Agora - Senior Security Engineer
silver
Job Score
100 ptsABOUT AGORA
At Agora, our mission is to transform how money moves. We believe stablecoins will underpin a new financial fabric, one that is faster, more global, and more efficient than today's siloed systems. That is why we are building AUSD and the Agora stack, a full service platform that makes issuing, managing, and integrating stablecoins seamless, whether you're a developer, fintech, or institution. With AUSD, stablecoins become programmable, composable, and ubiquitous by default.
We believe digital dollars should be a public good: trusted, accessible, and built for real-world utility. Our mission is to drive adoption through customizable, user-friendly on-ramps that make stable, dollar-based value available onchain.
We're backed by world-class investors including Paradigm and Dragonfly, and we're growing a team to reimagine how value moves online.
We're intentional about who we bring on. If you're passionate about security and want to help us build a safe environment for people to engage with money, let's talk.
ABOUT THE TEAM
Agora combines the discipline required to operate financial infrastructure with the pace and creativity of a crypto-native startup. We are a small, mission-driven team that values clear thinking, extreme ownership, attention to detail, and high-velocity decision-making.
The Security team works directly with Engineering, Product, Infrastructure, Compliance, and Operations to manage risk without creating unnecessary friction. We operate in short feedback loops and expect security engineers to understand systems deeply, make pragmatic decisions, and help teams ship securely.
JOB SUMMARY
We are looking for a Senior Security Engineer to help secure the products and services Agora builds and operates.
You will be the Security team's primary technical partner to Engineering. You will work alongside engineers from initial design through production operation: building and reviewing controls, architectures, code, infrastructure, and configuration; identifying meaningful risks; and helping teams implement practical solutions.
You will also play a hands-on role in Agora's security monitoring program. You will identify the telemetry and detections needed to protect our systems, implement and tune alert rules, investigate security events, and work closely with our SOC and internal teams during incident response.
This is a broad ownership role. You should be equally comfortable reviewing an API authorization model, reasoning about an AWS or Kubernetes deployment, tuning a security scanner, investigating suspicious production activity, and driving a vulnerability through remediation.
Agora's environment includes TypeScript and Node.js services, React applications, REST APIs, relational databases, Docker, Kubernetes on AWS, Pulumi infrastructure as code, Argo CD and GitOps, Cloudflare, and blockchain infrastructure. You do not need to arrive as an expert in every part of the stack, but you should be able to learn unfamiliar systems quickly and evaluate them from first principles.
We prefer candidates located close to Eastern Time, while welcoming exceptional engineers across Pacific Time through ET+2. Regardless of where you are located, your working hours will need to have a majority overlap with ET business hours.
KEY RESPONSIBILITIES
Partner with Engineering and Product throughout the development lifecycle, from early design and threat modeling through launch and ongoing operation.
Perform security reviews of system designs, application code, APIs, infrastructure as code, cloud environments, Kubernetes workloads, deployment pipelines, and production configurations.
Identify vulnerabilities and design weaknesses, communicate their impact clearly, and work with engineers on pragmatic remediation.
Serve as a trusted security subject-matter expert for application security, cloud and container security, identity and access management, secrets management, API security, data protection, and secure software development.
Develop reusable security guidance, secure patterns, review checklists, and engineering standards that make the secure approach easier to adopt.
Administer and improve Agora's security tooling, including AI-assisted security tools, SAST, DAST, software composition analysis, container and infrastructure-as-code scanning, CSPM, security monitoring, and related capabilities.
Integrate security controls into developer workflows and CI/CD pipelines; tune rules, reduce noise, improve coverage, and ensure findings lead to action.
Translate threat models and known attack paths into concrete logging, monitoring, and detection requirements.
Identify gaps in application, cloud, identity, infrastructure, and blockchain-related security telemetry, then work with engineering teams to address them.
Design, implement, test, document, and tune security alert rules and detection logic.
Triage and investigate security detections, correlate activity across relevant data sources, and determine scope, impact, severity, and required response.
Work closely with Agora's SOC to improve alert quality, escalation criteria, investigation procedures, and response runbooks.
Participate in security incident response, including investigation, containment, eradication, recovery, stakeholder coordination, and evidence preservation.
Lead or contribute to post-incident reviews and ensure lessons learned result in durable improvements to architecture, controls, monitoring, and operational processes.
Own the day-to-day execution of the vulnerability management program, including intake, validation, risk-based prioritization, assignment, remediation tracking, exception management, verification, and reporting.
Support third-party penetration tests, code reviews, architecture assessments, and other independent security engagements, from scoping and reviewer selection through remediation and closure.
Assess the security implications of new vendors, technologies, integrations, and architectural changes.
Build lightweight automation and metrics that improve security visibility, shorten investigation and remediation time, and help leadership understand material risk.
Contribute to Agora's product security, platform security, detection engineering, vulnerability management, and incident-readiness roadmaps.
BASIC QUALIFICATIONS
5+ years of hands-on experience in product security, application security, cloud security or a closely related security engineering role.
Strong software engineering fundamentals and the ability to review application code. Experience with TypeScript, Node.js, JavaScript, or another modern language is especially relevant.
Experience reviewing web applications, backend services, REST APIs, authentication and authorization systems, and relational database designs.
Practical knowledge of common application and API vulnerabilities, threat-modeling techniques, secure design principles, and modern identity patterns.
Experience securing AWS environments, containerized workloads, Kubernetes, infrastructure as code, and CI/CD or GitOps workflows.
Hands-on experience implementing or administering security tools such as SAST, DAST, SCA, CSPM, container scanning, secrets detection, infrastructure-as-code scanning, SIEM, or cloud-native detection platforms.
Experience developing or tuning security detections using application, cloud, identity, network, and infrastructure telemetry.
Strong investigation skills, including the ability to analyze logs and system activity, develop and test hypotheses, establish timelines, and determine the scope and impact of suspicious behavior.
Experience working with SOC, including alert escalation, investigation handoffs, runbook development, and detection-quality improvement.
Experience participating in security incident response and coordinating effectively with engineering and operational teams under time pressure.
Experience operating a vulnerability management process and driving remediation across multiple engineering teams.
Ability to evaluate findings and detections based on exploitability, confidence, and business impact rather than relying exclusively on automated severity.
Experience working with external penetration testers, auditors, or specialist security reviewers.
Strong written and verbal communication skills, including the ability to explain technical risk and incident status clearly to technical and non-technical stakeholders.
High autonomy and sound judgment. You can take an ambiguous concern, investigate it deeply, propose a path forward, and close the loop.
A collaborative, low-ego approach to security. You build trust with engineers while maintaining a high bar for systems protecting financial assets and sensitive data.
PREFERRED QUALIFICATIONS
Experience securing fintech, payments, digital-assets or other high-assurance financial platforms.
Familiarity with blockchain systems, smart-contract integrations, transaction flows, custody models, signing infrastructure, or cryptographic key management.
Experience with TypeScript, Pulumi, AWS, Argo CD, Cloudflare, PostgreSQL, Prometheus, or Grafana.
Experience with incident-response tooling, security data pipelines, log normalization, detection-as-code, or automated enrichment and response.
Experience defining operational metrics such as detection coverage, false-positive rate, investigation time, and mean time to contain.
Experience designing security controls for distributed, event-driven, multi-tenant, or high-availability systems.
Ability to create security automation, internal tools, or CI/CD integrations using code.
Experience applying AI-assisted tools to security investigations, detection engineering, or secure development.
Relevant offensive-security, incident-response and cloud-security experience or certifications.
Agora operates a centralized USD-pegged stablecoin platform with robust compliance, security, and governance. We are equally committed to fostering a diverse, inclusive, and equitable workplace.
We are an Equal Employment Opportunity Employer. We do not discriminate based on race, color, ancestry, national origin, religion or creed, mental or physical disability, medical condition, genetic information, sex (including pregnancy, childbirth, and related conditions), gender identity or expression, sexual orientation, age, marital status, military or veteran status, citizenship, or any other characteristic protected under applicable federal, state, or local law.
Interview Process
Silver screening Interview
Client Take home Challenge
Client Screening Interview
Client Technical interview
Client Behavioral Interview
Agora operates a centralized USD-pegged stablecoin platform with robust compliance, security, and governance. We are equally committed to fostering a diverse, inclusive, and equitable workplace.
We are an Equal Employment Opportunity Employer. We do not discriminate based on race, color, ancestry, national origin, religion or creed, mental or physical disability, medical condition, genetic information, sex (including pregnancy, childbirth, and related conditions), gender identity or expression, sexual orientation, age, marital status, military or veteran status, citizenship, or any other characteristic protected under applicable federal, state, or local law.
About Information Security
The Information Security area is one of the most strategic and in-demand fields in the technology market. With the rise of cyberattacks, data breaches, and regulations like LGPD and GDPR, companies of all sizes invest heavily in professionals who can protect their digital assets.
Key specializations include Network Security, Cloud Security (AWS, Azure, GCP), Offensive Security (Penetration Testing, Red Team), Defensive Security (SOC, Blue Team), AppSec, and Security Governance. Tools like SIEM (Splunk, QRadar), firewalls, EDR, and Vulnerability Management platforms are essential.
Certifications like CISSP, CEH, OSCP, CompTIA Security+, and AWS Security Specialty are important differentiators. Information security professionals are among the highest-paid in the sector, with growing demand especially in fintechs, healthtechs, and large enterprises.
Discover Other Areas
Understand the scope of work, key skills, and tools used in different career areas.
About Branding
Branding is the area responsible for building, managing, and strengthening a brand's identity and market value. Branding professionals create strategies that define how the brand is perceived by the public, from the logo to the complete customer experience.
Key skills include brand strategy, visual identity, brand guidelines, positioning, naming, brand voice, market research, brand equity, and brand management. Knowledge of graphic design (Figma, Illustrator, Photoshop), storytelling, and brand experience is a differentiator.
Branding professionals in technology companies are highly valued, especially those who master employer branding, digital branding, and can build strong, memorable brands in competitive markets. The field offers opportunities from brand designer to head of brand, with a focus on identity, differentiation, and perceived value.
About Web3
The Web3 area represents the new phase of the decentralized internet, built on blockchain technology. Web3 professionals create decentralized applications (dApps), interact with smart contracts, manage digital assets (cryptocurrencies and NFTs), and utilize DeFi (Decentralized Finance) protocols, revolutionizing how data, ownership, and finance are managed online.
About UI Design
The User Interface (UI) Design area focuses on creating and designing all the visual elements that users interact with in a digital product. This includes screens, buttons, icons, typography, color palettes, and responsive layouts, ensuring an aesthetically pleasing, consistent, and easy-to-use interface. Skills in tools like Figma and knowledge of design systems are essential.
About Content Manager
The Content Manager is the professional responsible for leading the entire content strategy, production, and management of an organization. They define the editorial strategy, coordinate writing teams, and ensure content aligns with business goals and brand identity.
Key skills include content strategy, editorial planning, content audit, buyer persona, customer journey, content ops, content governance, performance metrics (ROI, engagement, organic traffic), and team management. Knowledge of WordPress, Contentful, Notion, and analytics tools is a differentiator.
Content Managers in technology companies are highly valued, especially those who can align content with conversion funnels, lead multidisciplinary teams, and use data to optimize editorial strategy. The field offers opportunities from content manager to head of content, with a focus on strategy, quality, and scale.
About SEO Analyst
The SEO Analyst is the professional responsible for optimizing websites for search engines, increasing organic visibility and qualified traffic. With the growing importance of digital marketing, SEO professionals are fundamental to any online presence strategy.
Key skills include on-page and off-page SEO, technical SEO, keyword research, SEO audits, link building, optimized content creation, and metrics analysis. Tools like Google Search Console, Google Analytics, Ahrefs, Semrush, Moz, and Screaming Frog are essential for daily work.
SEO analysts in technology companies are highly valued, especially those who master technical SEO, Core Web Vitals, and data-driven content strategies. The field offers opportunities from junior analyst to head of SEO, with a focus on organic growth, domain authority, and return on investment.
Comments 0