{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/title/senior-security-engineer"},"x-facet":{"type":"title","slug":"senior-security-engineer","display":"Senior Security Engineer","count":2},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_80dbb0f6-e54"},"title":"Senior Security Engineer","description":"<p>We are seeking a subject matter expert with direct experience in a wide range of security technologies, tools, and methodologies. This role is suited for an experienced Windows Engineer with proven understanding in enterprise security and will focus on building toolsets and processes to support the Information Security Program (ISP).</p>\n<p>The team fosters a collaborative environment and is building a best-in-class program to partner with the business to protect the Firm&#39;s information and computer systems.</p>\n<p>Principal Responsibilities:</p>\n<ul>\n<li>Provide a high level of security consultancy and engineering support for Windows/Active Directory/Azure security solutions including analysis and development of Windows security solutions.</li>\n<li>Strong understanding of modern authentication protocols, e.g., OIDC / OAUTH 2.</li>\n<li>Contribute to the vision, strategy, and drive design and implementation for authentication platforms both on premises and in the cloud.</li>\n<li>Provide security consultancy and engineering support for SAML, OIDC and Kerberos authentication across different Identity providers, including analysis and development of SSO, PKI, and other authentication solutions.</li>\n<li>Able to demonstrate clear understanding of current risks and threats related to Identity Management at technical and managerial levels.</li>\n<li>Actively monitor new and emerging security and privacy related technologies, trends, issues, and solutions and assess their applicability to key business initiatives and strategies.</li>\n<li>Participate in Information Security Incident Response activities for the Firm&#39;s environment.</li>\n<li>Liaison with key stakeholders to create and enforce policy including Technology organization, Trading units, Legal, Internal Audit, and Compliance.</li>\n<li>Provide support to Security and other technical operations staff to ensure smooth turnover from Engineering to Production - and provide mentoring to junior level security professionals.</li>\n<li>Develop and maintain documentation of all Security products including specific tools, technologies, and processes.</li>\n</ul>\n<p>Qualifications/Skills Required:</p>\n<ul>\n<li>Bachelor&#39;s degree in computer science or engineering preferred.</li>\n<li>7 + years&#39; experience working in a technical role with a minimum of 2 + years&#39; experience focusing on information security in the financial industry (preferred).</li>\n<li>Excellent understanding and experience of engineering Microsoft security solutions – including desktop and server operating systems, EntraID, Active Directory, Group Policy, Desired Configuration State, DNS, Messaging.</li>\n<li>Ability to understand code in C#/.NET and / or Python and strong scripting experience in PowerShell.</li>\n<li>Experience managing IaaS, SaaS solutions and services using CI/CD pipelines. Jenkins, Terraform experience is a strong plus.</li>\n<li>Solid understanding of SAML, OIDC and Kerberos authentication and related technology controls and best practices.</li>\n<li>Experience with Office 365 security controls including usage of Azure Active Directory, Conditional Access, o365 logging APIs, Microsoft CAS, and Microsoft Authenticator.</li>\n<li>Understanding and experience with implementing Data Loss Prevention (DLP) solutions, policies, and technologies.</li>\n<li>Understanding of Azure Information Protection (AIP) and its components, including labeling, classification, and encryption.</li>\n<li>Ability to develop and implement strategies to ensure compliance with data protection regulations, such as GDPR or HIPAA, utilizing DLP and AIP solutions.</li>\n<li>Strong knowledge and experience in a variety of security technologies including: EDR, SIEM, Vulnerability Management is a plus.</li>\n<li>Relevant security certification (CISSP, GCIA, CISM, etc.) and/or product certifications (PingFederate, Azure, Windows, AD etc.) a plus.</li>\n</ul>\n<p>The estimated base salary range for this position is $175,000 to $250,000, which is specific to New York and may change in the future. Millennium pays a total compensation package which includes a base salary, discretionary performance bonus, and a comprehensive benefits package.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_80dbb0f6-e54","directApply":true,"hiringOrganization":{"@type":"Organization","name":"IT Infrastructure","sameAs":"https://mlp.eightfold.ai","logo":"https://logos.yubhub.co/mlp.eightfold.ai.png"},"x-apply-url":"https://mlp.eightfold.ai/careers/job/755944784476","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$175,000 to $250,000","x-skills-required":["security technologies","tools","methodologies","Windows security solutions","OIDC / OAUTH 2","SAML","Kerberos authentication","Identity providers","SSO","PKI","EDR","SIEM","Vulnerability Management"],"x-skills-preferred":["C#/.NET","Python","PowerShell","Jenkins","Terraform","Azure Active Directory","Conditional Access","o365 logging APIs","Microsoft CAS","Microsoft Authenticator","Data Loss Prevention (DLP)","Azure Information Protection (AIP)"],"datePosted":"2026-04-18T22:12:55.408Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"New York, New York, United States of America"}},"employmentType":"FULL_TIME","occupationalCategory":"IT","industry":"Finance","skills":"security technologies, tools, methodologies, Windows security solutions, OIDC / OAUTH 2, SAML, Kerberos authentication, Identity providers, SSO, PKI, EDR, SIEM, Vulnerability Management, C#/.NET, Python, PowerShell, Jenkins, Terraform, Azure Active Directory, Conditional Access, o365 logging APIs, Microsoft CAS, Microsoft Authenticator, Data Loss Prevention (DLP), Azure Information Protection (AIP)","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":175000,"maxValue":250000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_68e291fb-412"},"title":"Senior Security Engineer","description":"<p>Talent Wanted. For hazardous journey. Small wages, bitter cold, long months of complete darkness, constant danger, safe return doubtful. Honour and recognition in case of success.</p>\n<p>Fridtjof Nansen crossed the Arctic, going places no human had ever been. Together with our users, we&#39;re doing the same onchain , and someone needs to make sure we don&#39;t get killed on the way there.</p>\n<p>We&#39;re building the single best platform for onchain investing , agentic trading, staking infrastructure, AI-powered analytics , and we&#39;re scaling fast. Fast enough that security can&#39;t be an afterthought bolted on later. It has to be built in, from the start, by someone who knows what they&#39;re doing.</p>\n<p><strong>Our mission:</strong></p>\n<p>Surface the signal and create winners.</p>\n<p><strong>What you&#39;ll do at Nansen</strong></p>\n<p>You&#39;ll be the person who makes sure we can move fast without breaking things that matter. That means embedding security into everything we build , cloud infrastructure, applications, CI/CD pipelines, AI systems, staking operations , across a generalist role that spans the full surface area.</p>\n<ul>\n<li>Run security assessments across systems, architectures, and code , find the vulnerabilities before someone else does</li>\n<li>Advise engineering teams on secure design decisions. You&#39;re a partner, not a blocker</li>\n<li>Deploy and maintain security infrastructure: SIEM, vulnerability scanning, endpoint protection, logging , the things that let us sleep at night</li>\n<li>Secure our CI/CD pipelines and deployment workflows end-to-end</li>\n<li>Own secrets management, key management, and access controls. No shortcuts</li>\n<li>Address LLM security head-on: API key management, prompt injection prevention, and the risks that come with shipping AI-powered products at speed</li>\n<li>Coordinate penetration tests and security audits with external vendors</li>\n<li>Create and maintain secure coding guidelines and code review processes that engineers actually follow</li>\n<li>Represent the Security Team in the incident response process</li>\n<li>Drive compliance readiness , SOC 2, ISO 27001 , pragmatically, not bureaucratically</li>\n</ul>\n<p><strong>What we&#39;re looking for</strong></p>\n<ul>\n<li>You&#39;ve built and hardened production security at scale , you know the difference between a policy document and an actually secure system</li>\n<li>Strong cloud security knowledge (AWS, GCP or equivalent). Container security and network security fundamentals</li>\n<li>Hands-on experience implementing security tooling, not just evaluating it</li>\n<li>Secrets and key management expertise , you&#39;ve managed this at a company where it actually mattered</li>\n<li>You understand the security implications of AI/LLM and agent-based systems. This is new territory and we need someone thinking about it seriously</li>\n<li>CI/CD pipeline security is second nature</li>\n<li>Pragmatic about compliance , you can get us to SOC 2 without drowning the engineering team in process</li>\n<li>You don&#39;t just use AI as a tool. You think with it. AI-first isn&#39;t a checkbox , it&#39;s how you work</li>\n<li>Strong async communication skills , we&#39;re remote-first, Slack-and-docs-heavy, and EMEA hours are preferred for team overlap</li>\n<li>Bonus: blockchain, smart contract, or staking infrastructure security experience. Kubernetes and Terraform security. Incident response or security operations background</li>\n</ul>\n<p><strong>What we offer our crew</strong></p>\n<ul>\n<li>Competitive salary. Meaningful equity. Real ownership in what you build</li>\n<li>Fully remote with two no-meeting days a week , because deep work doesn&#39;t happen in a Google Meet</li>\n<li>Annual company retreat and team off-sites in one of our offices: Singapore, Bangkok, London, and Oslo , flights and accommodation covered</li>\n<li>Unlimited AI tokens , Claude, OpenAI, whatever helps you move fast</li>\n<li>Your own OpenClaw for work</li>\n<li>Nansen Pro account: giving you full access to the most detailed onchain data in the market</li>\n<li>A team that started as data engineers and data scientists that has grown to over 80 builders. Your craft is respected here.</li>\n<li>Speed, ownership, curiosity, courage. These aren&#39;t values on a wall , they&#39;re how we run.</li>\n<li>A front-row seat (and a hand in building) the next chapter of finance</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_68e291fb-412","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Nansen","sameAs":"https://nansen.ai/","logo":"https://logos.yubhub.co/nansen.ai.png"},"x-apply-url":"https://job-boards.greenhouse.io/nansen/jobs/5811520004","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["cloud security","container security","network security","security tooling","secrets management","key management","access controls","API key management","prompt injection prevention","LLM security","CI/CD pipeline security","compliance","SOC 2","ISO 27001"],"x-skills-preferred":["blockchain security","smart contract security","staking infrastructure security","Kubernetes security","Terraform security","incident response","security operations"],"datePosted":"2026-04-17T12:47:56.366Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote Europe | Remote Asia"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"cloud security, container security, network security, security tooling, secrets management, key management, access controls, API key management, prompt injection prevention, LLM security, CI/CD pipeline security, compliance, SOC 2, ISO 27001, blockchain security, smart contract security, staking infrastructure security, Kubernetes security, Terraform security, incident response, security operations"}]}