<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>68e291fb-412</externalid>
      <Title>Senior Security Engineer</Title>
      <Description><![CDATA[<p>Talent Wanted. For hazardous journey. Small wages, bitter cold, long months of complete darkness, constant danger, safe return doubtful. Honour and recognition in case of success.</p>
<p>Fridtjof Nansen crossed the Arctic, going places no human had ever been. Together with our users, we&#39;re doing the same onchain , and someone needs to make sure we don&#39;t get killed on the way there.</p>
<p>We&#39;re building the single best platform for onchain investing , agentic trading, staking infrastructure, AI-powered analytics , and we&#39;re scaling fast. Fast enough that security can&#39;t be an afterthought bolted on later. It has to be built in, from the start, by someone who knows what they&#39;re doing.</p>
<p><strong>Our mission:</strong></p>
<p>Surface the signal and create winners.</p>
<p><strong>What you&#39;ll do at Nansen</strong></p>
<p>You&#39;ll be the person who makes sure we can move fast without breaking things that matter. That means embedding security into everything we build , cloud infrastructure, applications, CI/CD pipelines, AI systems, staking operations , across a generalist role that spans the full surface area.</p>
<ul>
<li>Run security assessments across systems, architectures, and code , find the vulnerabilities before someone else does</li>
<li>Advise engineering teams on secure design decisions. You&#39;re a partner, not a blocker</li>
<li>Deploy and maintain security infrastructure: SIEM, vulnerability scanning, endpoint protection, logging , the things that let us sleep at night</li>
<li>Secure our CI/CD pipelines and deployment workflows end-to-end</li>
<li>Own secrets management, key management, and access controls. No shortcuts</li>
<li>Address LLM security head-on: API key management, prompt injection prevention, and the risks that come with shipping AI-powered products at speed</li>
<li>Coordinate penetration tests and security audits with external vendors</li>
<li>Create and maintain secure coding guidelines and code review processes that engineers actually follow</li>
<li>Represent the Security Team in the incident response process</li>
<li>Drive compliance readiness , SOC 2, ISO 27001 , pragmatically, not bureaucratically</li>
</ul>
<p><strong>What we&#39;re looking for</strong></p>
<ul>
<li>You&#39;ve built and hardened production security at scale , you know the difference between a policy document and an actually secure system</li>
<li>Strong cloud security knowledge (AWS, GCP or equivalent). Container security and network security fundamentals</li>
<li>Hands-on experience implementing security tooling, not just evaluating it</li>
<li>Secrets and key management expertise , you&#39;ve managed this at a company where it actually mattered</li>
<li>You understand the security implications of AI/LLM and agent-based systems. This is new territory and we need someone thinking about it seriously</li>
<li>CI/CD pipeline security is second nature</li>
<li>Pragmatic about compliance , you can get us to SOC 2 without drowning the engineering team in process</li>
<li>You don&#39;t just use AI as a tool. You think with it. AI-first isn&#39;t a checkbox , it&#39;s how you work</li>
<li>Strong async communication skills , we&#39;re remote-first, Slack-and-docs-heavy, and EMEA hours are preferred for team overlap</li>
<li>Bonus: blockchain, smart contract, or staking infrastructure security experience. Kubernetes and Terraform security. Incident response or security operations background</li>
</ul>
<p><strong>What we offer our crew</strong></p>
<ul>
<li>Competitive salary. Meaningful equity. Real ownership in what you build</li>
<li>Fully remote with two no-meeting days a week , because deep work doesn&#39;t happen in a Google Meet</li>
<li>Annual company retreat and team off-sites in one of our offices: Singapore, Bangkok, London, and Oslo , flights and accommodation covered</li>
<li>Unlimited AI tokens , Claude, OpenAI, whatever helps you move fast</li>
<li>Your own OpenClaw for work</li>
<li>Nansen Pro account: giving you full access to the most detailed onchain data in the market</li>
<li>A team that started as data engineers and data scientists that has grown to over 80 builders. Your craft is respected here.</li>
<li>Speed, ownership, curiosity, courage. These aren&#39;t values on a wall , they&#39;re how we run.</li>
<li>A front-row seat (and a hand in building) the next chapter of finance</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>cloud security, container security, network security, security tooling, secrets management, key management, access controls, API key management, prompt injection prevention, LLM security, CI/CD pipeline security, compliance, SOC 2, ISO 27001, blockchain security, smart contract security, staking infrastructure security, Kubernetes security, Terraform security, incident response, security operations</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Nansen</Employername>
      <Employerlogo>https://logos.yubhub.co/nansen.ai.png</Employerlogo>
      <Employerdescription>Nansen is a company building a platform for onchain investing, agentic trading, staking infrastructure, and AI-powered analytics.</Employerdescription>
      <Employerwebsite>https://nansen.ai/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/nansen/jobs/5811520004</Applyto>
      <Location>Remote Europe | Remote Asia</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>2798986b-685</externalid>
      <Title>Security Engineering Lead</Title>
      <Description><![CDATA[<p>As a Security Engineering Lead on our team, you&#39;ll be leading the security and auditing efforts for Espresso&#39;s codebase leading up to, and beyond, launch. We are looking for an experienced security engineering and software auditing professional who can lead review processes of our design and codebase.</p>
<p>Responsibilities:</p>
<p>Lead security audits of (a subset of) the Espresso codebase
As a project leader, you will have mobility in how you choose to organize security and audit efforts
Dive into the code of a fairly complex distributed system, learning and developing an understanding of the system on the fly (with help from the engineering team that built it, of course)
Coordinate with several engineering teams to aid in your audit, raise concerns and communicate results, and guide the effort to harden the system based on your findings
Coordinate with, manage, and review the work of external security auditing teams, in certain cases
Suggest improvements to testing and engineering practices to promote more secure and maintainable code</p>
<p>Requirements:</p>
<p>Solid grasp of software engineering principles, both low-level (e.g. language-specific best practices) and high-level (e.g. reliable software architecture, particularly in distributed systems)
If focused on Rust: ≥ 1 year experience writing Rust, particularly with async Rust.
If focused on Solidity: Multiple years experience writing smart contracts; experience with smart contract security audits or formal verification of smart contracts
Experience as an engineer or software architect in a security-critical industry
Be capable of describing the stakes, the challenges you&#39;ve faced in building secure software, and the steps/processes you&#39;ve taken to mitigate risk
Experience as an auditor, pentester, QA tester, etc.
Have a well thought-out approach to testing software and designing it to be testable/auditable
Ability to think adversarially, and identify potential reliability or security vulnerabilities even in software that is correct in common or “happy path” scenarios
Experience on the design and/or testing of distributed systems
Comfort diving into unknowns and asking questions</p>
<p>Preferred:</p>
<p>Knowledge of relevant testing and static analysis tools (e.g. Foundry, Slither) is a plus
Blockchain knowledge/experience is preferred, but could also be include IoT, automotive, finance, etc.
Ideally, the candidate should have a general philosophy of software design that has been molded by experience working on security-critical systems</p>
<p>Benefits:</p>
<p>Fully remote with flexible hours
Work alongside the brightest minds in the crypto space
Competitive salary + equity package
Regular team off-sites to international locations
Unlimited vacation policy
Top-tier health, dental, and vision coverage for US employees</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Rust, async Rust, Solidity, smart contract security audits, formal verification of smart contracts, software engineering principles, low-level programming, high-level programming, distributed systems, testing and static analysis tools, Foundry, Slither, blockchain knowledge, IoT, automotive, finance</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Espresso Systems</Employername>
      <Employerlogo>https://logos.yubhub.co/espressosystems.com.png</Employerlogo>
      <Employerdescription>Espresso Systems builds foundational infrastructure to power tomorrow&apos;s internet, providing rollups with secure, real-time visibility into what&apos;s happening on all integrated chains.</Employerdescription>
      <Employerwebsite>https://www.espressosystems.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/Espresso/135f4767-f690-41f8-9ab0-95fd9d398677</Applyto>
      <Location>Remote</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
  </jobs>
</source>