3-5+ years in security engineering with a deep focus on cloud and/or infrastructure.
  • Strong IaC skills: experience writing, reviewing, and refactoring large-scale IaC, with an understanding of failure modes.
  • Production experience across AWS, GCP, or Azure.
  • Hands-on experience with a cloud security platform.
  • Strong scripting skills in Python or Go.
  • Comfort owning a domain end-to-end: design, build, operate.

Nice To Haves

  • Experience defending crypto, fintech, or other targeted environments.
  • Experience with CI/CD security.
  • Adjacent experience in offensive security, application security, or other engineering disciplines.
  • Familiarity with how on-chain operations interact with off-chain infrastructure.
  • Working knowledge of Kubernetes security (RBAC, admission control, workload identity) and ability to operate it.

Responsibilities

  • Own cloud security posture across AWS and GCPs, including IAM, network, encryption, logging, and account structure.
  • Prioritize and drive remediation of findings from Cloud Native Application Protection (CNAP) through engineering efforts, and measure progress.
  • Design and enforce IaC guardrails, including pre-merge policy-as-code, required modules, and CI gates to make secure configurations the default.
  • Lead identity and access design across cloud, Identity Provider (IdP), and developer platforms, enforcing least-privilege principles continuously.
  • Own the secrets management strategy and migrate away from long-lived credentials where feasible.
  • Conduct focused offensive testing against infrastructure, including cloud red-team scenarios, IAM privilege escalation, CI/CD supply-chain attacks, and lateral movement, translating findings into durable controls.
  • Partner with SecOps on cloud control-plane abuse detection coverage and with Product Security on the infrastructure aspects of application threat models.
  • Drive third-party and supply-chain risk management for infrastructure components like container base images, build pipelines, OSS dependencies in Terraform modules, and IaC providers.
  • Lead incident response for infrastructure-related incidents in collaboration with the SecOps lead.
  • Mentor engineers on threat modeling, secure-by-default infrastructure patterns, and blast radius analysis.

Benefits

  • Competitive compensation including salary, future token rights, and/or equity.
  • Full benefits (medical, vision, and dental).
  • Flexible vacation policy (PTO).
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service