Jobs and Careers
PH

Senior/Staff Security Engineer - Corporate Security

Phantom
UKRemotefull_timeVerifiedPosted 10 Oct 2025
💰 $285,000/yr($225,000/yr$285,000/yr)

About the role

Phantom is revolutionizing the way millions of people interact with the crypto ecosystem. Our self-custodial wallet offers a seamless, unified experience for managing accounts and tokens across Solana, Bitcoin, Ethereum, and Polygon, empowering users with a single, convenient solution. By integrating cutting-edge security features and launching innovative tools for an enhanced personalized user experience, Phantom is able to provide a next-generation, safe and easy to use self-custodial wallet for everyone. This strategy has allowed Phantom to achieve significant milestones including surpassing 15 million MAU’s, reaching #1 in the Google play store finance category, and consistently trending as a Top 50 app across all categories, right next to X, PayPal, Coinbase, and ChatGPT.

We're seeking a Senior/Staff Security Engineer to own and scale the security of Phantom's corporate infrastructure. This is a foundational role—you'll be our first dedicated corporate security hire, working directly with the Head of Security to build enterprise security capabilities from the ground up.

You'll protect our distributed workforce, secure our corporate systems, and enable our team to move fast without compromising safety. This role sits at the intersection of security engineering, IT operations, and risk management, where you'll build security controls that are both robust and user-friendly.

What You'll Do

Build & Secure Corporate Infrastructure

  • Design, implement, and manage security for all corporate endpoints across our fully distributed workforce

  • Deploy and operate our security stack including MD, EDR/XDR, ZTNA and SSO

  • Implement zero-trust architecture principles including device trust, conditional access, and least-privilege controls

  • Enforce security baselines, hardening standards, and compliance policies across all corporate systems

  • Build and maintain secure authentication systems and identity management workflows

Drive Security Initiatives & Risk Reduction

  • Lead security initiatives for endpoint hardening, access controls, and corporate infrastructure protection

  • Conduct security design reviews and risk assessments for new services, tools, and integrations

  • Perform vulnerability assessments and drive remediation efforts across corporate systems

  • Partner with IT and cross-functional teams to balance security requirements with business velocity

  • Develop and enforce IT security policies, standards, and procedures aligned with industry best practices

Detection, Response & Automation

  • Respond to security incidents and events impacting corporate systems with urgency and technical depth

  • Collaborate with the Detection & Response team to build detection rules, alerts, and monitoring for corporate infrastructure threats

  • Automate security workflows using Python, Go, or similar languages to reduce manual toil

  • Create runbooks and playbooks for common security scenarios

  • Leverage security tooling and automation to scale security operations efficiently

Security Culture & Education

  • Evangelize security best practices through education, training, and internal communications

  • Build security awareness programs that empower employees to make secure decisions

  • Partner with engineering teams to embed "secure by default" principles into development workflows

  • Serve as a trusted security advisor across the organization

What We're Looking For

Must-Have

  • 5+ years of experience in corporate/enterprise security, IT security, or endpoint security engineering

  • Deep hands-on expertise with:

    • MDM platforms: JAMF, Kandji, Intune, or similar for macOS/iOS fleet management

    • EDR/XDR solutions: CrowdStrike, SentinelOne, Microsoft Defender, or similar

    • Identity & Access Management: Okta, Azure AD/Entra ID, or similar SSO/IAM platforms

    • Authentication protocols: SAML, OAuth, OIDC, SCIM

    • Zero Trust architecture: Device trust, conditional access, identity verification, and least-privilege access models

  • Strong scripting/automation skills: Python, Go, Bash for security automation and tooling

  • Cloud security knowledge: Hands-on experience with AWS, GCP, or Azure

  • macOS security expertise: Deep understanding of macOS sec

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Phantom

View company profile →