Senior Security Engineer (NYC / MIA)
Indexed description
Backed by Ribbit Capital, Franklin Templeton, NYCA, First Round, and Lightspeed Faction, with $23.6M raised in 2025. Trusted by more than 40,000 clients including global leaders such as MoneyGram, WireX, Toku, and more, Crossmint provides embedded smart wallets, on/offramps, cross-chain stablecoin orchestration, tokenization, and other blockchain primitives through simple, developer-friendly APIs that integrate in minutes and scale to millions of users.
In January 2026, Crossmint secured MiCA authorization from Spain's CNMV, becoming one of a select few stablecoin infrastructure providers fully licensed to operate across all 27 EU member states and held to the same regulatory standards as traditional financial institutions. Crossmint also powers the Republic of the Marshall Islands' first digital UBI program, backs MoneyGram's new stablecoin cross-border experience launching in LATAM, and recently partnered with WireX to expand multichain stablecoin payment infrastructure to non-EVM networks like Stellar.
The future of finance is stablecoin-native. Crossmint makes it easy to get there.
Location
NYC or Miami. Hybrid office setting.
Type of Employment
Full-time
Salary range
180,000 - 210,000 USD
Note: We determine candidate levels through insights gained during the interview process.
About The Role
We are seeking a Senior Security Engineer to own the operational execution of security at Crossmint as we continue to scale. The volume of security operations, compliance work, and engineering support requires dedicated ownership to maintain a strong security posture as the company grows.
This role is foundational. You will run the day-to-day security function, partnering closely with engineering, compliance, and external vendors to ensure our infrastructure, applications, and processes remain secure. This role enables security leadership to focus on strategy, automation, and long-term risk management while you ensure operational excellence and follow-through.
What You Will Do
Security Operations and Infrastructure
- Own and operate cloud security across our cloud environments: AWS primarily, with some exposure to GCP, Vercel.
- Design, maintain, and monitor engineering security controls including cloud IAM, logging, monitoring/alerting, and key management.
- Secure our coding assets, including: CI/CD pipelines, GitHub Action environments, secrets management, and software supply chain.
- Manage security-related access controls including privileged access, service accounts, credential rotation, and performing access reviews.
- Perform secure code reviews and provide hands-on application security support to engineering teams.
- Review authentication flows, payment logic, and API security with human judgment, not just automated scanners.
- Partner with engineers to remediate vulnerabilities and embed security best practices into product development.
- Coordinate our external security review program with our 3P security auditor firms.
- Own vulnerability management workflows including prioritization, remediation tracking, and verification.
- Support incident response through internal triage, investigation, and remediation in collaboration with external 24/7 response partners.
- Support SOC 2 and other compliance efforts by collecting evidence, documenting controls, and maintaining audit-ready processes for engineering-security related controls.
- Contribute to regulatory and compliance initiatives such as DORA, where applicable.
- 4-8 years of experience as a security engineer. 3+ years of hands-on experience securing AWS environments or equivalent cloud, including IAM, Security Hub, CloudTrail, GuardDuty, and KMS.
- Strong understanding of CI/CD security, including GitHub Actions, secrets scanning, and dependency management.
- Experience with secure code review or application security fundamentals
- Experience working with at least one compliance framework, preferably SOC 2, though ISO 27001 or similar is acceptable.
- Highly organized with great attention to detail. You don’t drop balls.
- Comfort operating in a fast-paced startup environment with ambiguity.
- Ability to communicate security concepts clearly to non-technical stakeholders without creating friction.
- Experience using AI-assisted tools such as Claude or GitHub Copilot for security automation.
- Ability to work flexible hours if an incident arises
- Fintech or payments industry experience.
- Exposure to DORA or MiCA compliance requirements.
- Familiarity with crypto or blockchain security considerations.
- Take a security issue from identification through remediation with minimal guidance.
- Prioritize work based on risk and impact, not who is asking the loudest.
- Document work clearly to support audits and long-term knowledge sharing.
- Push back diplomatically when something is insecure while offering practical alternatives.
- Unblock themselves by researching and validating solutions independently.
- Know when to escalate issues versus handling them autonomously.
- Hand-holding on basic cloud or security concepts.
- Detailed instructions for routine tasks such as access reviews or credential rotation.
- Constant check-ins to remain productive.
Benefits
- Extensive access to leading AI tools and subscriptions, with AI actively encouraged and integrated into daily workflows.
- Stock options program.
- We conduct two performance reviews annually. The first addresses performance ratings, bonuses, and promotions. The second encompasses these elements along with salary adjustments reflecting inflation and market conditions.
- Unlimited, flexible PTO.
- Flexible work schedule.
- Company laptop and allowance for any necessary home equipment.
- Daily stipend for commuting to the office.
- Company-paid trips for annual off-sites and onsites.
- Insurance covered by Crossmint.
- 401(k) Plan.
- Results and delivery: Ship high quality work fast.
- Build for the long term: Build scalable, secure, and reliable solutions. Use AI.
- Extreme Ownership: Be an effective Directly Responsible Individual (DRI). Be proactive.
- Be a team player: Be an effective and kind colleague providing credible challenge. Be present and reliable.
- Adolfo Fernández - Recruitment & People Ops
- Gloria Alogo - People Ops, Onboarding & Benefits
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search