Engineering Lead — Security
职位要求 / 描述
About Somnia SOMNIA is the Agentic Chain - a hyper-performance L1 operating at an order of magnitude faster than existing networks. We empower builders and traders to create real-time, autonomous, and fully decentralized products, powered by agents, that were previously impossible and cannot be built anywhere else. It’s where the future of Web3 protocols will be built, so we’re facilitating a new wave of on-chain applications from DEX to Prediction Protocols and much, much more. Somnia is being developed by Somnia Foundation backed by Improbable https://www.improbable.io/, a British tech Unicorn +++ that has been at the forefront of building virtual worlds for over a decade. Somnia received initial funding from MSquared https://www.msquared.io/, which raised $150 million https://www.businesswire.com/news/home/20220407005101/en/Improbable-Raises-US150m-to-Establish-M%C2%B2-MSquared-a-Metaverse-Network-and-Ecosystem-Powered-by-Its-Morpheus-Technology from a16z crypto, SoftBank, Mirana Ventures, CMT Digital, and SIG. About the Role: We're looking for an Engineering Lead to own security across Somnia—the infrastructure and operations running the L1, the products and services teams ship on top of it, the policies and processes that govern how we work, and the multisig and key management protecting the protocol's most critical assets. A senior, hands-on role: you help set the security strategy and posture and do the work—hardening infrastructure, defining incident response, securing signing and treasury operations, and raising the bar across the team. You treat security as an enabler of velocity, not a blocker, and use AI as a multiplier. Key Responsibilities: - Work with the other technical leaders to help define the engineering culture and bar. - Own the security posture of the L1 infrastructure—validators, RPC, signing services, supporting systems. Harden hosts, networks, and pipelines; drive vulnerability management, patching, and security monitoring. - Define and roll out the policies and standards that govern the organization—access control, secrets management, secure SDLC, change management, compliance-readiness. Practical enough that engineers actually follow them. - Drive application and supply-chain security for what Somnia ships—secure-by-default patterns, dependency and build-pipeline scanning in CI, and security reviews where the stakes are highest. That includes the agentic workflow itself: the permissions and provenance of agent-authored changes. Product teams own their security day-to-day; you set the bar and pave the road. - Design and operate multisig governance, signing ceremonies, and the key lifecycle (generation, storage, rotation, recovery) for treasury, upgrades, and privileged ops. No single points of failure; everything auditable. - Build and lead the security incident-response capability—detection, triage, containment, blameless postmortems—and run tabletops, from a compromised laptop to a live protocol exploit, so the team is ready before an incident, not during one. - Stay hands-on—threat modeling, security reviews, and red-team exercises—and coordinate external audits and bug bounties to raise the bar company-wide. - Work with the infrastructure and L1 teams so that node and validator operations resist compromise and upgrades ship safely. Requirements: Must Have - Extensive security engineering, with deep infrastructure security and SecOps expertise at scale—and the application-security breadth to raise the bar across product teams. - Hands-on securing and operating production systems—Linux internals, networking, containers/Kubernetes, IaC. - Track record defining and implementing security policies an engineering org actually adopts. - Key management at depth: signing workflows, HSMs, secrets management, key generation/rotation/recovery. - Strong incident response leadership: detection, containment, forensics, postmortems. - Cryptography fundamentals as applied to bloc
技能关键字
职责方向
相似岗位
Security Engineering Intern, GRCCoinhakoSenior Product Security EngineerBlockchain.comSecurity EngineerCoinflowHead of SecurityDefuse Labs数据来自公开渠道整理,薪资为公开 JD 或聚合估算,仅供参考,以面试谈薪为准。 ← 返回链聘 ChainHire 职位看板