Senior IT Security Engineer
Job Description
WHO WE ARE The Solana Foundation is a non-profit based in Zug, Switzerland, dedicated to the adoption, decentralization, and security of the Solana network. Solana is a high performance blockchain that can deliver a fast and friendly user experience, without sacrificing security. The Solana Foundation is working to realize a world where individuals own their data, use permissionless networks, and transfer information and value freely around the world. We are looking for talented people who are willing to jump right in and use their expertise to help the ecosystem build. THE OPPORTUNITY Solana Foundation is seeking a Senior IT Security Engineer to own and mature our enterprise security program. You'll be the primary owner of identity, endpoint, and SaaS security across a global team — managing everything from Okta, EDR, and MDM to the secure configuration of our cloud and developer infrastructure. This is a hands-on, high-ownership role for someone who has built and run enterprise security programs before and is ready to apply that experience to the unique risk models of web3. This individual will work closely with the CISO to implement defined security strategy and with operations teams and engineering teams to deliver security approaches that protect critical assets and enable company execution at the speed of crypto. TO BE SUCCESSFUL IN THIS ROLE YOU WILL: - Own deployment, configuration, and ongoing management of our centralled identity and access management platform - Configure and manage our EDR (endpoint detection and response) solution across the fleet - Configure and manage our MDM (mobile device management) solution and enforce secure baseline configurations - Manage secure configuration and governance across our SaaS application fleet - Collaborate with operations to ensure security is integrated across the full lifecycle of a global endpoint fleet, from procurement and dropshipping through provisioning, patching, and retirement - Implement access control systems and internal data security practices across the organization per security standards defined by the CISO - Operate vulnerability management solutions, including scanning, triage, and remediation tracking - Audit and secure the configuration of modern enterprise tech stacks including GitHub, AWS, and GCP per established security policies - Execute backup testing processes and participate in incident response efforts - Maintain and improve compliance with security frameworks such as ISO 27001 and SOC 2 YOU IDEALLY HAVE: - Strong infrastructure and enterprise security experience, including security governance, access control systems, and vulnerability management - Hands-on experience deploying and managing single-sign on solutions, EDR, and MDM tooling - Experience securing and managing a SaaS application fleet at an organization-wide scale - Experience managing a global fleet of endpoints across its entire lifecycle - Experience owning secure configuration of modern enterprise tech stacks such as GitHub, AWS, and GCP - Comfortable scripting (Python, Go, or Bash) to automate security workflows, evidence collection, and integrations across the identity, endpoint, and SaaS stack - Experience building backup processes and leading incident response - Experience working within security frameworks such as ISO 27001, SOC 2, or similar - Strong communication skills and comfort operating autonomously across time zones
Bonus Points
- Experience working across both traditional web2 operational security and crypto/web3 environments, with an understanding of how their security and risk models differ - Experience securing custody, key management, or other crypto-specific infrastructure
How to Stand Out
- Highlight hands‑on experience with Zero‑Trust architectures and modern identity platforms (e.g., Okta, Azure AD Conditional Access, Duo). In your resume and cover letter, list specific policies you authored, MFA roll‑outs you led, and measurable reductions in credential‑theft incidents—Solana’s security program expects you to own identity across a globally distributed team.
- Build a concise portfolio of “security automation” artifacts: Terraform or Ansible scripts that provision endpoint hardening, Cloud‑Security‑Posture‑Management (CSPM) rules for SaaS apps, and custom detection playbooks for SIEM tools like Splunk or Elastic. Include a GitHub repo (private link with read‑only access) and a one‑page README that explains the problem, your solution, and the impact (e.g., “cut average patch‑deployment time from 48 h to 8 h”).
- Demonstrate deep knowledge of blockchain‑related risk vectors. Prepare a short 5‑minute presentation (or a slide deck) that outlines how you would assess and mitigate threats to a high‑throughput network like Solana—covering node‑level hardening, supply‑chain security for validator software, and secure API gateway design. Bring this to the interview to show you understand the domain beyond generic IT security.
- Quantify your endpoint security achievements using concrete metrics (e.g., “implemented CrowdStrike Falcon across 1,200 devices, achieving 99.9 % detection coverage and a 35 % decrease in mean‑time‑to‑contain”). Solana’s interviewers will probe for data‑driven results, so embed numbers throughout your CV and be ready to discuss the dashboards you built to monitor them.
- When negotiating salary, reference Solana’s non‑profit status and its funding model (e.g., endowment, token‑based incentives). Research the typical range for senior security engineers in the Zurich crypto ecosystem (≈ CHF 140‑170k base plus equity or token grants) and propose a mixed compensation package that includes a modest base, performance‑based token awards, and a flexible remote‑work stipend for home‑office equipment.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.