Join Solana Foundation as a Senior IT Security Engineer to lead and enhance our enterprise security program in a dynamic web3 environment.
Posted by employer 1 month ago
First seen on Joblaze 1 week ago
Last verified on the company career page 1 day ago
Skills & Technologies
Not disclosed in this posting: compensation, years of experience, visa sponsorship.
Joblaze summary
In the role of Senior IT Security Engineer at the Solana Foundation, the individual will take charge of enhancing the organization's enterprise security program, focusing on identity, endpoint, and SaaS security. Key skills include hands-on experience with security governance, access control systems, and vulnerability management, along with proficiency in managing modern tech stacks like GitHub and AWS. This position is ideal for someone with a strong background in enterprise security who is comfortable working autonomously and navigating the unique challenges of the web3 landscape.
Joblaze insights
Quick facts
From the original posting
The Solana Foundation is a non-profit based in Zug, Switzerland, dedicated to the adoption, decentralization, and security of the Solana network. Solana is a high performance blockchain that can deliver a fast and friendly user experience, without sacrificing security. The Solana Foundation is working to realize a world where individuals own their data, use permissionless networks, and transfer information and value freely around the world. We are looking for talented people who are willing to jump right in and use their expertise to help the ecosystem build.
Solana Foundation is seeking a Senior IT Security Engineer to own and mature our enterprise security program. You'll be the primary owner of identity, endpoint, and SaaS security across a global team — managing everything from Okta, EDR, and MDM to the secure configuration of our cloud and developer infrastructure. This is a hands-on, high-ownership role for someone who has built and run enterprise security programs before and is ready to apply that experience to the unique risk models of web3. This individual will work closely with the CISO to implement defined security strategy and with operations teams and engineering teams to deliver security approaches that protect critical assets and enable company execution at the speed of crypto.
Own deployment, configuration, and ongoing management of our centralled identity and access management platform
Configure and manage our EDR (endpoint detection and response) solution across the fleet
Configure and manage our MDM (mobile device management) solution and enforce secure baseline configurations
Manage secure configuration and governance across our SaaS application fleet
Collaborate with operations to ensure security is integrated across the full lifecycle of a global endpoint fleet, from procurement and dropshipping through provisioning, patching, and retirement
Implement access control systems and internal data security practices across the organization per security standards defined by the CISO
Operate vulnerability management solutions, including scanning, triage, and remediation tracking
Audit and secure the configuration of modern enterprise tech stacks including GitHub, AWS, and GCP per established security policies
Execute backup testing processes and participate in incident response efforts
Maintain and improve compliance with security frameworks such as ISO 27001 and SOC 2
Strong infrastructure and enterprise security experience, including security governance, access control systems, and vulnerability management
Hands-on experience deploying and managing single-sign on solutions, EDR, and MDM tooling
Experience securing and managing a SaaS application fleet at an organization-wide scale
Experience managing a global fleet of endpoints across its entire lifecycle
Experience owning secure configuration of modern enterprise tech stacks such as GitHub, AWS, and GCP
Comfortable scripting (Python, Go, or Bash) to automate security workflows, evidence collection, and integrations across the identity, endpoint, and SaaS stack
Experience building backup processes and leading incident response
Experience working within security frameworks such as ISO 27001, SOC 2, or similar
Strong communication skills and comfort operating autonomously across time zones
Experience working across both traditional web2 operational security and crypto/web3 environments, with an understanding of how their security and risk models differ
Experience securing custody, key management, or other crypto-specific infrastructure