The world of digital assets is accelerating in speed, magnitude, and complexity, opening the door to new ways for leveraging the blockchain. Fireblocks’ platform and network provide the simplest and most secure way for companies to work with digital assets and it trusted by some of the largest financial institutions, banks, globally-recognized brands, and Web3 companies in the world, including BNY Mellon, BNP Paribas, ANZ Bank, Revolut, and thousands more.
The Security & Information team is looking for someone who is passionate about technology and has a roll-up-their-sleeves mentality to join our global team. You’ll play a crucial role in enhancing our security infrastructure, improving networking, ensuring scalability, and maintaining strong security as we continue to grow. If you want to be an industry leader, on a team experiencing hyper-growth, look no further!
What you’ll do
In this role, you will:
- Secure our infrastructure: Manage and administer various security platforms, technologies, and tools.
- Guide the team: Provide expert advice and support to the team on complex security matters.
- Leverage AI & ML: Use Machine Learning and Generative AI to automate workflows and build intelligent, proactive security solutions.
- Manage threats: Quickly identify breach attempts, contain and eradicate threats, and streamline incident response processes.
- Drive continuous improvement: Continuously test our security controls and leverage threat intelligence to help the business make informed decisions.
This is a hybrid position requiring regular on-site presence at our New York office. Must be located in the New York metropolitan area or willing to commute.
Responsibilities
- Investigate alerts, triage, deep dive, and come up with proper action items and remediation plans, leveraging AI-driven insights for faster context gathering and alert prioritization.
- Perform host-based analysis, artifact analysis, and malware analysis in support of security investigations and incident response.
- Coordinate investigation, containment, and other response activities with business stakeholders and groups.
- Develop incident analysis and findings reports for management, including gap identification and recommendations for improvement.
- Recommend or develop new detection logic and tune existing sensors/security controls, incorporating machine learning models to reduce false positives and improve detection efficacy.
- Work with security solutions owners to assess existing security solutions' ability to detect/mitigate advanced TTPs, identifying opportunities to augment traditional controls with AI-based defenses.
- Occasional weekend and on-call support is required.
Minimum Requirements
- 4+ years experience working in an Incident Response/Cyber Security Operations Center (in-house or outsourced) creating, escalating, and managing security incidents, utilizing both traditional and AI-augmented SOC tools.
- Managing low to high-risk cybersecurity alerts, and incidents, leveraging ML&AI-based anomaly detection for efficient monitoring and analysis, and responding to security threats.
- Collaborating with stakeholders to drive incident response and remediation.
- Development of common runbooks for most frequent or critical incident types.
- 3+ years of working with security tools such as SIEM, Analytics & Intelligence, Intrusion Detection, Malware detection, Data Loss Protection, and Identity & Access Management
- Familiarity with cloud services, Kubernetes, cloud environment architecture, and the major cloud providers (AWS, GCP, Azure)
- Solid understanding of system and security controls on at least two OSs (Windows, Linux / Unix, and MacOS (Advantage), including host-based forensics and experience with analyzing OS artifacts.
- Problem solver, an in-depth thinker with a growth mindset, and a strong drive to integrate AI and machine learning into daily security operations.
Preferred Qualifications
- Experience with developing or integrating AI-driven tools (e.g., leveraging LLMs or ML models) to automate and enhance SecOps workflows, such as threat hunting or alert triaging.
- Bachelor's degree in Computer Science, Information Technology, or related fieldץ
- Familiarity with Infrastructure as Code (IaC) and DevSecOps practices, including monitoring controls across CI/CD pipelines.
Fireblocks' mission is to enable every business to easily and securely access digital assets and cryptocurrencies. In order to do that, we strongly believe our workforce should be as diverse as our clients, and this is why we embrace diversity and inclusion in all its forms.

