D

Head of Security

Defuse Labs · 钱包/DeFi · 上架 2026-07-27
面议
安全负责人/总监📍 Global - Remote远程

职位要求 / 描述

<p>NEAR is one of the most active ecosystems in crypto, spanning a Layer-1 protocol, a leading cross-chain intents and settlement layer (NEAR Intents), a consumer-facing financial app (<a href="http://near.com">near.com</a>), and a rapidly growing AI stack &amp; agent framework (Ironclaw). It also sits at a turning point on security. Recent industry incidents, the acceleration of AI-enabled attacks, and the emergence of institutional counterparties now requiring a named security owner have made it clear: the ecosystem needs a senior, credible operator to own this function end-to-end.</p> <p>This is that role. You will be Head of Security, with primary ownership of Defuse Labs (NEAR Intents) and NEAR One — the two entities carrying the highest operational risk — and extending coverage to the NEAR Foundation and NEAR AI in partnership with their leadership. </p> <h3><strong>What you'll own</strong></h3> <p>Your objective is to pragmatically manage hard security risks across companies operating complex financial instruments in adversarial cross-chain environments. We care about real practical security first and foremost, not paper-based certifications.</p> <p>You will be protecting against state actors, insider threats, and countless numbers of LLM agents. The scope includes every single chain we integrate. Think defence in depth, but the depth must cover things like <a href="https://x.com/AlexAuroraDev/status/2049551130443895061">13-block reorgs of Litecoin</a> or <a href="https://rekt.news/rhea-finance-rekt">margin trading engine exploits</a> in a partner protocol.</p> <p><strong>End-to-end security posture</strong><strong><br></strong>Define and operate security across NEAR Intents and NEAR One — including identity, cloud (AWS/GCP), endpoints, application security, and SecOps — within a crypto-native model where smart contract risk, on-chain monitoring, key management, and validator/infrastructure security are first-class concerns.</p> <p><strong>Smart contract and protocol security</strong><strong><br></strong>Establish security standards, audit strategy, and release gating for production deployments. Own how code moves from development to mainnet.</p> <p><strong>Incident response</strong><strong><br></strong>Lead ecosystem-wide response across both traditional infrastructure and on-chain events — preparation, detection, containment, and recovery. When incidents happen, you are the point of coordination and decision-making.</p> <p><strong>Key management and asset security</strong><strong><br></strong>Design and oversee key management architecture across protocol, treasury, and operational environments, including MPC, custody models, and access controls.</p> <p><strong>Offensive security</strong><strong><br></strong>Define and run a continuous testing strategy — internal security testing, external audits, red teaming, and bug bounty programs.</p> <p><strong>Team and tooling</strong><strong><br></strong>Build a lean, high-leverage security function from the ground up. Decide where commercial tooling is required and where open-source or in-house approaches are more effective.</p> <p><strong>AI and emerging surfaces</strong><strong><br></strong>Establish security practices for AI and agent-based systems, including model integrity, prompt injection risks, and agent execution boundaries.</p> <h3><strong>Who you are</strong></h3> <ul> <li>A proven security leader from an environment where getting it wrong was not an option — a major on-chain protocol, a top-tier exchange or custodian, critical infrastructure, or a peer ecosystem operating at serious scale. You've built programs, not just maintained them.</li> <li>Deeply technical. You can read a Terraform module, challenge a threat model, and set budget priorities in the same afternoon — and you're comfortable arguing with engineers on the merits.</li> <li>Think from first principles. You understand how ROI on an audit is calculated and how much of the cost is attributable to the au

技能关键字

#Smart Contract#Validator/节点#Terraform#AWS#GCP#AI#安全审计

职责方向

团队管理架构设计故障/值班监控告警性能/容量部署发布

数据来自公开渠道整理,薪资为公开 JD 或聚合估算,仅供参考,以面试谈薪为准。 ← 返回链聘 ChainHire 职位看板

Head of Security · Defuse Labs
面议
立即投递 →