Staff Application Security Engineer
Gemini (View all Jobs)
New York, New York; Portland, Oregon; Chicago, Illinois; Los Angeles, California; San Francisco, California; Remote
1. Phone chat 2. Take-home project 3. Discussion on-site. Questions on prior experiences and culture fit
Empower the Individual Through Crypto
Gemini is a crypto exchange and custodian that allows customers to buy, sell, store, and earn more than 30 cryptocurrencies like bitcoin, bitcoin cash, ether, litecoin, and Zcash. Gemini is a New York trust company that is subject to the capital reserve requirements, cybersecurity requirements, and banking compliance standards set forth by the New York State Department of Financial Services and the New York Banking Law. Gemini was founded in 2014 by twin brothers Cameron and Tyler Winklevoss to empower the individual through crypto.
Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build crypto products that are simple, elegant, and secure. Whether you are an individual or an institution, we want to help you buy, sell, and store your bitcoin and cryptocurrency. Crypto is not just a technology, it's a movement.
At Gemini, our mission is to empower the individual and that includes giving our employees flexibility of choice — our Office Optional Policy allows employees to choose to work from one of our physical locations or from home.
Select roles that are location-specific will still be eligible for flexible schedules.
The Department: Information Security
In the emerging industry of digital assets, there is nothing more important than trust (which is why Gemini’s very first hires were Security experts). The Gemini Security team forms the backbone of all that we do and is as diverse as the number of challenges we tackle in the crypto space. From security architecture and engineering to maintenance of cold storage systems and data centers to cybersecurity and litigation support, our team ensures that our customers, clients, and employees are safe, secure, and supported.
The Role: Staff Security Engineer - Blockchain
The Application Security team establishes a "paved road" for our engineers so that they can more-easily deliver secure software with minimal friction, supporting their work across the entire Secure Development Lifecycle (SDL). The Application Security team considers how we’re balancing friction with security value, fighting back “security theater” by using our expertise with an empathetic, customer-service approach.
Our blockchain security team within Application Security is focused on ensuring the safety and security of Gemini and our customer’s on-chain operations and assets. New tokens, networks, decentralized finance products, and web3 interactive platforms are being released everyday. The Blockchain Security team stays on the cutting edge so that Gemini can continue to deliver innovative crypto-based products while keeping our customers safe.
- Support engineers across the SDL, including design reviews, threat modeling, and code audits of blockchain-related infrastructure
- Evaluate security risk of new cryptocurrencies tokens and networks
- Consult with Gemini’s various businesses on the best blockchain security practices
- Deliver automation for high-signal, low-noise security tooling to increase coverage
- Collaborate with product and engineering on architecting resilient, security-first services
- Partner with third-party security firms to provide external validation of software development
- Provide subject matter expertise to business partners on vendor selection as necessary
- 5+ years of experience working in application security roles or performing similar job functions
- Enjoys working directly with software engineers, including in new languages, tool chains, and tech stacks
- Prior experience with securing/hacking smart contracts or decentralized platforms (crypto or traditional)
- Prior leadership of security design reviews, threat modeling, and defining security requirements
- Awareness of numerous vulnerability classes, with knowledge of modern mitigation techniques
- Detail-oriented communication skills via email, pull requests, and/or in-person presentations
- Able to balance a software implementation's relative risk in context to defined business goals
- Creating and extending software for development tooling to improve security automation
- Experience building (or breaking) smart contracts (Solidity, Vyper, Rust, etc)
- Experience working with decentralized networks (either crypto or traditional)
- Experience with the finance sector (DeFi or traditional FinTech)
- Experience working with low-level cryptographic implementations/primitives
It Pays to Work Here
We take a holistic approach to compensation at Gemini, which includes:
- Competitive base salaries across all departments
- Ownership in the company via profit sharing units
- Amazing benefits, 401k match contribution, and flexible hours
- Snacks, Perks, Wellness Outings & Events
At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace and affirmative action employer. If you have a specific need that requires accommodation, please let a member of the People Team know.
Please mention No Whiteboard if you apply!
I'm a one-man team looking to improve tech interviews, and could use any support! 😄