Staff Product Security Engineer (Security)
What security roles in crypto pay
64 salaries · our own dataThis role pays $200k-$250k, above the $202k median for security roles in crypto on this board.
As a Staff Product Security Engineer at Phantom, you own product security across a mobile wallet and financial platform used by tens of millions of people worldwide. You partner with engineering and product teams to identify and address security risks spanning mobile applications, web products, APIs, and backend services. At the Staff level, you set technical direction, lead complex security initiatives, and raise the bar for how Phantom designs, builds, and ships secure products. You work in a fully remote, AI-native security team that aggressively uses AI to expand the speed, depth, and reach of security work.
What you'll do
- Partner with engineering teams to identify and address security risks across Phantom's mobile applications, web products, APIs, and backend services
- Lead security reviews for new products and major architectural changes, with particular attention to authorization boundaries, sensitive data, transaction integrity, key material, and third-party integrations
- Embed practical security controls into the software development lifecycle, from design and implementation through testing, release, and production operation
- Perform AI-assisted security code reviews and targeted testing of high-risk features, building repeatable approaches that find vulnerabilities before they reach production
- Develop and improve tooling that gives engineers fast, actionable security feedback without creating unnecessary friction, using automation and AI-assisted workflows where they materially improve coverage or speed
- Harden CI/CD, build, and release systems against supply chain threats, including dependency risk, secrets exposure, build provenance, artifact integrity, and compromised developer or automation workflows
- Triage findings from internal testing, researchers, bug bounty submissions, and third-party assessments, working with owners to determine real-world impact and drive issues through verified remediation
- Support the investigation of product security incidents and suspicious activity, turning lessons from incidents into durable improvements to product architecture, detection, and engineering standards
- Establish product security patterns and expectations across engineering, leading ambiguous cross-functional initiatives and influencing architecture beyond any single product team
What you bring
- 5+ years of experience in product security, application security, security engineering, or software engineering, including senior or staff-level experience
- Strong understanding of web, mobile, API, and distributed-system security, including authentication, authorization, session management, cryptography, and common vulnerability classes
- Hands-on experience building or applying AI-assisted security tooling to test applications and APIs, combining automated analysis with source-code review and manual validation
- Demonstrated ability to review production code in one or more languages such as TypeScript, JavaScript, Rust, Python, or Go
- Experience securing software supply chains and CI/CD systems, including dependencies, build infrastructure, secrets, artifacts, signing, and release integrity
- Experience threat modeling complex products and translating security risks into concrete engineering requirements
- Strong judgment when evaluating exploitability, business impact, and appropriate remediation
- Track record of partnering effectively with engineering and product teams while maintaining a high security bar
- Clear written and verbal communication, including the ability to explain technical risk to both engineers and non-security stakeholders
Nice to have
- Experience securing consumer financial products, wallets, payments, or other systems where client integrity and transaction safety are critical
- Familiarity with blockchain systems, smart-contract interactions, transaction simulation, signing workflows, or self-custodial wallet architecture
- Experience securing browser extensions or native mobile applications
- Experience building and integrating application-security tooling, static or dynamic analysis, security test infrastructure, or policy-as-code controls
- Familiarity with AWS, Kubernetes, CI/CD systems, and cloud-native service architectures
- Experience working with bug bounty programs or coordinating external security assessments
What we offer
- Target base salary of $200,000 to $250,000 plus equity and benefits, determined by your skillset, prior experience, interview quality, and market factors including location
- Eligibility to participate in the company's performance bonus program
- Comprehensive medical, dental, and vision insurance with 100% coverage
- Stipend for your ideal remote setup
- Flexible hours and a supportive remote environment
- Unlimited vacation
- 401(k) retirement plan
- Monthly wellness benefit
- Weekly meal benefit
- Global off-sites
About Phantom
Phantom is a mobile wallet and financial platform with tens of millions of users worldwide, ranked #1 in Google Play's finance category. The company enables users to access global markets including perpetuals, prediction markets, tokenized assets, stablecoins, and partnerships with trusted names like Hyperliquid, Stripe, Kalshi, and Visa. Phantom is fully remote with approximately 180 people and is backed by $150M in Series C funding from a16z, Sequoia Capital, and Paradigm.
