- Partner with Engineering and Product throughout the development lifecycle, from early design and threat modeling through launch and ongoing operation.
- Perform security reviews of system designs, application code, APIs, infrastructure as code, cloud environments, Kubernetes workloads, deployment pipelines, and production configurations.
- Identify vulnerabilities and design weaknesses, communicate their impact clearly, and work with engineers on pragmatic remediation.
- Serve as a trusted security subject-matter expert for application security, cloud and container security, identity and access management, secrets management, API security, data protection, and secure software development.
- Develop reusable security guidance, secure patterns, review checklists, and engineering standards that make the secure approach easier to adopt.
- Administer and improve Agora's security tooling, including AI-assisted security tools, SAST, DAST, software composition analysis, container and infrastructure-as-code scanning, CSPM, security monitoring, and related capabilities.
- Integrate security controls into developer workflows and CI/CD pipelines; tune rules, reduce noise, improve coverage, and ensure findings lead to action.
- Translate threat models and known attack paths into concrete logging, monitoring, and detection requirements.
- Identify gaps in application, cloud, identity, infrastructure, and blockchain-related security telemetry, then work with engineering teams to address them.
- Design, implement, test, document, and tune security alert rules and detection logic.
- Triage and investigate security detections, correlate activity across relevant data sources, and determine scope, impact, severity, and required response.
- Work closely with Agora's SOC to improve alert quality, escalation criteria, investigation procedures, and response runbooks.
- Participate in security incident response, including investigation, containment, eradication, recovery, stakeholder coordination, and evidence preservation.
- Lead or contribute to post-incident reviews and ensure lessons learned result in durable improvements to architecture, controls, monitoring, and operational processes.
- Own the day-to-day execution of the vulnerability management program, including intake, validation, risk-based prioritization, assignment, remediation tracking, exception management, verification, and reporting.
- Support third-party penetration tests, code reviews, architecture assessments, and other independent security engagements, from scoping and reviewer selection through remediation and closure.
- Assess the security implications of new vendors, technologies, integrations, and architectural changes.
- Build lightweight automation and metrics that improve security visibility, shorten investigation and remediation time, and help leadership understand material risk.
- Contribute to Agora's product security, platform security, detection engineering, vulnerability management, and incident-readiness roadmaps.
- 5+ years of hands-on experience in product security, application security, cloud security or a closely related security engineering role.
- Strong software engineering fundamentals and the ability to review application code. Experience with TypeScript, Node.js, JavaScript, or another modern language is especially relevant.
- Experience reviewing web applications, backend services, REST APIs, authentication and authorization systems, and relational database designs.
- Practical knowledge of common application and API vulnerabilities, threat-modeling techniques, secure design principles, and modern identity patterns.
- Experience securing AWS environments, containerized workloads, Kubernetes, infrastructure as code, and CI/CD or GitOps workflows.
- Hands-on experience implementing or administering security tools such as SAST, DAST, SCA, CSPM, container scanning, secrets detection, infrastructure-as-code scanning, SIEM, or cloud-native detection platforms.
- Experience developing or tuning security detections using application, cloud, identity, network, and infrastructure telemetry.
- Strong investigation skills, including the ability to analyze logs and system activity, develop and test hypotheses, establish timelines, and determine the scope and impact of suspicious behavior.
- Experience working with SOC, including alert escalation, investigation handoffs, runbook development, and detection-quality improvement.
- Experience participating in security incident response and coordinating effectively with engineering and operational teams under time pressure.
- Experience operating a vulnerability management process and driving remediation across multiple engineering teams.
- Ability to evaluate findings and detections based on exploitability, confidence, and business impact rather than relying exclusively on automated severity.
- Experience working with external penetration testers, auditors, or specialist security reviewers.
- Strong written and verbal communication skills, including the ability to explain technical risk and incident status clearly to technical and non-technical stakeholders.
- High autonomy and sound judgment. You can take an ambiguous concern, investigate it deeply, propose a path forward, and close the loop.
- A collaborative, low-ego approach to security. You build trust with engineers while maintaining a high bar for systems protecting financial assets and sensitive data.
- Experience securing fintech, payments, digital-assets or other high-assurance financial platforms.
- Familiarity with blockchain systems, smart-contract integrations, transaction flows, custody models, signing infrastructure, or cryptographic key management.
- Experience with TypeScript, Pulumi, AWS, Argo CD, Cloudflare, PostgreSQL, Prometheus, or Grafana.
- Experience with incident-response tooling, security data pipelines, log normalization, detection-as-code, or automated enrichment and response.
- Experience defining operational metrics such as detection coverage, false-positive rate, investigation time, and mean time to contain.
- Experience designing security controls for distributed, event-driven, multi-tenant, or high-availability systems.
- Ability to create security automation, internal tools, or CI/CD integrations using code.
- Experience applying AI-assisted tools to security investigations, detection engineering, or secure development.
- Relevant offensive-security, incident-response and cloud-security experience or certifications.
Skills Required
- 5+ years of hands-on experience in product security, application security, cloud security, or a closely related security engineering role
- Strong software engineering fundamentals and ability to review application code
- Experience with TypeScript, Node.js, JavaScript, or another modern programming language
- Experience reviewing web applications, backend services, REST APIs, authentication and authorization systems, and relational database designs
- Knowledge of application and API vulnerabilities, threat modeling, secure design principles, and modern identity patterns
- Experience securing AWS environments, containerized workloads, Kubernetes, infrastructure as code, and CI/CD or GitOps workflows
- Experience implementing or administering SAST, DAST, SCA, CSPM, container scanning, secrets detection, infrastructure-as-code scanning, SIEM, or cloud-native detection tools
- Experience developing or tuning security detections using application, cloud, identity, network, and infrastructure telemetry
- Strong investigation skills, including log analysis, hypothesis testing, timeline development, and scope and impact assessment
- Experience working with a SOC on alert escalation, investigation handoffs, runbooks, and detection-quality improvement
- Experience participating in security incident response and coordinating with engineering and operational teams under time pressure
- Experience operating a vulnerability management process and driving remediation across multiple engineering teams
- Ability to assess findings based on exploitability, confidence, and business impact
- Experience working with external penetration testers, auditors, or specialist security reviewers
- Strong written and verbal communication skills
- High autonomy, sound judgment, and ability to investigate ambiguous security concerns through resolution
- Collaborative, low-ego approach to security
- Experience securing fintech, payments, digital-assets, or other high-assurance financial platforms
- Familiarity with blockchain systems, smart-contract integrations, transaction flows, custody models, signing infrastructure, or cryptographic key management
- Experience with TypeScript, Pulumi, AWS, Argo CD, Cloudflare, PostgreSQL, Prometheus, or Grafana
- Experience with incident-response tooling, security data pipelines, log normalization, detection-as-code, or automated enrichment and response
- Experience defining security operational metrics
- Experience designing controls for distributed, event-driven, multi-tenant, or high-availability systems
- Ability to create security automation, internal tools, or CI/CD integrations using code
- Experience applying AI-assisted tools to security investigations, detection engineering, or secure development
- Relevant offensive-security, incident-response, or cloud-security experience or certifications
What We Do
At Agora, our mission is to transform how money moves. We believe stablecoins will underpin a new financial fabric, one that is faster, more global, and more efficient than today’s siloed systems. That is why we are building AUSD and the Agora stack, a full service platform that makes issuing, managing, and integrating stablecoins seamless – whether you’re a developer, fintech, or institution. With AUSD, stablecoins become programmable, composable, and ubiquitous by default. We’re backed by world-class investors including Paradigm and Dragonfly, and we’re growing a team to reimagine how value moves online. We're intentional about who we bring on. If you’re passionate about stablecoins and want to help create more open, intuitive ways for people to engage with money, let’s talk. jobs.gem.com/agora









