Secure Agora’s applications, APIs, cloud infrastructure, Kubernetes workloads, deployment pipelines, and blockchain-related systems. Responsibilities include threat modeling, architecture and code reviews, security tooling administration, detection engineering, monitoring, incident response, vulnerability management, penetration-test coordination, security automation, and cross-functional remediation. The role partners closely with Engineering, Product, Infrastructure, Compliance, Operations, and the SOC to improve controls, telemetry, response readiness, and security risk visibility.
ABOUT AGORA
At Agora, our mission is to transform how money moves. We believe stablecoins will underpin a new financial fabric, one that is faster, more global, and more efficient than today's siloed systems. That is why we are building AUSD and the Agora stack, a full service platform that makes issuing, managing, and integrating stablecoins seamless, whether you're a developer, fintech, or institution. With AUSD, stablecoins become programmable, composable, and ubiquitous by default.
We believe digital dollars should be a public good: trusted, accessible, and built for real-world utility. Our mission is to drive adoption through customizable, user-friendly on-ramps that make stable, dollar-based value available onchain.
We're backed by world-class investors including Paradigm and Dragonfly, and we're growing a team to reimagine how value moves online.
We're intentional about who we bring on. If you're passionate about security and want to help us build a safe environment for people to engage with money, let's talk.
ABOUT THE TEAM
Agora combines the discipline required to operate financial infrastructure with the pace and creativity of a crypto-native startup. We are a small, mission-driven team that values clear thinking, extreme ownership, attention to detail, and high-velocity decision-making.
The Security team works directly with Engineering, Product, Infrastructure, Compliance, and Operations to manage risk without creating unnecessary friction. We operate in short feedback loops and expect security engineers to understand systems deeply, make pragmatic decisions, and help teams ship securely.
JOB SUMMARY
We are looking for a Senior Security Engineer to help secure the products and services Agora builds and operates.
You will be the Security team's primary technical partner to Engineering. You will work alongside engineers from initial design through production operation: building and reviewing controls, architectures, code, infrastructure, and configuration; identifying meaningful risks; and helping teams implement practical solutions.
You will also play a hands-on role in Agora's security monitoring program. You will identify the telemetry and detections needed to protect our systems, implement and tune alert rules, investigate security events, and work closely with our SOC and internal teams during incident response.
This is a broad ownership role. You should be equally comfortable reviewing an API authorization model, reasoning about an AWS or Kubernetes deployment, tuning a security scanner, investigating suspicious production activity, and driving a vulnerability through remediation.
Agora's environment includes TypeScript and Node.js services, React applications, REST APIs, relational databases, Docker, Kubernetes on AWS, Pulumi infrastructure as code, Argo CD and GitOps, Cloudflare, and blockchain infrastructure. You do not need to arrive as an expert in every part of the stack, but you should be able to learn unfamiliar systems quickly and evaluate them from first principles.
We prefer candidates located close to Eastern Time, while welcoming exceptional engineers across Pacific Time through ET+2. Regardless of where you are located, your working hours will need to have a majority overlap with ET business hours.
KEY RESPONSIBILITIES
- Partner with Engineering and Product throughout the development lifecycle, from early design and threat modeling through launch and ongoing operation.
- Perform security reviews of system designs, application code, APIs, infrastructure as code, cloud environments, Kubernetes workloads, deployment pipelines, and production configurations.
- Identify vulnerabilities and design weaknesses, communicate their impact clearly, and work with engineers on pragmatic remediation.
- Serve as a trusted security subject-matter expert for application security, cloud and container security, identity and access management, secrets management, API security, data protection, and secure software development.
- Develop reusable security guidance, secure patterns, review checklists, and engineering standards that make the secure approach easier to adopt.
- Administer and improve Agora's security tooling, including AI-assisted security tools, SAST, DAST, software composition analysis, container and infrastructure-as-code scanning, CSPM, security monitoring, and related capabilities.
- Integrate security controls into developer workflows and CI/CD pipelines; tune rules, reduce noise, improve coverage, and ensure findings lead to action.
- Translate threat models and known attack paths into concrete logging, monitoring, and detection requirements.
- Identify gaps in application, cloud, identity, infrastructure, and blockchain-related security telemetry, then work with engineering teams to address them.
- Design, implement, test, document, and tune security alert rules and detection logic.
- Triage and investigate security detections, correlate activity across relevant data sources, and determine scope, impact, severity, and required response.
- Work closely with Agora's SOC to improve alert quality, escalation criteria, investigation procedures, and response runbooks.
- Participate in security incident response, including investigation, containment, eradication, recovery, stakeholder coordination, and evidence preservation.
- Lead or contribute to post-incident reviews and ensure lessons learned result in durable improvements to architecture, controls, monitoring, and operational processes.
- Own the day-to-day execution of the vulnerability management program, including intake, validation, risk-based prioritization, assignment, remediation tracking, exception management, verification, and reporting.
- Support third-party penetration tests, code reviews, architecture assessments, and other independent security engagements, from scoping and reviewer selection through remediation and closure.
- Assess the security implications of new vendors, technologies, integrations, and architectural changes.
- Build lightweight automation and metrics that improve security visibility, shorten investigation and remediation time, and help leadership understand material risk.
- Contribute to Agora's product security, platform security, detection engineering, vulnerability management, and incident-readiness roadmaps.
BASIC QUALIFICATIONS
- 5+ years of hands-on experience in product security, application security, cloud security or a closely related security engineering role.
- Strong software engineering fundamentals and the ability to review application code. Experience with TypeScript, Node.js, JavaScript, or another modern language is especially relevant.
- Experience reviewing web applications, backend services, REST APIs, authentication and authorization systems, and relational database designs.
- Practical knowledge of common application and API vulnerabilities, threat-modeling techniques, secure design principles, and modern identity patterns.
- Experience securing AWS environments, containerized workloads, Kubernetes, infrastructure as code, and CI/CD or GitOps workflows.
- Hands-on experience implementing or administering security tools such as SAST, DAST, SCA, CSPM, container scanning, secrets detection, infrastructure-as-code scanning, SIEM, or cloud-native detection platforms.
- Experience developing or tuning security detections using application, cloud, identity, network, and infrastructure telemetry.
- Strong investigation skills, including the ability to analyze logs and system activity, develop and test hypotheses, establish timelines, and determine the scope and impact of suspicious behavior.
- Experience working with SOC, including alert escalation, investigation handoffs, runbook development, and detection-quality improvement.
- Experience participating in security incident response and coordinating effectively with engineering and operational teams under time pressure.
- Experience operating a vulnerability management process and driving remediation across multiple engineering teams.
- Ability to evaluate findings and detections based on exploitability, confidence, and business impact rather than relying exclusively on automated severity.
- Experience working with external penetration testers, auditors, or specialist security reviewers.
- Strong written and verbal communication skills, including the ability to explain technical risk and incident status clearly to technical and non-technical stakeholders.
- High autonomy and sound judgment. You can take an ambiguous concern, investigate it deeply, propose a path forward, and close the loop.
- A collaborative, low-ego approach to security. You build trust with engineers while maintaining a high bar for systems protecting financial assets and sensitive data.
PREFERRED QUALIFICATIONS
- Experience securing fintech, payments, digital-assets or other high-assurance financial platforms.
- Familiarity with blockchain systems, smart-contract integrations, transaction flows, custody models, signing infrastructure, or cryptographic key management.
- Experience with TypeScript, Pulumi, AWS, Argo CD, Cloudflare, PostgreSQL, Prometheus, or Grafana.
- Experience with incident-response tooling, security data pipelines, log normalization, detection-as-code, or automated enrichment and response.
- Experience defining operational metrics such as detection coverage, false-positive rate, investigation time, and mean time to contain.
- Experience designing security controls for distributed, event-driven, multi-tenant, or high-availability systems.
- Ability to create security automation, internal tools, or CI/CD integrations using code.
- Experience applying AI-assisted tools to security investigations, detection engineering, or secure development.
- Relevant offensive-security, incident-response and cloud-security experience or certifications.
Agora operates a centralized USD-pegged stablecoin platform with robust compliance, security, and governance. We are equally committed to fostering a diverse, inclusive, and equitable workplace.
We are an Equal Employment Opportunity Employer. We do not discriminate based on race, color, ancestry, national origin, religion or creed, mental or physical disability, medical condition, genetic information, sex (including pregnancy, childbirth, and related conditions), gender identity or expression, sexual orientation, age, marital status, military or veteran status, citizenship, or any other characteristic protected under applicable federal, state, or local law.
Similar Jobs
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
Provides hands-on endpoint, mobile, network, and infrastructure security for executives, remote offices, and sensitive locations. Responsibilities include configuring devices and controls, conducting site security assessments, remediating gaps, troubleshooting security systems, coordinating with Physical Security and vendors, maintaining documentation and runbooks, supporting audits, and responding to urgent after-hours issues. Regular domestic and international travel is required.
Top Skills:
Endpoint SecurityInfrastructure SecurityMobile SecurityNetwork SecurityZero Trust
Artificial Intelligence • Marketing Tech • Software • Generative AI • Automation
Lead security engineering across AI systems, cloud infrastructure, product security, GRC automation, GitHub controls, and compliance workflows. Develop AI-specific threat models and guardrails, automate security checks and evidence collection, strengthen AWS and GCP environments, manage CSPM tooling, and secure software supply chains. Partner with Engineering, Product, Legal, IT, and GRC to establish security programs and practical controls for Jasper’s AI platforms.
Top Skills:
Ai AgentsAPIsAWSCi/CdCnappCspmDrataGCPGitGithub ActionsIamInfrastructure As CodeIso 27001LlmsRagSoc 2Software Composition AnalysisVantaWiz
Real Estate • Sales • Software • PropTech
Design, implement, and maintain security controls across cloud (AWS) and on-prem systems. Lead vulnerability management, incident response, and remediation. Serve as SME for SIEM, SAST/DAST, IAM. Embed security in SDLC, support SOC 2/ISO 27001 audit readiness, mentor junior engineers, and recommend control improvements.
Top Skills:
AgileAWSDastIamIso 27001On-PremSaaSSastSIEMSoc 2Vulnerability Management
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute



