Skip to content

Open nowPosted 32 days ago

Senior Security Engineer, Enterprise

jito-labs4 open roles

Pay
$180,000 – $200,000 a year
Where
USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Engineer, Enterprisejito-labs · USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on jito-labs's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 32 days ago

The posting

ABOUT JITO

Jito builds the market layer of Solana: the execution, capital, and incentive infrastructure behind the network's onchain economy. That includes the validator client running the majority of Solana stake, BAM (a new framework for verifiable ordering, pre-execution privacy, and programmable blockspace), JitoSOL (the leading liquid staking token on Solana), and JTX (trading built directly on our own market infrastructure).

We are a lean, high-density team. Everyone here owns real surface area, works in the open, and ships at pace. The engineers on this team are the people market makers call when milliseconds matter.

About the Role We're growing our security team and looking for an engineer who can own a broad operational and technical scope: someone equally at home triaging an access request, running a security review, or building a custom testing framework. You'll report directly to the Head of Security, working closely to strengthen and scale our security posture across the organization.

What You'll Do • Identity and access management: provisioning, lifecycle operations, and monitoring for critical changes • Security reviews across our product portfolio: threat modeling, code review, fuzzing, and functional testing • Day-to-day bug bounty operations: triage, remediation tracking, and escalation of high-severity findings • AI security research and tooling: adversarial testing frameworks for agent controls, with a focus on reusable patterns • Software supply chain monitoring: malicious package detection beyond standard CVE scanning • External penetration test coordination: scoping, logistics, and post-engagement remediation tracking • Compliance documentation and evidence gathering as requirements emerge

What We're Looking For • A software engineering background is essential: you've built production systems, and that foundation shapes how you approach security • You've since moved into product security and are fluent in the full lifecycle: threat modeling, secure design review, whitebox code review, and vulnerability testing • 5+ years of professional experience, with a meaningful portion in software engineering before transitioning into security • Proficiency in at least one systems or backend language (Rust preferred; Go, C++, or Python also work). You will write code, build tooling, and read production codebases as a routine part of this role. • Demonstrated experience in product or application security, not solely infrastructure- or compliance-focused roles • Track record of building security tooling or automation from scratch • Experience conducting or leading security reviews on production software systems • Solid understanding of identity and access management concepts and tooling • Genuine interest in AI security with the ability to build adversarial testing tooling • A thoughtful approach to software supply chain risk beyond checkbox scanning • Strong written communication: documentation is a real part of this job • Comfortable with high ownership and working autonomously on a small team • Experience in web3, crypto, or DeFi • Bachelor's degree in Computer Science, Computer Engineering, or a related technical field

Nice to Have • Hands-on experience with mobile device management (MDM) platforms and endpoint policy enforcement • Familiarity with enterprise IAM systems and SSO: configuration, integration, and audit • Experience with privileged access management (PAM) tooling and the operational patterns around it • Strong Linux administration skills: comfortable at the command line, understanding of kernel-level security primitives, experience hardening Linux environments • Experience with multisig schemes: signing policy design, quorum configuration, or key management in a production context • Familiarity with hardware security modules (HSMs): integration, key lifecycle management, or operational use • Exposure to trusted execution environments (TEEs): attestation, confidential compute, or secure enclave design

HOW WE WORK

Remote-first, writing-heavy, and transparent by default: most decisions happen in public Slack channels, and everyone's voice carries. We value ownership, humility, curiosity, and getting it done over getting it perfect. Small egos, high standards.

WHAT WE OFFER

Competitive compensation including salary and token incentives, the tools you need to do your best work, and a seat at the center of Solana's market infrastructure alongside some of the strongest engineers in the ecosystem.

Jito is an equal opportunity employer. We evaluate candidates on the basis of their skills, experience, and potential contribution, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against jito-labs's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on jito-labs's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    jito-labs's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.