About Onramp
Onramp is building the money platform of the future for individuals, businesses, and financial institutions: Bitcoin, dollars, and stablecoins in one place, secured by multi-institution custody and delivered through products people love and APIs institutions build on. We are a FinCEN-registered Money Services Business, SOC 2 Type I compliant with the Type II observation period underway, and work directly with banks, custodians, and financial institutions. Security is not a department here. It is the product.
The Role
You'll be the day-to-day owner of Onramp's security roadmap, reporting to our Engineering Lead and partnering with our CCO, who owns SOC 2 and compliance. We already run a layered program mapped to our SOC 2 controls; your job is to take it further and keep it ahead of the threat landscape. About two-thirds of your time is security, the rest is product engineering on the same team. On any given week, you might:
- Advance our controls across identity, endpoint, network, email, and browser layers, and handle the change management that gets a small team to adopt them
- Lead incident response: triage, run the response, coordinate with custody partners when needed, and turn every event into a stronger playbook
- Build AI-driven offensive testing: continuous, agent-assisted pen testing and attack simulation that complements our manual program and feeds findings straight to engineering
- Harden the developer pipeline and cloud posture across GitHub, GCP, and Vercel: supply chain scanning, secrets management, IAM least-privilege, required checks on auth, withdrawal, and KYC paths
- Extend custody-specific monitoring and runbooks: fee wallet controls, signing and quorum alerting, address verification
- Refine the verification SOPs sales and ops use against deepfakes, synthetic identity, impersonation, and coerced withdrawals, and train the team on them
- Run access reviews, service account inventory, vendor risk reviews, and SOC 2 evidence as part of the work rather than after it
- Govern our AI-native toolchain with a lightweight pre-adoption review for new connectors and agents
- Ship product code in our TypeScript/Next.js and Elixir/Phoenix services
Who You Are
- 4+ years hands-on security engineering, ideally at an early- or growth-stage fintech, custody, or exchange, where you owned the controls, not just the findings
- You've run incident response end to end and written the post-incident review
- Offensive-minded, with pen testing experience and real interest in making it continuous with AI agents
- A working software engineer on at least one side of a modern stack (React/Next.js and TypeScript, or Elixir/Phoenix, Node, or comparable)
- Deep on identity, endpoint, and cloud security in a Google Workspace, GitHub, GCP, and Vercel environment, and opinionated about right-sizing tooling for a small team
- Fluent in today's threats: AI-driven supply chain attacks, session theft, OAuth phishing, deepfake social engineering
- SOC 2 in practice: you know what an auditor asks for and build evidence into the workflow
- Insanely AI-native, with strong views on securing agents without adding friction
- A clear writer of runbooks, threat models, and async updates people actually read
- Calm in an incident, direct in a review, comfortable with early-stage ambiguity and pace
- You don't need bitcoin protocol experience to apply. You do need to be curious about it and willing to go deep on custody fast.
Nice to Have
Bitcoin custody experience (multisig, PSBT, key-agent architectures), Elixir/Phoenix, agentic security tooling, GCP Security Command Center or Wiz, Terraform, OSCP or equivalent, CTFs or public disclosures.
Why This Role, Why Now
- Ownership: the program, standards, and tooling are yours to drive as we scale
- Stakes: we custody bitcoin for HNW clients, RIAs, and institutions. Withdrawals are irreversible
- The AI moment: budget and mandate to push AI-native security on both the defensive and offensive side
- Range: security engineer and product engineer in one seat, on a small team where you see the whole system
How We Work
Remote-first (US), high-trust, low-ceremony. Small pods, direct communication, written culture, biweekly all-hands with live AI demos. We care about output, not hours.
This role starts as a remote contract with a clear path to full-time and equity once fit is confirmed on both sides.
The Process
Intro call, technical conversation with the Engineering Lead and CCO, a working session (bring your AI toolkit), founder conversation, offer.
What We Offer
- High agency and first-principles thinkers
- Flat structure, builder-first execution culture
- Mission-driven: Bitcoin only, no altcoins
- Collaborative, transparent, and low-ego
- Competitive compensation, with meaningful equity on conversion to full-time
How to Apply
Send your resume and a short intro video to hiring@onrampbitcoin.com covering:
- A security control or program you owned end to end and how you got a team to adopt it
- An incident you helped run and what changed because of it
- One AI-leveraged workflow you've built or wished you had
- Why Onramp
Email subject: Application — Security Engineer