OF
RWA Job

Senior Security Engineer - Product Security

Ondo Finance
Remote (US)Posted 2mo ago

Role at a glance

Location
Remote (US)
Level
Senior
Function
Engineering

Apply directly on Ondo Finance’s site. RWA Signal does not collect applications.

About this role

RWA Signal Brief

Ondo Finance is seeking a Senior Security Engineer to oversee product security for their institutional-grade RWA infrastructure. The role focuses on bridging traditional application security with the unique risks inherent in on-chain integrations, such as wallet flows and signing mechanisms. You will lead threat modeling, manage bug bounty programs, and refine the secure software development lifecycle to ensure products remain resilient against both fintech and blockchain-specific threats.

  • 5+ years of experience in Product or Application Security.
  • Deep secure code review skills in TypeScript, Python, or Go.
  • Proven experience managing AppSec tooling and reducing false positives.
  • Ability to lead threat modeling sessions with engineering teams.
  • Experience managing end-to-end bug bounty or responsible disclosure programs.
Application SecurityThreat ModelingBug Bounty ManagementSecure SDLCWeb/API SecurityBlockchain Security

Summary written by RWA Signal. The employer’s own description follows below.

About the role (from employer)

About Ondo

Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. We operate at the intersection of traditional finance and on-chain systems, which means our product surface has to hold up against both the ordinary threats that hit any high-value fintech and the specific ones that follow value on-chain.

About the Role

We are hiring a Senior Security Engineer - Product Security to own how we ship secure products at Ondo. You will be a security partner for our product engineering teams, driving threat modeling, owning secure code reviews for new products or feature expansions, maintaining and tuning AppSec tooling, and improving the existing SSDLC. You can expect to take ownership of the bug bounty program, new feature to existing product reviews, and similar broad ownership of critical functions paired to a dedicated ProdSec lead. An AI-native approach is welcome, paired with AI-driven approaches should expect to be justified by describing how doing so enables risk outcomes.

This is a hands-on IC role. You will read code, run threat models, review architecture proposals, own tooling, and push engineering teams to build products that are secure by default. You partner closely with adjacent security function like AppSec, Infrasec, and SecOps.

What You’ll Do

  • Drive threat modeling for new features, integrations, and architectural changes across the product surface. Push threat models past templates into decisions that engineering teams actually implement.
  • Own secure code review for high-risk changes — authentication, session management, cryptographic paths, wallet and signing flows, RPC and third-party integrations, permission and consent surfaces.
  • Expand the AppSec tooling stack and treat “reducing false positives” as a first-class deliverable. AI-native integrations are welcome.
  • Design and evolve our secure SDLC: where security fits in the dev workflow, what triggers a review, what a lightweight security sign-off looks like versus a full one, and how do we validate controls.
  • Run our responsible disclosure and bug bounty program. Set scope, triage inbound reports, decide payouts, and drive findings to closure with engineering.
  • Support and own appropriate scope for the intake and closure of findings from external audits and pentests — coordinate with audit vendors (Coinspect, Cantina, NCC Group, and others), organize findings into our internal risk register, and drive remediation with engineering owners.
  • Partner with engineering leads to align o secure-by-default patterns - libraries, templates, sensible defaults, and paved-road implementations of anything security-relevant.
  • Threat model blockchain-integrated components like wallet flows, RPC integrations, signing infrastructure, on-chain admin actions triggered from off-chain systems in partnership with engineers who own the on-chain code.
  • Contribute to hiring, mentoring, and pushing the technical bar on the Security team.

What We’re Looking For

  • 5+ years in Product Security or Application Security, including senior IC time at a fast-moving product company.
  • Deep secure code review skills in at least one modern stack (TypeScript / JavaScript, Python, or Go). Ability to move across stacks at the level required to threat model.
  • Strong threat modeling skills, appropriate to experience - you can drive a real threat model with an engineering team, not just fill in a template. In practice, we look for core understanding of industry-relevant TTPs and IoCs and strong intuitions on how to apply those lessons learned to our products.
  • Practical experience owning or majorly contributing to an AppSec tooling program. You have shipped rules, tuned noise, and measured impact.
  • Comfortable running or building a bug bounty / responsible disclosure program end-to-end assuming properly resourced to do so.
  • Strong working knowledge of modern web and API security - session and auth flows, OAuth and OIDC, browser security model, common web/API vulnerability classes, and their less-common variants.
  • Comfortable reading Terraform, cloud IAM policies, and CI/CD configuration well enough to reason about how a product vulnerability crosses into an infra risk.
  • Strong engineering partnership skills - you engage constructively, understand the “why” before proposing risk controls, you know when to accept risk, and you write things down.
  • Willing to grow into blockchain-adjacent product security on the job, including the specific attack surface introduced by wallet, signing, and on-chain-integration code.

Blockchain Exposure Note

  • This role firmly lives in Web2 prodsec. But, it also requires someone who understands what “Web2 vs Web3” terminology means. In other words, how our products interact with blockchains creates unique threat models that all product security teammates must grasp. At a minimum, by Day 1 you should have strong intuitions about how blockchains will make your prodsec experience unique, you should grasp the common terminologies, and you should be able to discuss with colleagues several incident post-mortems that demonstrate how Web2 compromises lead to Web3 funds losses.
  • You do not need to be an expert in smart contract auditing, blockchain security architectures, or decentralized consensus-driven risk controls.

Nice to Have

  • Prior work at a crypto, fintech, or other company where products handle high-value or irreversible actions.
  • Familiarity with wallet, signing, or key-management flows.
  • Reading-level familiarity with Solidity or Rust, target: when ProdSec intersects with smart contracts or other on-chain applications, you can parse what the code is likely doing, and work with blockchain security subject matter experts from there.
  • Bug bounty history - reports, CVEs, or published write-ups.
  • Familiarity with browser-extension security, mobile app security, or account-abstraction wallet designs.
  • Public output - talks, blog posts, open-source tools, CVEs.

How We Work

The Security team values a high trust team environment where respectful candor can thrive. We expect senior engineers to have an opinionated take on how to accomplish a task, accept feedback from the team and other external stakeholders and return it in kind, and to always assume positive intent. Professionalism, ethics, and enabling stakeholders towards common goals are important always.

Source & provenanceThis job is published by Ondo Finance on their own careers site (6 August 2026) and aggregated by RWA Signal.View original posting

Ondo Finance in the news

Company profile →
Ondo Tokenized Stocks Hit Record $1.26B TVL as ONDO Tests Key Support
Stocks

Ondo Tokenized Stocks Hit Record $1.26B TVL as ONDO Tests Key Support

Ondo Finance has achieved a significant milestone as its platform for tokenized stocks and ETFs reached a record $1.26 billion in total value locked. The platform currently supports a diverse catalog of over 450 individual tokenized equities and exchange-traded funds. Beyond the TVL growth, the protocol has recorded a cumulative trading volume exceeding $28 billion, signaling robust institutional and retail interest in on-chain equity exposure. While the ONDO governance token continues to experience market volatility and technical chart analysis, the platform's underlying asset adoption remains a distinct metric from the token's price performance. This growth highlights the increasing demand for bridging traditional equity markets with blockchain infrastructure to enhance liquidity and accessibility. The sustained capital inflows into these tokenized products suggest a maturing market for real-world assets beyond simple yield-bearing instruments. As Ondo continues to scale its offerings, the ability to maintain this pace of adoption will be a critical indicator for the broader RWA sector.

Blockonomi·Oct 3, 20267.5
Ondo Perps Adds Spot Trading for 12 Tokenized Stocks and ETFs
Stocks

Ondo Perps Adds Spot Trading for 12 Tokenized Stocks and ETFs

Ondo Finance has expanded its Ondo Perps platform by launching spot trading for 12 tokenized stocks and ETFs, including assets like NVIDIA, Tesla, and gold-linked tokens. This development allows eligible non-U.S. traders to purchase these tokens directly on the platform using USDC and immediately utilize them as collateral for perpetual futures positions. By integrating spot and derivatives trading, the platform enables users to maintain long exposure while simultaneously hedging through short positions without needing separate stablecoin collateral. The system utilizes an offchain matching engine with onchain settlement, supporting assets on Ethereum and Arbitrum. This move represents a significant evolution in RWA utility, as it transforms tokenized securities from passive holdings into active margin collateral. The platform applies specific risk management measures, such as asset-specific haircuts ranging from 10% to 25%, to account for potential price divergence. This integration highlights the growing trend of creating unified trading environments where real-world assets serve as the foundational liquidity for decentralized derivatives markets.

cryptonews.net·Oct 2, 20267.5
BNB Chain crosses $1B in tokenized stocks, ETFs as market hits $3.7B
Stocks

BNB Chain crosses $1B in tokenized stocks, ETFs as market hits $3.7B

BNB Chain has become the first blockchain network to surpass $1 billion in tokenized stocks and exchange-traded funds, capturing approximately 30% of the total $3.7 billion market. This milestone reflects a significant shift in market dominance, as BNB Chain's share grew from 13% in January to its current leading position. Data from Token Terminal indicates that the broader tokenized stock and ETF sector expanded by 17% in September, reaching a total market capitalization of $3.35 billion. BNB Chain currently outperforms Ethereum, which holds $828 million, and Solana, which holds $738 million in similar assets. Binance Research reports that BNB Chain also leads in user adoption, with 1.8 million addresses holding tokenized stocks, representing 45% of the total market. The network hosts key products such as Binance bStocks and Ondo Global Markets tokenized securities. This rapid growth highlights the increasing institutional and retail appetite for on-chain exposure to traditional financial instruments, signaling a maturing landscape for RWA integration across major blockchain ecosystems.

Cointelegraph — Tokenization·Oct 2, 20267.5