Staff Security Engineer, Threat Detection & Response

Remote (USA)

Gemini

Gemini makes crypto simple. Buy, Sell and Store over 70 coins including bitcoin on the trusted crypto-native finance platform. Become a crypto investor today.

View all jobs at Gemini

Apply now Apply later

About the Company

Gemini is a global crypto and Web3 platform founded by Tyler Winklevoss and Cameron Winklevoss in 2014. Gemini offers a wide range of crypto products and services for individuals and institutions in over 70 countries.

Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build crypto products that are simple, elegant, and secure. Whether you are an individual or an institution, we help you buy, sell, and store your bitcoin and cryptocurrency. 

At Gemini, our mission is to unlock the next era of financial, creative, and personal freedom.

The Department: Threat Detection & Response

The Role: Staff Security Engineer

Gemini is seeking a Staff Threat Detection & Response Engineer with a strong background in Site Reliability Engineering (SRE) or Systems Engineering to join our Threat Detection & Response (TDR) team. This hybrid role is designed for a versatile security professional who will actively participate in incident response and alert triage, while also owning and advancing the core infrastructure, tools, and platforms that power our TDR operations.

This engineer will be deeply embedded in the TDR mission, sharing on-call responsibilities and engaging in front-line security operations. At the same time, they will serve as the team's foremost expert in systems reliability and engineering, leading high-impact projects involving observability, automation, and infrastructure that improve our security response capabilities.

Responsibilities:

  • Participate in the TDR on-call rotation and contribute to detection, triage, and incident response workflows
  • Design, implement, and maintain the systems and platforms used in threat detection and response, such as Crowdstrike, Splunk, osquery, and XSOAR
  • Improve reliability, scalability, and performance of TDR tooling and data pipelines across AWS, Kubernetes, and other cloud-native environments
  • Automate repetitive processes and enhance alerting, logging, and monitoring for TDR infrastructure
  • Collaborate with other teams to improve integrations between security tools and the broader Gemini ecosystem

Minimum Qualifications:

  • Significant professional experience in both security operations (e.g., detection engineering, incident response, alert triage) and systems engineering or SRE roles
  • Proficiency with infrastructure as code and cloud-native environments, especially AWS and Kubernetes
  • Strong coding skills in Python or similar languages used for automation and system tooling
  • Experience with tools such as Splunk, Crowdstrike, osquery, and SOAR platforms
  • Comfortable participating in on-call rotations and rapidly responding to security incidents
  • Excellent problem-solving skills and ability to work independently in a fast-paced environment

Preferred Qualifications:

  • Experience designing and maintaining CI/CD pipelines for security tooling
  • Familiarity with workflow orchestration tools like Airflow or Argo
  • Deep understanding of logging, metrics, and monitoring systems, including data pipelines
  • Contributions to open source security or infrastructure tools
  • Prior experience in fraud detection or insider threat programs
  • Ability to mentor and up-skill teammates in systems and platform engineering practices
It Pays to Work Here   The compensation & benefits package for this role includes:
  • Competitive starting salary
  • A discretionary annual bonus
  • Long-term incentive in the form of a new hire equity grant
  • Comprehensive health plans
  • 401K with company matching
  • Paid Parental Leave
  • Flexible time off

Salary Range: The base salary range for this role is between $172,000 - $241,000 in the State of New York, the State of California and the State of Washington. This range is not inclusive of our discretionary bonus or equity package. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.

In the United States, we have a flexible hybrid work policy for employees who live within 30 miles of our office headquartered in New York City and our office in Seattle. Employees within the New York and Seattle metropolitan areas are expected to work from the designated office twice a week, unless there is a job-specific requirement to be in the office every workday. Employees outside of these areas are considered part of our remote-first workforce. We believe our hybrid approach for those near our NYC and Seattle offices increases productivity through more in-person collaboration where possible.

At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.

#LI-JS2

Apply now Apply later
Job stats:  1  0  0

Tags: Automation AWS CI/CD Cloud CrowdStrike Crypto Incident response Kubernetes Monitoring Open Source Python SOAR Splunk Threat detection XSOAR

Perks/benefits: Competitive pay Equity / stock options Flex vacation Health care Parental leave Salary bonus

Regions: Remote/Anywhere North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.