Lead Security and Infrastructure Engineer
LatamCent Tampa, Florida, United States · $170K–$210K/yr
Staffing and Recruiting · 11-50 employees
About the role
The Lead Security and Infrastructure Engineer will own security, infrastructure operations, and reliability across cloud and on-chain environments. Responsibilities include hardening systems, managing incident response, building CI/CD pipelines, and establishing security governance.
What they look for
Requirements
Candidates must have 8+ years of experience in DevOps, SRE, or security engineering with deep expertise in Google Cloud Platform. The role requires production experience with Ethereum/EVM systems and strong proficiency in Node.js, TypeScript, and infrastructure-as-code.
Benefits
Full description
About the Role
We are looking for a hands-on Lead Security and Infrastructure Engineer to own security, infrastructure operations, and reliability across cloud, application, and on-chain environments.
You'll work directly with the CTO as the founding security and infrastructure hire. You'll be responsible for hardening existing systems, building missing security and infrastructure capabilities, supporting production operations, and establishing the processes and tooling needed as the company scales.
The technology environment includes Google Cloud Platform, Cloud Run, BigQuery, MySQL, Node.js, TypeScript, and Cloudflare, alongside Ethereum and EVM-compatible networks, wallets, stablecoins, and smart contracts.
This is a builder role. You'll own systems end to end, from architecture and implementation through monitoring, incident response, and on-call.
What Success Looks Like in Your First 3-6 Months
- Establish clear security ownership, access controls, secrets management, and secure defaults across production systems.
- Improve incident detection, response procedures, runbooks, and post-incident processes.
- Strengthen GCP, Cloudflare, database, and deployment configurations against security and reliability risks.
- Improve observability across production infrastructure so issues are detected before they impact customers.
- Validate backup, disaster recovery, RTO/RPO, and restoration procedures through hands-on drills.
- Establish a practical roadmap for the security and infrastructure function as the company scales.
Key Responsibilities
Security Engineering
- Own the security posture across cloud, application, and on-chain systems.
- Lead security incident response, including detection, containment, forensics, remediation, and blameless post-mortems.
- Build security tooling, runbooks, and processes that improve incident response over time.
- Establish secure defaults for secrets management, IAM, network segmentation, audit logging, and production access.
- Own access governance, least-privilege policies, and separation of duties across production systems.
- Conduct threat modeling, vulnerability management, and recurring security reviews.
- Build detection and alerting for anomalous traffic, abuse, and scanning across Cloud Run, load balancers, and Cloudflare.
- Support compliance and audit-readiness initiatives such as SOC 2.
- Represent security requirements with partners, customers, and internal stakeholders.
Infrastructure Operations & Reliability
- Own the infrastructure operations supporting production releases.
- Build and improve CI/CD pipelines for deploying Cloud Run services safely and consistently.
- Own release hygiene, including rollouts, rollbacks, deployment controls, and operational readiness.
- Provide hands-on operational support for production infrastructure.
- Perform maintenance, upgrades, troubleshooting, and toil reduction across the platform.
- Build and maintain infrastructure-as-code and deployment automation on GCP.
- Harden Cloud Run, BigQuery, MySQL, and Cloudflare configurations.
- Improve logging, metrics, tracing, monitoring, and alerting.
- Own reliability practices around capacity, backups, availability, and on-call operations.
- Own disaster recovery capabilities, including RTO/RPO targets, database backups, point-in-time recovery, failover procedures, and DR runbooks.
- Run regular restoration drills and game days to validate recovery procedures.
Blockchain & Web3 Security
- Secure Ethereum and EVM integrations, including wallet and key management, transaction signing, and smart-contract interactions.
- Review on-chain settlement flows for security and correctness.
- Partner with product and engineering teams on new payment and blockchain features.
- Monitor on-chain operations and develop safeguards against crypto-specific failure modes.
- Help strengthen security around stablecoin and on-chain settlement infrastructure.
Requirements
- 8+ years of experience in DevOps, infrastructure, SRE, or a closely related field, with significant hands-on security engineering ownership.
- Experience operating at a senior or lead level and setting security and infrastructure direction.
- Deep, hands-on Google Cloud Platform experience, including Cloud Run, IAM, networking, BigQuery, logging and monitoring, Security Command Center, and cloud security operations.
- Strong security fundamentals across IAM, least privilege, secrets and key management, network security, incident response, and vulnerability management.
- Production experience with Ethereum or EVM-based systems, including wallets, key management, transaction signing, and smart-contract interactions.
- Strong experience with Cloudflare, including WAF, DNS, rate limiting, edge security, and Pages.
- Experience with Node.js / TypeScript application environments.
- Experience working with MySQL in production.
- Strong infrastructure-as-code and CI/CD experience.
- Demonstrated incident response experience in production environments.
- Strong written and verbal English communication skills at a C1-C2 level.
- Must be authorized to work in the United States and currently based in the United States.
Preferred Qualifications
- Experience in fintech, payments, payroll, or another regulated environment that handles funds or sensitive financial data.
- Experience with SOC 2, ISO 27001, PCI, or similar compliance frameworks.
- Security certifications such as CISSP, OSCP, or GCP Professional Cloud Security Engineer.
- Smart-contract security auditing experience.
- Experience with stablecoins and on-chain settlement at scale.
- Experience building a security or infrastructure function from the ground up.
- Experience designing and operating disaster recovery programs for financial or high-availability systems.
Compensation & Logistics
- Base Salary: $170,000-$210,000 USD per year
- Equity: Meaningful equity participation
- Time Off: Unlimited PTO
- Schedule: Flexible work schedule focused on outcomes
- Benefits: 401(k) with a 3% company contribution
- Work Model: Fully remote
- Location: United States
- Employment: Full-time
Company Overview
Our client is a global payments and payroll platform built for modern, distributed teams. The platform enables businesses to pay employees, contractors, and freelancers across borders using both traditional banking rails and digital assets.
The platform manages the infrastructure behind cross-border payments, including invoicing, KYC/KYB, onboarding, compliance, tax, identity, and reporting.
The technology operates at the intersection of traditional finance and Ethereum-based settlement. The stack includes Google Cloud Platform, Cloud Run, BigQuery, MySQL, Node.js, TypeScript, and Cloudflare, alongside a large smart-contract ecosystem deployed across EVM-compatible networks.
The team is lean, remote-first, and high ownership. Security, correctness, accountability, direct communication, and strong documentation are especially important because the platform handles real money and sensitive customer information.