Back to Jobs
Development Just now

Engineering Lead - Security

United StatesUnited States
Full-time
Not Disclosed
Lead/Manager

Job Description

Key Skills Required

Master these to land this role

BackendBestseller 🔥
Learn in 18 Hours
DevOpsBestseller 🔥
Learn in 63 Hours
Smart ContractsCybersecurityBlockchain

Want to know if you're a match for this job?

Calculate My Match Score

We're looking for an Engineering Lead to own security across Somnia—the infrastructure and operations running the L1, the products and services teams ship on top of it, the policies and processes that govern how we work, and the multisig and key management protecting the protocol's most critical assets.

A senior, hands-on role: you help set the security strategy and posture and do the work—hardening infrastructure, defining incident response, securing signing and treasury operations, and raising the bar across the team. You treat security as an enabler of velocity, not a blocker, and use AI as a multiplier.

Key Responsibilities:

  • Work with the other technical leaders to help define the engineering culture and bar.

  • Own the security posture of the L1 infrastructure—validators, RPC, signing services, supporting systems. Harden hosts, networks, and pipelines; drive vulnerability management, patching, and security monitoring.

  • Define and roll out the policies and standards that govern the organization—access control, secrets management, secure SDLC, change management, compliance-readiness. Practical enough that engineers actually follow them.

  • Drive application and supply-chain security for what Somnia ships—secure-by-default patterns, dependency and build-pipeline scanning in CI, and security reviews where the stakes are highest. That includes the agentic workflow itself: the permissions and provenance of agent-authored changes. Product teams own their security day-to-day; you set the bar and pave the road.

  • Design and operate multisig governance, signing ceremonies, and the key lifecycle (generation, storage, rotation, recovery) for treasury, upgrades, and privileged ops. No single points of failure; everything auditable.

  • Build and lead the security incident-response capability—detection, triage, containment, blameless postmortems—and run tabletops, from a compromised laptop to a live protocol exploit, so the team is ready before an incident, not during one.

  • Stay hands-on—threat modeling, security reviews, and red-team exercises—and coordinate external audits and bug bounties to raise the bar company-wide.

  • Work with the infrastructure and L1 teams so that node and validator operations resist compromise and upgrades ship safely.

Requirements:

Must Have

  • Extensive security engineering, with deep infrastructure security and SecOps expertise at scale—and the application-security breadth to raise the bar across product teams.

  • Hands-on securing and operating production systems—Linux internals, networking, containers/Kubernetes, IaC.

  • Track record defining and implementing security policies an engineering org actually adopts.

  • Key management at depth: signing workflows, HSMs, secrets management, key generation/rotation/recovery.

  • Strong incident response leadership: detection, containment, forensics, postmortems.

  • Cryptography fundamentals as applied to blockchain and key management.

  • Senior-level ownership and judgment; clear communication and the ability to influence without authority.

  • Comfortable in high-stakes environments. These are financial systems with real money on the line—mistakes are expensive and public, and that pressure has to sit fine with you.

  • Genuine interest in crypto and on-chain systems.

Nice to Have

  • Securing blockchain L1/L2 node and validator infrastructure.

  • Multisig governance and treasury operations in production.

  • EVM, smart contract security, and DeFi attack surfaces (MEV, bridges, oracles).

  • Coordinating external audits, bug bounties, and responsible disclosure.

  • Red teaming, offensive security, or detection engineering.

  • High-throughput or low-latency systems where security can't compromise performance.

How We Work

  • Agent maximalists: We are strong believers in agentic tooling being a massive accelerant to velocity beyond vibe coding prototypes: from equipping engineers with the latest tools through to agentic harnesses for security testing and shipping fixes and small features end-to-end.

  • Ownership and autonomy: A lean team that optimizes for individual impact and velocity. Engineers own features end-to-end, from idea to production, and are trusted to make the call to ship.

  • Outcome-oriented: We take on hard technical problems, but the tech is always a means to an end. What matters is what ships and the impact it has, not cleverness for its own sake.

  • Best tool for the job: We solve interesting problems in the simplest way possible. Mostly TypeScript for full-stack apps, C++ for high-performance systems, Go for infrastructure services and Solidity for smart contracts.

Why Join Somnia?

  • Design The Future: Join Somnia to work remotely with a global team, earn competitive compensation with token incentives, and help build the future of Web3 at a company where your impact truly matters.

  • First of its Kind: Make Somnia famous as the only hyperspeed L1 with native AI inference.

  • High Stakes: Influence a brand targeting a $1M+ launch budget in the 2026 peak-fragility market.

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More