Lead Security Engineer, Cloud Security

Circle5 months ago
San Francisco, CA, United States
Remote
Full-time
Junior Level (1-3 years)

Job Description

Position Overview

Circle (NYSE: CRCL) is one of the world's leading internet financial platform companies, building the foundation of a more open, global economy through digital assets, payment applications, and programmable blockchain infrastructure. As a Lead Cloud Security Engineer, you will safeguard our cloud infrastructure and applications, drive security initiatives across the technology stack, and collaborate with diverse teams to ensure secure, scalable solutions in a dynamic fintech landscape.

Key Responsibilities

  • Lead cloud and application security initiatives in collaboration with engineering, product, and infrastructure teams.
  • Integrate security controls and testing into CI/CD pipelines to ensure early detection and prevention of vulnerabilities.
  • Design and implement secure authentication, authorization, logging, and monitoring mechanisms.
  • Conduct and coordinate threat modeling, code reviews, and architecture assessments for new and existing systems.
  • Manage vulnerability discovery and remediation workflows using tools like Wiz or equivalent cloud-native platforms.
  • Partner with third-party vendors to perform penetration tests and security assessments.
  • Investigate escalated security events, triage incidents, and identify root causes.
  • Research emerging threats, particularly in blockchain and cloud-native environments, and adapt practices accordingly.
  • Contribute to security awareness and training initiatives to promote secure development practices across engineering.

Required Qualifications

  • 7+ years of experience in security engineering, with a focus on cloud and application security.
  • Proven track record in leading security projects and influencing security decisions in complex technical environments.
  • Hands-on experience with cloud security platforms (e.g., Wiz, Orca, Prisma Cloud) and public cloud infrastructure (AWS, GCP).
  • Strong understanding of SAST, DAST, Infrastructure as Code (IaC) scanning, and secure software development lifecycle practices.
  • Familiarity with container and orchestration security (e.g., Kubernetes, Docker).
  • Experience in designing and implementing detection logic, security controls, and automated guardrails.
  • Proficiency in at least one scripting or programming language (e.g., Python, Go, JavaScript).
  • Ability to work cross-functionally, lead initiatives, and prioritize effectively in a fast-paced environment.

Preferred Qualifications

  • Experience in the fintech, crypto, or blockchain space.
  • Familiarity with cryptographic fundamentals and blockchain-specific threat models.
  • Experience with tools and languages such as Terraform, Rust, Solidity, or Move.
  • Relevant certifications (e.g., CCSP, OSCP, CISSP, CEH).
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity, or equivalent experience.

Benefits & Perks

  • Base Pay Range: $172,500 - $227,500
  • Inclusive and flexible work environment that embraces innovation and supports diversity.

Required Skills

CI/CD Pipeline Integration
Threat Modeling
Scripting (Python, Go)
Application Security
Container & Orchestration Security
Vulnerability Management
Cloud Security