
Senior Security Engineer
- Hybrid
- Singapore, Central Singapore, Singapore
- Kualar Lumpur, Selangor, Malaysia
+1 more- Developers
Job description
Senior Security Engineer
Location: Singapore or Kuala Lumpur
Employment Type: Full-time
About the Opportunity
Nodeworthy is supporting a leading Solana-based decentralized exchange in hiring a Senior Security Engineer.
You will own and continuously improve the security of the company’s engineering and production environment. The role spans cloud infrastructure, DevOps, SRE, backend services, frontend applications, CI/CD pipelines and internal engineering systems.
This is a deeply hands-on position. The successful candidate must be able to do more than review systems and recommend improvements—you should be comfortable investigating incidents, modifying code and infrastructure, deploying fixes, monitoring the results and taking responsibility for production outcomes.
The ideal profile is an experienced DevOps or infrastructure engineer with strong security instincts and solid backend engineering capabilities. You may investigate suspicious production activity, strengthen cloud controls and contribute directly to backend or DevOps work within the same week.
Smart-contract auditing and protocol-level security reviews are handled by a separate internal team and are not part of this role.
What You’ll Own
Security Monitoring and Incident Response
Build and maintain security monitoring, logging, detection and alerting across infrastructure and applications.
Monitor cloud resources, production services, databases, APIs, CI/CD systems and engineering environments for suspicious activity.
Establish processes for identifying, triaging, investigating and responding to security incidents.
Investigate unusual access patterns, authentication attempts, API activity, infrastructure changes and abnormal application behaviour.
Lead incident containment, remediation, root-cause analysis and post-incident reviews.
Develop and maintain practical incident-response playbooks.
Define security metrics and provide clear reporting to engineering leadership.
Continuously improve the organisation’s detection and response capabilities.
Cloud and Infrastructure Security
Own the security posture of the company’s cloud and production infrastructure.
Secure and monitor GCP environments, including IAM, service accounts, Kubernetes, networking, compute, storage, databases and managed services.
Implement appropriate access controls and least-privilege policies.
Strengthen the management of credentials, secrets, API keys, service accounts and privileged access.
Identify and remediate misconfigurations, unnecessary permissions, exposed services and other infrastructure risks.
Introduce network segmentation and additional controls around sensitive systems.
Establish secure infrastructure baselines and monitor environments for deviations.
Work closely with DevOps and SRE engineers to incorporate security into infrastructure architecture and operational processes.
CI/CD and Software-Supply-Chain Security
Secure CI/CD pipelines, build systems, deployment infrastructure and engineering tooling.
Identify and reduce software-supply-chain risks.
Strengthen the security of source-code repositories, build environments, deployment credentials and automation systems.
Implement branch protections, access controls, secrets management and production deployment safeguards.
Introduce automated security checks into development and deployment workflows where appropriate.
Review infrastructure-as-code and deployment configurations for security weaknesses.
Ensure production deployments are auditable and have suitable approval, recovery and rollback controls.
Help developers adopt secure practices without unnecessarily slowing delivery.
Application and Engineering Security
Conduct security reviews of new products, services, APIs, features and infrastructure.
Identify vulnerabilities involving authentication, authorisation, injection, insecure configurations, data exposure and software dependencies.
Establish practical secure-coding and engineering standards.
Review third-party services and dependencies for security risks.
Improve API, endpoint, authentication and service-to-service security.
Partner with frontend engineers to identify and mitigate client-side risks.
Define appropriate security requirements during technical and product design.
Backend and DevOps Engineering
Contribute directly to backend services and APIs when required.
Review backend architecture for security, scalability, reliability and maintainability.
Identify and fix vulnerabilities within backend systems.
Implement controls such as authentication, authorisation, rate limiting and input validation.
Improve API security and service-to-service authentication.
Debug production incidents and performance issues.
Participate in architecture discussions and code reviews.
Provide additional backend or DevOps engineering capacity when needed.
Who You’ll Work With
This is a cross-functional role working closely with:
Backend and frontend engineering.
DevOps and SRE.
Product and operations.
External security researchers and auditors, where appropriate.
You will have significant autonomy and direct responsibility for the security and reliability of production systems.
Job requirements
What We’re Looking For
Essential Experience
At least 7 years of hands-on experience across DevOps, cloud infrastructure and production systems.
Strong knowledge of cloud security, particularly Google Cloud Platform and Kubernetes.
Deep understanding of networking, IAM, authentication, authorisation and secrets management.
Experience securing CI/CD pipelines and infrastructure-as-code.
Experience building and operating security monitoring, logging and alerting systems.
Strong incident-response capabilities, from initial investigation through containment, root-cause analysis and remediation.
Ability to navigate large codebases, infrastructure configurations, logs and production environments independently.
Strong backend engineering experience with the ability to contribute directly to backend and DevOps code.
Proficiency in at least one relevant backend language, such as Go, Python, TypeScript/Node.js, Java or Rust.
Strong debugging, analytical and problem-solving skills.
Ability to operate independently within a fast-moving engineering environment.
Working knowledge of cryptocurrency, blockchain, DeFi and exchange infrastructure.
Bonus Experience
Previous experience with a cryptocurrency, blockchain, DeFi, exchange or financial-technology company.
Significant production experience with Google Cloud Platform.
Experience securing high-availability or high-throughput financial systems.
Experience collaborating with external security researchers, penetration testers or auditors.
Diploma or bachelor’s degree in Computer Science, Cloud Security, Infrastructure Security or a related discipline.
Scope Clarification
This position focuses on cloud, infrastructure, application, operational and engineering security. Smart-contract auditing and protocol-security reviews fall outside the scope of the role.
Location Requirement
Candidates must be based in Singapore or Kuala Lumpur.
Application
This is a confidential search managed by Nodeworthy.
To apply, please submit:
Your CV.
A brief description of a security incident you investigated and how you resolved it.
Examples of cloud, DevOps, SRE or backend systems you have built or secured.
Your GitHub profile or technical portfolio, if available.
Shortlisted candidates will receive further information about the company and opportunity directly from Nodeworthy.
or
All done!
Your application has been successfully submitted!
You've already applied for this job
Thank you for your interest - we've already received your application, so this new submission can't be accepted. Your previous application is on file.
If you need assistance or believe this is an error, please email us at apply@nodeworthy.recruitee-mailbox.com