[Remote] Member of Technical Staff, Security Operations
Note: The job is a remote job and is open to candidates in USA. Anchorage Digital is a regulated crypto platform providing integrated financial services and infrastructure solutions. The Member of Technical Staff in Security Operations will develop and maintain security automation and tooling, manage vulnerabilities, and collaborate with engineering teams to ensure a secure environment across the platform.ResponsibilitiesBuild and maintain security automation and tooling to detect vulnerabilities through static and dynamic analysis across code and live systemsConduct application security assessments, penetration tests, and code reviews to identify high-risk security issues and provide secure development guidanceDevelop and operate vulnerability management workflows, partnering with engineering teams to prioritize and remediate findingsEstablish and test security guardrails for code, cloud resources, and infrastructure components throughout the Anchorage platformMonitor and respond to security events and configuration anomalies across the organization, leading investigation and containment effortsManage the full vulnerability lifecycle from discovery through remediation, tracking progress and ensuring timely closure of findingsLead or substantially contribute to Security Operations initiatives with minimal oversight, coordinating across team boundaries to drive projects to completionBreak complex security problems into manageable workstreams with accurate scope and time estimates. Present options clearly and provide well-reasoned priority recommendationsDeliver assurance artifacts and evidence for regulated entity requirements, supporting audit and compliance effortsBalance speed of response with thoroughness of investigation, adapting approach based on risk and business impactUnderstand and help implement the company's security strategy by participating in planning and defining Security Operations goals in alignment with Anchorage Digital's overall objectivesStay alert to emerging threats, vulnerabilities, and industry trends that could affect organizational security postureConsider security holistically across the product ecosystemâapplications, infrastructure, and third-party integrationsâwhile fostering a security-first cultureCollaborate cross-functionally with Engineering, Infrastructure, and Compliance teams to embed security into development and operational processesShare knowledge broadly across the team through documentation, runbooks, and post-incident reviews, preventing single points of failurePartner with engineering teams to explain security risks and remediation approaches, translating technical findings into actionable guidanceCollaborate across teams to review security configurations, triage findings, and engage in technical discussions. Communicate insights and recommendations clearly to improve processesDemonstrate empathy by understanding others' context, priorities, and constraintsâadapting communication style to maximize effectiveness with both technical and non-technical audiencesSkillsYou have 3+ years of hands-on experience in security engineering, application security, penetration testing, or security operationsYou have built or maintained security tools, integrations, or automation workflows using Python, Go, or similar languagesYou can identify and assess security vulnerabilities in applications, APIs, and cloud infrastructure, and effectively communicate remediation strategiesYou have experience with tools like Semgrep, CodeQL, Burp Suite, or equivalent for identifying security issues in code and running systemsYou understand AWS security fundamentals including IAM, VPCs, security groups, and CloudTrail/loggingYou can investigate security events, perform root cause analysis, and coordinate response effortsYou have developed 'computer science fundamentals,' i.e. concurrency, algorithms, and data structuresYou genuinely care about code quality and operational excellenceYou prioritize security outcomes, end-user experience, and business value over 'cool tech.'You self-describe as some combination of the following: creative, humble, ambitious, detail-oriented, hardworking, trustworthy, eager to learn, methodical, action-oriented, and tenaciousYou have experience running or participating in bug bounty programs (HackerOne, Bugcrowd, etc.)You have worked in a regulated financial services, fintech, or crypto environmentYou have exposure to blockchain security, smart contract auditing, or Web3 technologiesYou have built or contributed to open-source security toolsYou hold relevant certifications (OSCP, GWAPT, GCIH, AWS Security Specialty, etc.)You read blockchain protocol white papers for fun, and stay up to date with the proliferation of crypto-asset innovationsYou were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial systemCompany OverviewAnchorage Digital is a regulated crypto platform that provides institutions with integrated financial services and infrastructure solutions. It was founded in 2017, and is headquartered in San Francisco, California, USA, with a workforce of 501-1000 employees. Its website is https://www.anchorage.com.Company H1B SponsorshipAnchorage Digital has a track record of offering H1B sponsorships, with 6 in 2026, 16 in 2025, 7 in 2024, 1 in 2023, 9 in 2022, 2 in 2020. Please note that this does not guarantee sponsorship for this specific role.