Member of Technical Staff, Security Operations
Anchorage · United States
- Location
- United States
- Workplace
- Remote
- Employment
- Full time
- Level
- Staff
- Posted
- 21 months ago
About this role
Technical Skills:
- Build and maintain security automation and tooling to detect vulnerabilities through static and dynamic analysis across code and live systems.
- Conduct application security assessments, penetration tests, and code reviews to identify high-risk security issues and provide secure development guidance.
- Develop and operate vulnerability management workflows, partnering with engineering teams to prioritize and remediate findings.
- Establish and test security guardrails for code, cloud resources, and infrastructure components throughout the Anchorage platform.
Complexity and Impact of Work:
- Monitor and respond to security events and configuration anomalies across the organization, leading investigation and containment efforts.
- Manage the full vulnerability lifecycle from discovery through remediation, tracking progress and ensuring timely closure of findings.
- Lead or substantially contribute to Security Operations initiatives with minimal oversight, coordinating across team boundaries to drive projects to completion.
- Break complex security problems into manageable workstreams with accurate scope and time estimates. Present options clearly and provide well-reasoned priority recommendations.
- Deliver assurance artifacts and evidence for regulated entity requirements, supporting audit and compliance efforts.
- Balance speed of response with thoroughness of investigation, adapting approach based on risk and business impact.
Organizational Knowledge:
- Understand and help implement the company's security strategy by participating in planning and defining Security Operations goals in alignment with Anchorage Digital's overall objectives.
- Stay alert to emerging threats, vulnerabilities, and industry trends that could affect organizational security posture.
- Consider security holistically across the product ecosystem - applications, infrastructure, and third-party integrations - while fostering a security-first culture.
- Collaborate cross-functionally with Engineering, Infrastructure, and Compliance teams to embed security into development and operational processes.
Communication and Influence
- Share knowledge broadly across the team through documentation, runbooks, and post-incident reviews, preventing single points of failure.
- Partner with engineering teams to explain security risks and remediation approaches, translating technical findings into actionable guidance.
- Collaborate across teams to review security configurations, triage findings, and engage in technical discussions. Communicate insights and recommendations clearly to improve processes.
- Demonstrate empathy by understanding others' context, priorities, and constraints - adapting communication style to maximize effectiveness with both technical and non-technical audiences.
You may be a fit for this role if you have:
- Security Operations or AppSec experience: You have 3+ years of hands-on experience in security engineering, application security, penetration testing, or security operations.
- Security tooling and automation: You have built or maintained security tools, integrations, or automation workflows using Python, Go, or similar languages.
- Vulnerability assessment: You can identify and assess security vulnerabilities in applications, APIs, and cloud infrastructure, and effectively communicate remediation strategies.
- Static and dynamic analysis: You have experience with tools like Semgrep, CodeQL, Burp Suite, or equivalent for identifying security issues in code and running systems.
- Cloud security: You understand AWS security fundamentals including IAM, VPCs, security groups, and CloudTrail/logging.
- Incident response: You can investigate security events, perform root cause analysis, and coordinate response efforts.
- You have developed "computer science fundamentals," i.e. concurrency, algorithms, and data structures.
- You genuinely care about code quality and operational excellence.
- You prioritize security outcomes, end-user experience, and business value over "cool tech."
- You self-describe as some combination of the following: creative, humble, ambitious, detail-oriented, hardworking, trustworthy, eager to learn, methodical, action-oriented, and tenacious.
Although not a requirement, bonus points if:
- You have experience running or participating in bug bounty programs (HackerOne, Bugcrowd, etc.).
- You have worked in a regulated financial services, fintech, or crypto environment.
- You have exposure to blockchain security, smart contract auditing, or Web3 technologies.
- You have built or contributed to open-source security tools.
- You hold relevant certifications (OSCP, GWAPT, GCIH, AWS Security Specialty, etc.).
- You read blockchain protocol white papers for fun, and stay up to date with the proliferation of crypto-asset innovations.
- You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system. :)
As published by Anchorage. Applications are handled on their site.
Skills this posting mentions
About Anchorage
Anchorage Digital is a crypto platform that enables institutions to participate in digital assets through custody, staking, trading, governance, settlement, and the industry’s leading security infrastructure. Home to Anchorage Digital Bank N.A., the first federally chartered crypto bank in the U.S., Anchorage Digital also serves institutions through Anchorage Digital Singapore, which is licensed by the Monetary Authority of Singapore; Anchorage Digital New York, which holds a BitLicense from the New York Department of Financial Services; and self-custody wallet Porto by Anchorage Digital. The company is funded by leading institutions including Andreessen Horowitz, GIC, Goldman Sachs, KKR, and Visa, with its Series D valuation over $3 billion. Founded in 2017 in San Francisco, California, Anchorage Digital has offices in New York, New York; Porto, Portugal; Singapore; and Sioux Falls, South Dakota. For disclosures, please visit: https://www.anchorage.com/legal
All 41 openings at AnchorageOne click, then it is written
Apply to Anchorage with a resume written for this role.
Queue Member of Technical Staff, Security Operations and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Anchorage’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Anchorage
See all- 6 weeks ago
- 6 weeks ago
- 8 weeks ago
- 8 weeks ago
Member of Technical Staff, Custody (Backend Engineer)
United StatesRemote
$140k - $250k/yrStaffEngineering - 2 months ago
Member of Protocols - Client Success & Operations Manager, Token Vesting
United StatesRemote
$70k - $150k/yrManagerOperations - 2 months ago
Similar roles elsewhere
See more- Today
Senior Frontend Engineer, Ads Creative
RedditRemote - United StatesRemote
$191k - $267k/yrSeniorEngineering - Today
Staff Technical Product Manager, Ads ML Platform
RedditRemote - United StatesRemote
$217k - $304k/yrStaffEngineering - Today
Senior Software Engineer, Agentic Ads Experience
RedditRemote - United StatesRemote
$217k - $304k/yrSeniorEngineering - Today
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Anchorage publishes. Refolk is not the employer and does not handle their hiring. Applications go to Anchorage directly.