Senior Infrastructure Security Engineer
Secure Matter Labs' corporate and production infrastructure across identity, endpoint, detection and response, cloud and infrastructure security, incident response, secure systems design, and cross-team collaboration. The role supports open-source decentralized infrastructure and Ethereum L2 systems.
Responsibilities
- Own identity and collaboration security configuration, including access policies, third-party app governance, DLP, context-aware access, and admin audit.
- Drive least privilege and phishing-resistant MFA across the organization.
- Build and maintain detections, response playbooks, log-source integrations, and the detection-as-code pipeline.
- Reduce mean time to detect and respond to real incidents.
- Harden cloud infrastructure, Kubernetes clusters, and CI/CD pipelines.
- Review infrastructure as code, embed security guardrails, and partner on secrets management and supply-chain controls.
- Own endpoint security through MDM, baseline hardening, EDR tuning, and endpoint telemetry.
- Lead end-to-end security incident investigations covering containment, forensics, root cause, remediation, and post-mortems.
- Run threat models and architecture reviews for internal systems and infrastructure changes.
- Collaborate with Protocol Security, DevOps, IT Ops, and Product Engineering to raise risks and influence security outcomes.
Requirements
- 5+ years of hands-on infrastructure or detection-and-response security experience.
- Production experience securing cloud-based identity and collaboration platforms at scale.
- Hands-on experience with modern SIEM and SOAR tools, detections, log sources, response playbooks, and false-positive reduction.
- Strong cloud security background including IAM, network controls, workload identity, and organization-level guardrails.
- Experience securing macOS-dominant endpoint fleets with MDM, endpoint hardening, and EDR.
- Familiarity with Infrastructure as Code, secrets management, and security automation.
- Real incident response and security on-call experience.
- Clear technical communication across engineering and non-engineering stakeholders.
- Blockchain or Web3 exposure.
- Compliance framework experience with SOC 2 and ISO 27001.
- Kubernetes security.
- Detection engineering as code.
- Experience working in lean security teams.