Engineering Lead — Security
Job Description
About Somnia SOMNIA is the Agentic Chain - a hyper-performance L1 operating at an order of magnitude faster than existing networks. We empower builders and traders to create real-time, autonomous, and fully decentralized products, powered by agents, that were previously impossible and cannot be built anywhere else. It’s where the future of Web3 protocols will be built, so we’re facilitating a new wave of on-chain applications from DEX to Prediction Protocols and much, much more. Somnia is being developed by Somnia Foundation backed by Improbable https://www.improbable.io/, a British tech Unicorn +++ that has been at the forefront of building virtual worlds for over a decade. Somnia received initial funding from MSquared https://www.msquared.io/, which raised $150 million https://www.businesswire.com/news/home/20220407005101/en/Improbable-Raises-US150m-to-Establish-M%C2%B2-MSquared-a-Metaverse-Network-and-Ecosystem-Powered-by-Its-Morpheus-Technology from a16z crypto, SoftBank, Mirana Ventures, CMT Digital, and SIG.
About the Role
We're looking for an Engineering Lead to own security across Somnia—the infrastructure and operations running the L1, the products and services teams ship on top of it, the policies and processes that govern how we work, and the multisig and key management protecting the protocol's most critical assets. A senior, hands-on role: you help set the security strategy and posture and do the work—hardening infrastructure, defining incident response, securing signing and treasury operations, and raising the bar across the team. You treat security as an enabler of velocity, not a blocker, and use AI as a multiplier.Key Responsibilities
- Work with the other technical leaders to help define the engineering culture and bar.
- Own the security posture of the L1 infrastructure—validators, RPC, signing services, supporting systems. Harden hosts, networks, and pipelines; drive vulnerability management, patching, and security monitoring.
- Define and roll out the policies and standards that govern the organization—access control, secrets management, secure SDLC, change management, compliance-readiness.
- Drive application and supply-chain security for what Somnia ships—secure-by-default patterns, dependency and build-pipeline scanning in CI, and security reviews where the stakes are highest. That includes the agentic workflow itself: the permissions and provenance of agent-authored changes.
- Design and operate multisig governance, signing ceremonies, and the key lifecycle (generation, storage, rotation, recovery) for treasury, upgrades, and privileged ops. No single points of failure; everything auditable.
- Build and lead the security incident-response capability—detection, triage, containment, blameless postmortems—and run tabletops, from a compromised laptop to a live protocol exploit, so the team is ready before an incident, not during one.
- Stay hands-on—threat modeling, security reviews, and red-team exercises—and coordinate external audits and bug bounties to raise the bar company-wide.
- Work with the infrastructure and L1 teams so that node and validator operations resist compromise and upgrades ship safely.
Requirements
Must Have - Extensive security engineering, with deep infrastructure security and SecOps expertise at scale—and the application-security breadth to raise the bar across product teams.- Hands-on securing and operating production systems—Linux internals, networking, containers/Kubernetes, IaC.
- Track record defining and implementing security policies an engineering org actually adopts.
- Key management at depth: signing workflows, HSMs, secrets management, key generation/rotation/recovery.
- Strong incident response leadership: detection, containment, forensics, postmortems.
- Cryptography fundamentals as applied to blockchain and key management.
- Senior-level ownership and judgment; clear communication and the ability to influence without authority.
- Comfortable in high-stakes environments.
- Genuine interest in crypto and on-chain systems. Nice to Have - Securing blockchain L1/L2 node and validator infrastructure.
- Multisig governance and treasury operations in production.
- EVM, smart contract security, and DeFi attack surfaces (MEV, bridges, oracles).
- Coordinating external audits, bug bounties, and responsible disclosure.
- Red teaming, offensive security, or detection engineering.
- High-throughput or low-latency systems where security can't compromise performance.
- Ownership and autonomy:A lean team that optimizes for individual impact and velocity.
- Outcome-oriented: We take on hard technical problems, but the tech is always a means to an end. What matters is what ships and the impact it has, not cleverness for its own sake.
- Best tool for the job: We solve interesting problems in the simplest way possible.
How to Stand Out
- Show concrete blockchain security contributions: Fork a high‑profile open‑source security tool (e.g., OpenZeppelin Defender, Slither, or Certora), submit a pull request that adds a performance‑aware check (like gas‑optimized re‑entrancy detection), and include the PR link and any measurable impact (e.g., “reduced false‑positive rate by 22%”). This demonstrates both security depth and alignment with Somnia’s focus on hyper‑performance L1.
- Create a performance‑oriented threat model for a validator layer: Draft a 1‑page threat model that maps out attack vectors on consensus, state‑sync, and agent‑execution pipelines, then propose mitigations that leverage low‑latency Rust/Go primitives (e.g., SIMD‑accelerated BLS signatures). Bring this to the interview and be ready to walk through your assumptions and trade‑offs.
- Bundle a “real‑time audit” case study: Pick a recent public L1 or DeFi protocol, run a full audit using tools like MythX, Echidna, and a custom fuzz harness written in Rust, and present the results in a concise slide deck (scope, findings, performance impact of fixes, and timeline). Highlight how you kept the audit under a tight deadline while preserving throughput—key for Somnia’s autonomous agents.
- Demonstrate remote security leadership: Prepare a brief incident‑response runbook that shows how you’d coordinate async teams across time zones using Slack/Discord, Notion for runbooks, Linear for ticket triage, and GitHub Actions for automated post‑mortem reporting. Share a screenshot or excerpt in your portfolio to prove you can lead a distributed security org effectively.
- Negotiate with token‑aligned compensation: Research recent security‑lead offers at Web3 firms (base $250‑300k + 0.5‑2% token grants) and prepare a one‑pager that ties a performance‑based equity schedule to Somnia’s token economics (e.g., vesting accelerated on achieving zero‑critical‑vuln milestones). Present this during the offer stage to secure a package that reflects both market rates and Somnia’s on‑chain growth incentives.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.