安全工程师,Privy
查看雇主原标题
Security Engineer, PrivyStripe · NYC-Privy
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 42/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 稀有职位+1
- 公司来源健康度+8
该职位未包含:已披露薪资、远程职位、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译我们是谁
关于 Privy
我们的使命是让隐私和用户所有权成为在线默认。为此,我们为开发者构建简单、灵活的 API 和工具,使在加密轨道上构建新产品变得容易。
Privy 拥有钱包之上的抽象层和基础设施层,跨链、第三方提供商以及 Stripe 产品(如 Treasury 和 Link)进行集成。我们既能解决棘手的技术问题,又能利用 Stripe 的分销渠道触达 Ramp、Klarna、Deel、Kraken、Hyperliquid 和 Fomo 等客户——为主流用户和加密原生用户提供体验。
了解更多关于 Privy 的信息:Privy 与 Stripe:让加密货币惠及每个人
关于团队
Privy 的工程团队以以下特点著称:
• 高紧迫感:以极快的速度交付非常小的迭代,从而非常快速地学习。
• 产品品味:我们的客户是开发者,为他们构建有效的产品需要技术知识——你常常会是“那个 PM”。
• 安全思维:我们产品的很大一部分是信任。虽然我们有专门的安全团队,但每位工程师从一开始就将安全融入他们的设计中。
在实践中,我们使用 Node、React 和 AWS 这类无聊的技术,这样我们就能将工程精力完全集中在推动 Privy 核心产品的边界上,例如通过硬件飞地、多区域低延迟 API,以及主流开发者可以访问的区块链抽象。
你将做什么
作为 Privy 的安全工程师,你将通过亲身调查、运营所有权以及编写真实代码解决真实问题,帮助保持一个快速增长的平台的安全。你将跨安全运营、事件响应、应用和基础设施安全以及内部工具开展工作。
这个角色不仅限于审查日志和设计或简单地升级发现的问题。你将真正拥有保护 Privy 的日常工作:调查异常、改进安全工作流,并构建自动化,使团队随着时间推移变得更快、更有效。你将与 Privy 的工程师密切合作,并与密码学、应用安全、攻击性安全和基础设施安全方面的专家并肩工作,将安全专业知识转化为实用、持久的成果。
职责
• 拥有安全引擎
岗位职责
作为 Privy 的安全工程师,你将通过亲身调查、运营所有权以及编写真实代码解决真实问题,帮助保持一个快速增长的平台的安全。你将跨安全运营、事件响应、应用和基础设施安全以及内部工具开展工作。
这个角色不仅限于审查日志和设计或简单地升级发现的问题。你将真正拥有保护 Privy 的日常工作:调查异常、改进安全工作流,并构建自动化,使团队随着时间推移变得更快、更有效。你将与 Privy 的工程师密切合作,并与密码学、应用安全、攻击性安全和基础设施安全方面的专家并肩工作,将安全专业知识转化为实用、持久的成果。
• 端到端负责安全工程工作:调查警报、发现、异常和安全请求;识别根本原因;推动修复;并清晰记录结果。
• 参与 Privy 的安全值班轮换,帮助响应事件、分诊警报、支持漏洞工作流、完成访问审查,并处理安全升级事项。
• 构建和维护生产级工具,减少手动工作,包括警报丰富、自动分诊和路由、修复工作流、访问审查自动化以及检测改进。
• 主导对疑似安全事件或入侵的专项调查,有条不紊地收集证据并协调适当的响应。
• 主动识别反复出现的运营琐事来源,并设计持久解决方案,提高团队的速度、一致性以及扩展能力。
• 与产品和工程团队合作,评估安全风险,审查较低复杂度的设计和实施计划,并做出实用的安全权衡,以高质量和稳健性快速交付。
• 在 Privy 的应用、基础设施、云和产品安全领域做出贡献,建立广泛的背景,同时随着时间推移积累更深入的专业知识。
任职要求
我们正在寻找满足该职位最低要求的人选。如果你满足这些要求,我们鼓励你申请。优先资格是加分项,而非要求。
最低要求
• 在技术要求高的环境中担任安全工程师、检测工程师或类似亲力亲为的工程师的经验。
• 在 Python、Go、Ruby 或类似语言方面具备扎实的软件工程技能。你能够构建可维护的工具,并直接为生产修复做出贡献,而不仅仅是编写一次性脚本。
• 具备调查安全信号、事件、漏洞、可疑活动或其他模糊技术问题直至解决的经验。
• 熟悉安全运营、事件响应、漏洞管理、检测工程、访问审查或相关运营安全工作流。
• 对 Web、浏览器、基础设施或云安全有深入理解,并能够将这种理解应用于广泛的问题。
• 在压力下具备良好的判断力,有条不紊的调查方法,并能在信息不完整的情况下独立自主地开展工作。
• 出色的沟通和协作能力,包括能够向客户和内部利益相关者清晰解释技术发现、风险和建议行动。
• 自主驱动的工作方式:你能发现缺口,在模糊中取得进展,并可靠地闭环。
• 具备 AWS、GCP 或其他云安全环境的经验。
• 具备检测工程、安全自动化、事件响应工具或修复流水线的经验。
• 具备漏洞赏金经验、攻击性安全经历,或强烈的攻击者思维调查方法。
• 具备 IAM、密钥管理、安全的生产访问或安全 CI/CD 的经验。
• 具备应用安全、基础设施安全、密码学或隐私工程的背景。
• 具备金融科技、支付、区块链或其他注重尽职调查的金融产品领域的经验。
• 具备帮助塑造安全运营、事件响应实践、漏洞管理工作流或漏洞赏金计划的经验。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
Who we are
About Privy
Our mission is to make privacy and user ownership the default online. To do so, we build simple, flexible APIs and tools for developers that make it easy to build new products on crypto rails.
Privy owns the abstractions and infrastructure layer above wallets, integrating across chains, third-party providers, and Stripe products like Treasury and Link. We get to solve hard technical problems while leveraging Stripe's distribution to reach customers like Ramp, Klarna, Deel, Kraken, Hyperliquid, and Fomo — powering experiences for both mainstream users and crypto natives.
Learn more about Privy: Privy and Stripe: Bringing crypto to everyone
About the team
Engineering at Privy is distinguished by:
• High urgency: Shipping very small iterations, very fast, to learn very quickly.
• Product taste: Our customers are developers, and to build effective products for them requires technical knowledge - you will often be "the PM".
• Security mindset: A great portion of our product is trust. While we have a dedicated security team, every engineer brings security to their designs from the start.
In practice, we use boring technology like Node, React, and AWS so we can focus our engineering energy entirely on pushing the boundaries of Privy's core product, e.g. through hardware enclaves, multi-region low latency APIs, and blockchain abstractions that are accessible to mainstream developers.
What you’ll do
As a Security Engineer at Privy, you will help keep a rapidly growing platform secure through hands-on investigation, operational ownership, and building real code to solve real problems. You’ll work across security operations, incident response, application and infrastructure security, and internal tooling.
This is not a role limited to reviewing logs and designs or simply escalating findings. You will carry real ownership for the day-to-day work that protects Privy: investigating anomalies, improving security workflows, and building the automation that makes the team faster and more effective over time. You’ll work closely with engineers across Privy and alongside specialists in cryptography, application security, offensive security, and infrastructure security to turn security expertise into practical, durable outcomes.
Responsibilities
• Own security engine
岗位职责
As a Security Engineer at Privy, you will help keep a rapidly growing platform secure through hands-on investigation, operational ownership, and building real code to solve real problems. You’ll work across security operations, incident response, application and infrastructure security, and internal tooling.
This is not a role limited to reviewing logs and designs or simply escalating findings. You will carry real ownership for the day-to-day work that protects Privy: investigating anomalies, improving security workflows, and building the automation that makes the team faster and more effective over time. You’ll work closely with engineers across Privy and alongside specialists in cryptography, application security, offensive security, and infrastructure security to turn security expertise into practical, durable outcomes.
• Own security engineering work end to end: investigate alerts, findings, anomalies, and security requests; identify root causes; drive remediation; and clearly document outcomes.
• Participate in Privy’s security on-call rotation, helping respond to incidents, triage alerts, support vulnerability workflows, complete access reviews, and handle security escalations.
• Build and maintain production-quality tooling that reduces manual work, including alert enrichment, automated triage and routing, remediation workflows, access-review automation, and detection improvements.
• Lead focused investigations into suspected security events or compromises, gathering evidence methodically and coordinating the appropriate response.
• Proactively identify recurring sources of operational toil and engineer durable solutions that improve the team’s speed, consistency, and ability to scale.
• Partner with product and engineering teams to assess security risks, review lower-complexity designs and implementation plans, and make practical security tradeoffs to deliver quickly with quality and soundness.
• Contribute across Privy’s application, infrastructure, cloud, and product-security surface area, developing broad context while building deeper expertise over time.
任职要求
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
• Experience as a security engineer, detection engineer, or similarly hands-on engineer in a technically demanding environment.
• Strong software-engineering skills in Python, Go, Ruby, or a similar language. You can build maintainable tooling and contribute directly to production fixes, not only one-off scripts.
• Experience investigating security signals, incidents, vulnerabilities, suspicious activity, or other ambiguous technical problems through to resolution.
• Familiarity with security operations, incident response, vulnerability management, detection engineering, access reviews, or related operational-security workflows.
• A strong understanding of web, browser, infrastructure, or cloud security, with the ability to apply that understanding across a broad range of problems.
• Good judgment under pressure, a methodical approach to investigation, and comfort working independently with agency despite incomplete information.
• Strong communication and collaboration skills, including the ability to explain technical findings, risks, and recommended actions clearly to clients and internal stakeholders alike.
• A self-directed approach to work: you notice gaps, make progress through ambiguity, and reliably close the loop.
• Experience with AWS, GCP, or other cloud-security environments.
• Experience with detection engineering, security automation, incident-response tooling, or remediation pipelines.
• Bug-bounty experience, offensive-security exposure, or a strong attacker-minded approach to investigation.
• Experience with IAM, secrets management, secure production access, or secure CI/CD.
• Background in application security, infrastructure security, cryptography, or privacy engineering.
• Experience with fintech, payments, blockchain, or another diligence-forward financial product domain.
• Experience helping shape security operations, incident-response practices, vulnerability-management workflows, or a bug-bounty program.