Security Engineer
Apply NowDepartment: Engineering
Location: Remote (US)
Type: Contract-to-hire
Intro: Onramp is hiring a Security Engineer. Remote (US). You'd own and advance the security program for a bitcoin custody platform, lead incident response, build AI-driven continuous pen testing, and still ship product code. Two-thirds security, one-third engineering. If irreversible transactions and small-team ownership sound like your kind of problem: [email protected]
Onramp is building the money platform of the future for individuals, businesses, and financial institutions: Bitcoin, dollars, and stablecoins in one place, secured by multi-institution custody and delivered through products people love and APIs institutions build on. We are a FinCEN-registered Money Services Business, run an active SOC 2 Type II program, and work directly with banks, custodians, and financial institutions. Security is not a department here. It is the product.
You'll be the day-to-day owner of Onramp's security roadmap, reporting to our Engineering Lead and partnering with our CCO, who owns SOC 2 and compliance. We already run a layered program mapped to our SOC 2 controls; your job is to take it further and keep it ahead of the threat landscape. About two-thirds of your time is security, the rest is product engineering on the same team. On any given week, you might:
- Advance our controls across identity, endpoint, network, email, and browser layers, and handle the change management that gets a small team to adopt them
- Lead incident response: triage, run the response, coordinate with custody partners when needed, and turn every event into a stronger playbook
- Build AI-driven offensive testing: continuous, agent-assisted pen testing and attack simulation that complements our manual program and feeds findings straight to engineering
- Harden the developer pipeline and cloud posture across GitHub, GCP, and Vercel: supply chain scanning, secrets management, IAM least-privilege, required checks on auth, withdrawal, and KYC paths
- Extend custody-specific monitoring and runbooks: fee wallet controls, signing and quorum alerting, address verification
- Refine the verification SOPs sales and ops use against deepfakes, synthetic identity, impersonation, and coerced withdrawals, and train the team on them
- Run access reviews, service account inventory, vendor risk reviews, and SOC 2 evidence as part of the work rather than after it
- Govern our AI-native toolchain with a lightweight pre-adoption review for new connectors and agents
- Ship product code in our TypeScript/Next.js and Elixir/Phoenix services
- 4+ years hands-on security engineering, ideally at an early- or growth-stage fintech, custody, or exchange, where you owned the controls, not just the findings
- You've run incident response end to end and written the post-incident review
- Offensive-minded, with pen testing experience and real interest in making it continuous with AI agents
- A working software engineer on at least one side of a modern stack (React/Next.js and TypeScript, or Elixir/Phoenix, Node, or comparable)
- Deep on identity, endpoint, and cloud security in a Google Workspace, GitHub, GCP, and Vercel environment, and opinionated about right-sizing tooling for a small team
- Fluent in today's threats: AI-driven supply chain attacks, session theft, OAuth phishing, deepfake social engineering
- SOC 2 in practice: you know what an auditor asks for and build evidence into the workflow
- Insanely AI-native, with strong views on securing agents without adding friction
- A clear writer of runbooks, threat models, and async updates people actually read
- Calm in an incident, direct in a review, comfortable with early-stage ambiguity and pace
- You don't need Bitcoin protocol experience to apply. You do need to be curious about it and willing to go deep on custody fast.
Bitcoin custody experience (multisig, PSBT, key-agent architectures), Elixir/Phoenix, agentic security tooling, GCP Security Command Center or Wiz, Terraform, OSCP or equivalent, CTFs or public disclosures.
- Ownership: the program, standards, and tooling are yours to drive as we scale
- Stakes: we custody bitcoin for HNW clients, RIAs, and institutions. Withdrawals are irreversible
- The AI moment: budget and mandate to push AI-native security on both the defensive and offensive side
- Range: security engineer and product engineer in one seat, on a small team where you see the whole system
Remote-first (US), high-trust, low-ceremony. Small pods, direct communication, written culture, biweekly all-hands with live AI demos. We care about output, not hours.
This role starts as a remote contract with a clear path to full-time and equity once fit is confirmed on both sides.
Intro call, technical conversation with the Engineering Lead and CCO, a working session (bring your AI toolkit), founder conversation, offer.
- High agency and first-principles thinkers
- Flat structure, builder-first execution culture
- Mission-driven: Bitcoin only, no altcoins
- Collaborative, transparent, and low-ego
- Competitive compensation, with meaningful equity on conversion to full-time
Send your resume and a short intro video to [email protected] covering:
- A security control or program you owned end to end and how you got a team to adopt it
- An incident you helped run and what changed because of it
- One AI-leveraged workflow you've built or wished you had
- Why Onramp
Email subject: Application — Security Engineer