Senior Security Engineer (NYC / MIA)

CrossmintNew York, NY
Hybrid

About The Position

We are seeking a Senior Security Engineer to own the operational execution of security at Crossmint as we continue to scale. The volume of security operations, compliance work, and engineering support requires dedicated ownership to maintain a strong security posture as the company grows. This role is foundational. You will run the day-to-day security function, partnering closely with engineering, compliance, and external vendors to ensure our infrastructure, applications, and processes remain secure. This role enables security leadership to focus on strategy, automation, and long-term risk management while you ensure operational excellence and follow-through.

Requirements

  • 4-8 years of experience as a security engineer.
  • 3+ years of hands-on experience securing AWS environments or equivalent cloud, including IAM, Security Hub, CloudTrail, GuardDuty, and KMS.
  • Strong understanding of CI/CD security, including GitHub Actions, secrets scanning, and dependency management.
  • Experience with secure code review or application security fundamentals
  • Experience working with at least one compliance framework, preferably SOC 2, though ISO 27001 or similar is acceptable.
  • Highly organized with great attention to detail. You don’t drop balls.
  • Comfort operating in a fast-paced startup environment with ambiguity.
  • Ability to communicate security concepts clearly to non-technical stakeholders without creating friction.
  • Experience using AI-assisted tools such as Claude or GitHub Copilot for security automation.
  • Ability to work flexible hours if an incident arises

Nice To Haves

  • Fintech or payments industry experience.
  • Exposure to DORA or MiCA compliance requirements.
  • Familiarity with crypto or blockchain security considerations.

Responsibilities

  • Own and operate cloud security across our cloud environments: AWS primarily, with some exposure to GCP, Vercel.
  • Design, maintain, and monitor engineering security controls including cloud IAM, logging, monitoring/alerting, and key management.
  • Secure our coding assets, including: CI/CD pipelines, GitHub Action environments, secrets management, and software supply chain.
  • Manage security-related access controls including privileged access, service accounts, credential rotation, and performing access reviews.
  • Perform secure code reviews and provide hands-on application security support to engineering teams.
  • Review authentication flows, payment logic, and API security with human judgment, not just automated scanners.
  • Partner with engineers to remediate vulnerabilities and embed security best practices into product development.
  • Coordinate our external security review program with our 3P security auditor firms.
  • Own vulnerability management workflows including prioritization, remediation tracking, and verification.
  • Support incident response through internal triage, investigation, and remediation in collaboration with external 24/7 response partners.
  • Support SOC 2 and other compliance efforts by collecting evidence, documenting controls, and maintaining audit-ready processes for engineering-security related controls.
  • Contribute to regulatory and compliance initiatives such as DORA, where applicable.

Benefits

  • Extensive access to leading AI tools and subscriptions, with AI actively encouraged and integrated into daily workflows.
  • Stock options program.
  • Two performance reviews annually. The first addresses performance ratings, bonuses, and promotions. The second encompasses these elements along with salary adjustments reflecting inflation and market conditions.
  • Unlimited, flexible PTO.
  • Flexible work schedule.
  • Company laptop and allowance for any necessary home equipment.
  • Daily stipend for commuting to the office.
  • Company-paid trips for annual off-sites and onsites.
  • Insurance covered by Crossmint.
  • 401(k) Plan.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service