Lead Security Engineer, Cloud Security
Circle5 months ago
San Francisco, CA, United States
Remote
Full-time
Junior Level (1-3 years)
Job Description
Position Overview
Circle (NYSE: CRCL) is one of the world's leading internet financial platform companies, building the foundation of a more open, global economy through digital assets, payment applications, and programmable blockchain infrastructure. As a Lead Cloud Security Engineer, you will safeguard our cloud infrastructure and applications, drive security initiatives across the technology stack, and collaborate with diverse teams to ensure secure, scalable solutions in a dynamic fintech landscape.
Key Responsibilities
- Lead cloud and application security initiatives in collaboration with engineering, product, and infrastructure teams.
- Integrate security controls and testing into CI/CD pipelines to ensure early detection and prevention of vulnerabilities.
- Design and implement secure authentication, authorization, logging, and monitoring mechanisms.
- Conduct and coordinate threat modeling, code reviews, and architecture assessments for new and existing systems.
- Manage vulnerability discovery and remediation workflows using tools like Wiz or equivalent cloud-native platforms.
- Partner with third-party vendors to perform penetration tests and security assessments.
- Investigate escalated security events, triage incidents, and identify root causes.
- Research emerging threats, particularly in blockchain and cloud-native environments, and adapt practices accordingly.
- Contribute to security awareness and training initiatives to promote secure development practices across engineering.
Required Qualifications
- 7+ years of experience in security engineering, with a focus on cloud and application security.
- Proven track record in leading security projects and influencing security decisions in complex technical environments.
- Hands-on experience with cloud security platforms (e.g., Wiz, Orca, Prisma Cloud) and public cloud infrastructure (AWS, GCP).
- Strong understanding of SAST, DAST, Infrastructure as Code (IaC) scanning, and secure software development lifecycle practices.
- Familiarity with container and orchestration security (e.g., Kubernetes, Docker).
- Experience in designing and implementing detection logic, security controls, and automated guardrails.
- Proficiency in at least one scripting or programming language (e.g., Python, Go, JavaScript).
- Ability to work cross-functionally, lead initiatives, and prioritize effectively in a fast-paced environment.
Preferred Qualifications
- Experience in the fintech, crypto, or blockchain space.
- Familiarity with cryptographic fundamentals and blockchain-specific threat models.
- Experience with tools and languages such as Terraform, Rust, Solidity, or Move.
- Relevant certifications (e.g., CCSP, OSCP, CISSP, CEH).
- Bachelor's degree in Computer Science, Engineering, Cybersecurity, or equivalent experience.
Benefits & Perks
- Base Pay Range: $172,500 - $227,500
- Inclusive and flexible work environment that embraces innovation and supports diversity.
Required Skills
CI/CD Pipeline Integration
Threat Modeling
Scripting (Python, Go)
Application Security
Container & Orchestration Security
Vulnerability Management
Cloud Security