xelys jobs xelys jobs

Member of Technical Staff, Security Operations

Anchorage Digital

midsecuritybackend United States 35 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Security OperationsApplication Security (AppSec)Penetration TestingVulnerability ManagementPythonGoStatic AnalysisCodeQLBurp SuiteAWS Security

About the role

Role Overview

Build and run security automation and Security Operations capabilities to detect vulnerabilities, investigate security events, and drive remediation across the Anchorage platform.

Responsibilities

  • Security automation & tooling: Build and maintain tooling to detect vulnerabilities using static and dynamic analysis across code and live systems.
  • AppSec assessments: Conduct application security assessments, penetration tests, and code reviews; identify high-risk issues and provide secure development guidance.
  • Vulnerability management: Develop and operate vulnerability management workflows, partnering with engineering teams to prioritize and remediate findings.
  • Security guardrails: Establish and test security guardrails for code, cloud resources, and infrastructure components.
  • Security event operations: Monitor and respond to security events and configuration anomalies; lead investigation and containment efforts.
  • Vulnerability lifecycle ownership: Manage the vulnerability lifecycle from discovery → remediation, tracking progress and ensuring timely closure.
  • Independent execution: Lead or meaningfully contribute to Security Operations initiatives with minimal oversight; coordinate across teams to deliver.
  • Risk-based planning: Break security problems into workstreams with accurate scoping and time estimates; present options with clear, well-reasoned priority recommendations.
  • Compliance evidence: Deliver assurance artifacts and evidence to support regulated entity requirements, audits, and compliance.
  • Continuous improvement: Stay alert to emerging threats/vulnerabilities and industry trends; adapt investigation approach based on risk and business impact.

Requirements

  • Security Operations / AppSec experience: 3+ years hands-on in security engineering, application security, penetration testing, or security operations.
  • Security tooling & automation: Built/maintained security tools, integrations, or automation workflows using Python, Go, or similar.
  • Vulnerability assessment: Ability to identify and assess vulnerabilities in applications, APIs, and cloud infrastructure, and communicate remediation strategies.
  • Static & dynamic analysis: Experience with tools like Semgrep, CodeQL, Burp Suite, or equivalents.
  • Cloud security: Strong AWS fundamentals including IAM, VPC, security groups, and CloudTrail/logging.
  • Incident response: Investigate security events, perform root cause analysis, and coordinate response.
  • Computer science fundamentals: Concurrency, algorithms, and data structures.
  • Strong code quality and operational excellence mindset.

Nice to Have / Fit Indicators

  • Security-first approach balancing speed and thoroughness of investigation.
  • Ability to communicate effectively with both technical and non-technical audiences; documentation/runbooks and post-incident reviews.

About Anchorage Digital

Anchorage Digital is a U.S.-based security-focused technology company providing platforms and services related to digital asset infrastructure. The role centers on Security Operations and application security, partnering with engineering, infrastructure, and compliance to protect the Anchorage platform.

Scraped 6/23/2026