Jito Labs Logo

Jito Labs

Senior Security Engineer

Posted 4 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
180K-200K Annually
Senior level
Remote
Hiring Remotely in United States
180K-200K Annually
Senior level
Owns broad product and operational security responsibilities, including identity and access management, threat modeling, code review, fuzzing, bug bounty operations, AI security research, software supply chain monitoring, penetration test coordination, and compliance evidence. The role requires a strong software engineering background, product security expertise, security tooling development, systems programming experience, and familiarity with web3 or DeFi. It is remote-first and emphasizes autonomy, documentation, and high ownership.
The summary above was generated by AI
About Jito


Jito builds the market layer of Solana: the execution, capital, and incentive infrastructure behind the network's onchain economy. That includes the validator client running the majority of Solana stake, BAM (a new framework for verifiable ordering, pre-execution privacy, and programmable blockspace), JitoSOL (the leading liquid staking token on Solana), and JTX (trading built directly on our own market infrastructure).
We are a lean, high-density team. Everyone here owns real surface area, works in the open, and ships at pace. The engineers on this team are the people market makers call when milliseconds matter.

About the Role
We're growing our security team and looking for an engineer who can own a broad operational and technical scope: someone equally at home triaging an access request, running a security review, or building a custom testing framework. You'll report directly to the Head of Security, working closely to strengthen and scale our security posture across the organization.
What You'll Do
• Identity and access management: provisioning, lifecycle operations, and monitoring for critical changes
• Security reviews across our product portfolio: threat modeling, code review, fuzzing, and functional testing
• Day-to-day bug bounty operations: triage, remediation tracking, and escalation of high-severity findings
• AI security research and tooling: adversarial testing frameworks for agent controls, with a focus on reusable patterns
• Software supply chain monitoring: malicious package detection beyond standard CVE scanning
• External penetration test coordination: scoping, logistics, and post-engagement remediation tracking
• Compliance documentation and evidence gathering as requirements emerge
What We're Looking For
• A software engineering background is essential: you've built production systems, and that foundation shapes how you approach security
• You've since moved into product security and are fluent in the full lifecycle: threat modeling, secure design review, whitebox code review, and vulnerability testing • 5+ years of professional experience, with a meaningful portion in software engineering before transitioning into security
• Proficiency in at least one systems or backend language (Rust preferred; Go, C++, or Python also work). You will write code, build tooling, and read production codebases as a routine part of this role.
• Demonstrated experience in product or application security, not solely infrastructure- or compliance-focused roles
• Track record of building security tooling or automation from scratch
• Experience conducting or leading security reviews on production software systems
• Solid understanding of identity and access management concepts and tooling
• Genuine interest in AI security with the ability to build adversarial testing tooling
• A thoughtful approach to software supply chain risk beyond checkbox scanning
• Strong written communication: documentation is a real part of this job
• Comfortable with high ownership and working autonomously on a small team
• Experience in web3, crypto, or DeFi
• Bachelor's degree in Computer Science, Computer Engineering, or a related technical field
Nice to Have
• Hands-on experience with mobile device management (MDM) platforms and endpoint policy enforcement
• Familiarity with enterprise IAM systems and SSO: configuration, integration, and audit
• Experience with privileged access management (PAM) tooling and the operational patterns around it
• Strong Linux administration skills: comfortable at the command line, understanding of kernel-level security primitives, experience hardening Linux environments
• Experience with multisig schemes: signing policy design, quorum configuration, or key management in a production context
• Familiarity with hardware security modules (HSMs): integration, key lifecycle management, or operational use
• Exposure to trusted execution environments (TEEs): attestation, confidential compute, or secure enclave design

How we work


Remote-first, writing-heavy, and transparent by default: most decisions happen in public Slack channels, and everyone's voice carries. We value ownership, humility, curiosity, and getting it done over getting it perfect. Small egos, high standards.


What we offer


Competitive compensation including salary and token incentives, the tools you need to do your best work, and a seat at the center of Solana's market infrastructure alongside some of the strongest engineers in the ecosystem.
Jito is an equal opportunity employer. We evaluate candidates on the basis of their skills, experience, and potential contribution, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by law.

 

Similar Jobs

2 Days Ago
Easy Apply
Remote
USA
Easy Apply
209K-250K Annually
Senior level
209K-250K Annually
Senior level
Big Data • Healthtech • HR Tech • Machine Learning • Software • Telehealth • Big Data Analytics
The Senior Security Engineer will secure networks, systems, applications, databases, and cloud infrastructure; embed security controls into build pipelines; manage vulnerabilities and remediation; respond to incidents through on-call rotation; and promote security awareness across engineering. The role requires cloud security, infrastructure-as-code, application security, REST API protection, IAM, and tools including AWS, Kubernetes, Terraform, Wiz, Exaforce, and CrowdStrike.
Top Skills: AWSAws IamCrowdstrikeDastExaforceInfrastructure As CodeKubernetesPythonRestful ApisSastTerraformWiz
6 Days Ago
In-Office or Remote
Senior level
Senior level
Fintech • Hardware • Payments
Monitors and investigates security alerts across SIEM, endpoint, identity, cloud, email, and network environments. Conducts threat hunting, incident response, containment, remediation, vulnerability management, and post-incident reviews. Develops playbooks, automation, integrations, detections, and infrastructure-as-code deployments. Uses and tunes agentic SOC tooling while maintaining human oversight. Coordinates with technical and business teams, participates in a 24/7 on-call rotation, mentors junior engineers, and improves security operations through metrics and continuous improvement.
Top Skills: Agentic AiAPIsAWSAzureCisa KevCloudFormationCvssDlpEdr/XdrEpssFirewallsLlmsMitre Att&CkPowershellPythonSase/SseSecure Email GatewaysSIEMSoarSplunk Enterprise SecurityTerraform
9 Days Ago
Remote
USA
165K-220K Annually
Senior level
165K-220K Annually
Senior level
Cloud • Information Technology • Machine Learning
Lead enterprise eDiscovery and insider-risk investigations by collecting, preserving, analyzing, and reviewing data from cloud infrastructure, endpoints, and repositories. Build AI-powered automation, correlate activity logs into investigative timelines, manage legal holds and governance policies, support digital forensics, and produce structured evidence packages for Security, Legal, HR, and investigative teams.
Top Skills: Ai AutomationCloud Audit LogsData Classification And Labeling TechnologiesDigital Forensics SoftwareEdiscovery PlatformsEs/QlGoPythonSIEMSQL

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account