About the job
About the Role
ether.fi is hiring a Security Engineer to join the team in Cayman. This role focuses on hands-on security work, especially around CI/CD pipelines, backend authentication, and managing bug bounty submissions. The position goes beyond compliance, with a strong emphasis on building and collaborating directly with engineering teams to secure infrastructure, protocols, and platforms.
This is an in-office role in Cayman. Daily on-site presence is required.
Main Responsibilities
Security Operations
- Monitor, alert, triage, and respond to security incidents as part of daily operations.
- Oversee endpoint security using an EDR system: fine-tune detections, investigate alerts, and resolve incidents.
- Manage identity lifecycles, including employee onboarding and offboarding, access provisioning, key rotation, and deprovisioning.
Bug Bounty & Vulnerability Management
- Own the ImmuneFi bug bounty program: triage, reproduce, and respond to submissions daily.
- Work closely with protocol and engineering teams to prioritize and track vulnerabilities until remediation.
- Develop internal tools and processes to make the bounty workflow more efficient and consistent.
DevSecOps & Pipeline Hardening
- Audit and strengthen CI/CD pipelines, focusing on secrets management, supply chain integrity, and integrating SAST/DAST tools.
- Identify and mitigate vulnerabilities in dependencies across repositories, including npm packages.
- Set and enforce security standards throughout the software development lifecycle.
Infrastructure Security
- Partner with the infrastructure team to review and improve cloud environments, including access controls, network segmentation, least privilege, and logging.
- Contribute to threat modeling for new systems and architectural changes.
- Help drive the adoption of new security tools and practices.
