FreshRemote.Work

Principal Security Engineer, Security

Seattle - remote first in US

Circle is a financial technology company at the epicenter of the emerging internet of money, where value can finally travel like other digital data — globally, nearly instantly and less expensively than legacy settlement systems. This ground-breaking new internet layer opens up previously unimaginable possibilities for payments, commerce and markets that can help raise global economic prosperity and enhance inclusion. Our infrastructure – including USDC, a blockchain-based dollar – helps businesses, institutions and developers harness these breakthroughs and capitalize on this major turning point in the evolution of money and technology.

What you’ll be part of:

Circle is committed to visibility and stability in everything we do. As we grow as an organization, we're expanding into some of the world's strongest jurisdictions. Speed and efficiency are motivators for our success and our employees live by our company values: Multistakeholder, Mindfulness, Driven by Excellence and High Integrity. Circlers are consistently evolving in a remote world where strength in numbers fuels team success. We have built a flexible and diverse work environment where new ideas are encouraged and everyone is a stakeholder.

What you’ll be responsible for:

Circle is looking for a passionate Principal Security Engineer with an expertise in Product and BlockChain  Security to help drive and implement technical strategies, innovative tooling, research, and processes. You’ll be part of the overall Security Engineering team and closely partner with the Engineering, Infrastructure, and IT teams responsible for supporting our cloud operations, software development, fleet of devices and endpoints.

What you'll work on:

  • Work with the product management and software engineering teams during all phases of the SDLC to ensure that applications are designed and implemented securely
  • Test web3 and web2 applications and underlying systems for vulnerabilities using both tools and manual techniques; manage the remediation of findings through resolution
  • Recommend code changes to eliminate vulnerabilities
  • Automate security tests within the CI/CD pipeline
  • Help develop secure coding standards and training materials based on findings seen in Circle’s environment to empower engineers to write more secure code
  • Research vulnerabilities specific to blockchain technologies and incorporate this knowledge in Circle’s security practices
  • Serve as an escalation point to investigate security alerts and identify incidents
  • Investigate vulnerability reports related to Circle products and systems
  • Manage vendors to conduct penetration tests and other security-related projects
  • Influence the continuous improvement of the application security program
  • Support other security team projects such as threat modeling, vulnerability scanning, and audits.

You will aspire to our four core values:

  • Multistakeholder - you have dedication and commitment to our customers, shareholders, employees and families and local communities.
  • Mindful - you seek to be respectful, an active listener and to pay attention to detail.  
  • Driven by Excellence - you are driven by our mission and our passion for customer success which means you relentlessly pursue excellence, that you do not tolerate mediocrity and you work intensely to achieve your goals. 
  • High Integrity - you seek open and honest communication, and you hold yourself to very high moral and ethical standards.  You reject manipulation, dishonesty and intolerance.

What you’ll bring to Circle:

  • 7+ years of total experience in a cyber security role
  • 4+ years of experience as a security engineer that has been leading and driving projects and developing resolutions in cybersecurity
  • Enthusiasm for securing and breaking software 
  • Experience with common attack techniques and conducting penetration tests
  • Experience designing software security features including, but not limited to, access control features, logging and monitoring features, input validation and session management.
  • Experience automating security tests in CI/CD pipelines
  • Experience working on applications deployed within AWS and GCP.
  • Experience working with Blockchains such as Etherium, Bitcoin, Solana
  • Working knowledge of public and private key cryptography
  • Demonstrated familiarity with techniques for making software robust against common attacks
  • Self-motivated and creative problem-solver able to work independently with minimal guidance
  • Demonstrated ability to work collaboratively across geographically distributed teams
  • Ability to manage multiple competing priorities and use good judgment to establish order of priorities on the fly
  • Experience working in financial services or financial technology desired
  • Bachelor's degree in computer science, computer engineering, cybersecurity or related field  Equivalent experience also accepted 
  • Certifications such as CISSP, CEH, or similar will receive favorable consideration but are not required
  • Experience with at least several of the following is highly desirable:  Solidity, Rust, Go, Move, JSON, and Python 
  • Previous experience working in a remote environment is preferred
  • An appetite for work travel when needed

Additional Information:

  • This position is eligible for day-one PERM sponsorship for qualified candidates.

Circle is on a mission to create an inclusive financial future, with transparency at our core. We consider a wide variety of elements when crafting our compensation ranges and total compensation packages.

Starting pay is determined by various factors, including but not limited to: relevant experience, skill set, qualifications, and other business and organizational needs. Please note that compensation ranges may differ for candidates in other locations.

Base Pay Range: $200,000 - $257,500

Annual Bonus Target: 17.5%

Also Included: Equity & Benefits (including medical, dental, vision and 401(k)). Circle has a discretionary vacation policy. We also provide 10 days of paid sick leave per year and 11 paid holidays per year in the U.S.

We are an equal opportunity employer and value diversity at Circle. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Additionally, Circle participates in the E-Verify Program in certain locations, as required by law.

#LI-Remote Apply

Job Profile

Regions

North America

Countries

United States

Restrictions

Remote first in US

Benefits/Perks

Day-one PERM sponsorship Day-one PERM sponsorship for qualified candidates Dental Diverse team culture Diverse work environment Driven by Excellence Encouragement of new ideas Equity Equity & Benefits Flexible and diverse work environment Flexible work environment High Integrity Inclusive financial future Medical Mindful Multistakeholder Transparency Vision

Tasks
  • Automate security tests
  • Develop secure coding standards
  • Drive technical strategies
  • Investigate security alerts
  • Manage remediation of findings
  • Manage vendors for security projects
  • Recommend code changes
  • Research
  • Research blockchain vulnerabilities
  • Support application security program
  • Test applications for vulnerabilities
Skills

Attention to detail AWS Benefits Blockchain Blockchain Security Blockchain Technologies CI/CD CI/CD automation Cloud operations Coding Communication Communities Compensation Continuous Improvement Cybersecurity Development Financial Services Financial technology GCP Go Infrastructure Management Monitoring Operations Organization Payments Penetration Testing Product Management Python Research Rust SDLC Secure coding Security Security Engineering Software Development Software Engineering Solana Technology Threat modeling Training Vulnerability assessment Vulnerability Scanning Web3 Web application security

Experience

7 years

Education

Bachelor's Bachelor's degree Bachelor's degree in Computer Science Business Computer Engineering Computer Science Cybersecurity Engineering Equivalent Related Field

Timezones

America/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9