About this opportunity
Onramp Bitcoin lists this Security Engineer opportunity in northern, Kentucky. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Onramp is building the money platform of the future for individuals, businesses, and financial institutions: Bitcoin, dollars, and stablecoins in one place, secured by multi-institution custody and delivered through products people love and APIs institutions build on. We are a FinCEN-registered Money Services Business, SOC 2 Type I compliant with the Type II observation period underway, and work directly with banks, custodians, and financial institutions. Security is not a department here. It is the product.
The Role
You'll be the day-to-day owner of Onramp's security roadmap, reporting to our Engineering Lead and partnering with our CCO, who owns SOC 2 and compliance. We already run a layered program mapped to our SOC 2 controls; your job is to take it further and keep it ahead of the threat landscape. About two-thirds of your time is security, the rest is product engineering on the same team. On any given week, you might:
Lead incident response: triage, run the response, coordinate with custody partners when needed, and turn every event into a stronger playbook
Build AI-driven offensive testing: continuous, agent-assisted pen testing and attack simulation that complements our manual program and feeds findings straight to engineering
Harden the developer pipeline and cloud posture across GitHub, GCP, and Vercel: supply chain scanning, secrets management, IAM least-privilege, required checks on auth, withdrawal, and KYC paths
Extend custody-specific monitoring and runbooks: fee wallet controls, signing and quorum alerting, address verification
Refine the verification SOPs sales and ops use against deepfakes, synthetic identity, impersonation, and coerced withdrawals, and train the team on them
Run access reviews, service account inventory, vendor risk reviews, and SOC 2 evidence as part of the work rather than after it
Govern our AI-native toolchain with a lightweight pre-adoption review for new connectors and agents
Ship product code in our TypeScript/Next.js and Elixir/Phoenix services
Who You Are
4+ years hands-on security engineering, ideally at an early- or growth-stage fintech, custody, or exchange, where you owned the controls, not just the findings
You've run incident response end to end and written the post-incident review
Offensive-minded, with pen testing experience and real interest in making it continuous with AI agents
A working software engineer on at least one side of a modern stack (React/Next.js and TypeScript, or Elixir/Phoenix, Node, or comparable)
Deep on identity, endpoint, and cloud security in a Google Workspace, GitHub, GCP, and Vercel environment, and opinionated about right-sizing tooling for a small team
Fluent in today's threats: AI-driven supply chain attacks, session theft, OAuth phishing, deepfake social engineering
SOC 2 in practice: you know what an auditor asks for and build evidence into the workflow
Insanely AI-native, with strong views on securing agents without adding friction
A clear writer of runbooks, threat models, and async updates people actually read
Calm in an incident, direct in a review, comfortable with early-stage ambiguity and pace
You don't need bitcoin protocol experience to apply. You do need to be curious about it and willing to go deep on custody fast.
Nice to Have
Bitcoin custody experience (multisig, PSBT, key-agent architectures), Elixir/Phoenix, agentic security tooling, GCP Security Command Center or Wiz, Terraform, OSCP or equivalent, CTFs or public disclosures.
Why This Role, Why Now
Ownership: the program, standards, and tooling are yours to drive as we scale
Stakes: we custody bitcoin for HNW clients, RIAs, and institutions. Withdrawals are irreversible
The AI moment: budget and mandate to push AI-native security on both the defensive and offensive side
Range: security engineer and product engineer in one seat, on a small team where you see the whole system
How We Work
Remote-first (US), high-trust, low-ceremony. Small pods, direct communication, written culture, biweekly all-hands with live AI demos. We care about output, not hours.
This role starts as a remote contract with a clear path to full-time and equity once fit is confirmed on both sides.
The Process
Intro call, technical conversation with the Engineering Lead and CCO, a working session (bring your AI toolkit), founder conversation, offer.
What We Offer
High agency and first-principles thinkers
Collaborative, transparent, and low-ego
Competitive compensation, with meaningful equity on conversion to full-time
#J-18808-Ljbffr
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.