Nansen
Staff Security Engineer
Job Summary
The role of Staff Security Engineer at Nansen involves ensuring the security of blockchain applications, cloud infrastructure, and data platforms. Key responsibilities include implementing security standards, managing encryption and key processes, and conducting vulnerability assessments and security audits. The candidate will lead incident response efforts and collaborate with external providers on security testing. A strong focus on defensive security, blockchain security, and security documentation is essential for this position.
Required Skills
Benefits
Job Description
Nansen is a leading blockchain analytics platform that empowers investors and professionals with real-time, actionable insights derived from on-chain data.
Role Overview
As a Staff Security Engineer, you will be responsible for ensuring the secure operation of our user-facing application and cloud infrastructure. Initially, you will concentrate on security for our staking offering, including key management, infrastructure hardening, and compliance readiness. Over time, your responsibilities will expand to cover the full application and data analytics platform. In addition to hands-on implementation, you will play a key role in shaping the organization's long-term security vision. Your primary focus will be on defensive security, and you will collaborate closely with DevOps, SREs, and other engineering teams to maintain and continuously improve our security posture.
You can be located anywhere in Europe or Asia, as our work is 100% online. The position is full-time.
Responsibilities
- Infrastructure and network security
- Take ownership of and actively implement baseline cloud, container, and application security standards, ensuring they are integrated into our stack, including regular use of vulnerability scanning tools.
- Harden bare-metal servers and deploy security tooling (e.g., AV/EDR, IDS/IPS, DLP, Logging & Monitoring), taking a hands-on role in the setup and maintenance.
- Collaborate with external providers to plan and oversee penetration tests, ensuring identified vulnerabilities are prioritized and addressed.
- Blockchain security
- Actively improve key management processes, focusing on protecting high-risk blockchain keys with Hardware Security Modules (HSMs) or equivalent solutions.
- Proactively monitor and assess blockchain-exposed surfaces, personally reviewing internal and external endpoints for exploitable vulnerabilities.
- Collaborate with external providers to plan and oversee security audits and reviews of smart contracts and blockchain components, ensuring actionable improvements are identified and addressed.
- Compliance
- Collaborate with teams to maintain clear, up-to-date security documentation, including reference architectures and operational procedures.
- Personally implement security architecture, methods, and controls required to meet compliance and audit requirements, ensuring execution is prioritized.
- Incident response
- Lead the investigation, containment, and resolution of security incidents, taking a proactive, hands-on approach.
- Conduct detailed postmortems to identify root causes and establish preventive measures.
Requirements
- Deep familiarity with key management best practices and encryption fundamentals.
- Strong understanding of defensive security tools and methodologies, including their practical application in dynamic environments.
- Proven experience implementing and maintaining security systems, such as SIEM, endpoint protection, network detection, vulnerability scanning, and cloud security tooling.
- Understanding of blockchain security, including securing blockchain systems, assessing smart contracts, and implementing robust key management processes.
- Familiarity with vulnerability scanning tools, penetration testing and code audit processes.
- Excellent communication and technical documentation skills.
- Familiarity with compliance frameworks and certification processes is a plus.
- Have an AI-first mindset. At Nansen, AI is not just a tool - it's a mindset. Ideal candidates are those who enthusiastically embrace AI tools and techniques to streamline processes and elevate outcomes.
What We Offer
- Competitive salary and generous equity.
- Remote work environment with a flexible schedule.
- A team that values learning and is willing to test and adopt innovative solutions (including AI)
- A company culture that values speed, ownership, curiosity, simplicity, transparency and courage.
- Opportunities for personal and professional growth as the company scales
- Exposure to a global network of industry experts, partners and influencers.
Nansen
Nansen is the leading onchain analytics platform trusted by the top crypto teams and investors. Gain insights from 20+ chains and over 300m labeled addresses.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.