AppSec Engineer
Digital Asset builds the technologies that are reshaping the foundations of financial markets. Our mission is to create the world’s most trusted, privacy-enabled, and interoperable digital infrastructure for global finance. At the heart of this mission is the Canton Network—the blockchain purpose-built for institutional finance. Uniquely combining privacy, compliance, and scalability, Canton enables real-time, secure settlement across multiple asset classes. Governed by the Canton Foundation with participation from leading financial institutions, it is the proven link between the promise of blockchain and the power of global finance. Founded in 2014 and headquartered in New York City, with offices in London, Zurich, Budapest, Hong Kong, and Sydney, we are on a mission to transform finance—and that transformation is now playing out rapidly on the Canton Network.
About The Role
Digital Asset enables mission-critical workflows in the financial industry through development using Daml and runs on the Canton ledger and the Canton Network. The security team supports this mission by providing infrastructure and application security guidance and tooling for DA products and services.
Responsibilities
- Participate in and, in some cases, lead security incident response efforts, including initial containment, investigation, forensic analysis, and post-incident reporting.
- Contribute to the secure design and architecture of new and existing systems, ensuring security is integrated from the start (Security by Design).
- Participate in fostering a DevSecOps culture in the company.
- Collaborate with other teams to facilitate adoption of security processes and tooling.
- Perform vulnerability assessments, run penetration tests, interpret results, and prioritize remediation efforts.
- Apply threat modeling and threat intelligence to enhance security posture.
Requirements
- Vulnerability & Threat Management: Proven ability to perform vulnerability assessments and run penetration tests, interpret the results, and prioritize remediation efforts. Experience with threat modeling and threat intelligence is also key.
- Cloud Security: Working knowledge of securing Google Cloud (and AWS, Azure). This includes identity and access management (IAM), GKE, Cloud Armor, logging, and data protection in the cloud.
- Scripting and Automation: Proficiency in scripting languages (e.g., Python, GoLang, or Bash) to automate security tasks, analyze logs, and develop custom tools.
- Kubernetes and Container Hardening: Expertise in securing GKE cluster components, including leveraging native features like Pod Security Standards (PSS) enforcement, Network Policies to control Pod-to-Pod traffic, and runtime security observability.
- AppSec Security: Integrating security checks (SAST/DAST, dependency scanning, SCA) into CI/CD pipelines, and hardening build infrastructure and workflows.
- Strong oral and written communication skills, ideally experience writing technical documentation and specifications.
- Some experience with cryptographic keys, KMS, HSMs.
- 3-7 years of experience in IT and application security.
- Bachelor’s Degree in Cyber Security, Computer Science, or related field.
- Based in the NY/NJ/CT tri-state area.
Pay
Base salaries are determined during our interview process, during which we assess the candidate's experience, skills, and capabilities against internal peers and the scope and responsibilities of the position. The range below may vary if based outside the New York tri-state area (New York, New Jersey, and Connecticut).
$220,000 - $250,000 USD
Benefits
We offer a comprehensive benefits package designed to support the well-being of our team members. Health and insurance benefits vary by region to ensure local relevance and compliance, and may include medical, dental, and vision coverage. We support our people at every stage of life with family-forward benefits and flexible working models designed to help you do your best work.