Phantom logo

Phantom

Staff Product Security Engineer (Security)

Work from homeNew this week

Remote role where the employee must remain based in a particular country.

United States only

Employer listed it 2 days ago · Added yesterday

First listed 2 days ago.

Salary

$200,000–$250,000 a week

Location

United States only

Timezone

Not stated

Contract

Full-time

Experience

Lead

Category

Software

Stated by the employer in the job description

Remote flexibility

Work from home

This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "Remote"
  • Job description states: "open to candidates based in the US"

What Nomaders makes of it

  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

Phantom is on a mission to connect the world to the freedom of open markets. Tens of millions of people all over the world use Phantom to access global markets that never close, including perpetuals, prediction markets, tokenized assets, stablecoins and memes. Phantom users are able to discover the markets that matter and the cultural moments that shape them, building conviction through real-time data and the verified performance of top traders. With self-custody and access to open networks at its core, Phantom lets them control their financial moves in the same app they use to safely store or spend money worldwide.

Phantom has reached #1 in Google Play's finance category and consistently ranks in the top 50 apps across all categories. Phantom partners with many of the most trusted and influential names in finance like Hyperliquid, Stripe, Kalshi and Visa, to make the most popular and innovative financial products accessible to everyone.

We are around 180 people, fully remote, backed by a $150M Series C investment from a16z, Sequoia Capital and Paradigm.

Security is core to Phantom’s product and the trust millions of users place in us. We’re building an AI-native security team that aggressively uses AI to expand the speed, depth, and reach of our work—from code review and threat modeling to vulnerability discovery and security automation. We’re looking for strong security engineers with high agency who can identify the risks that matter, build practical solutions, and take ownership from initial discovery through verified remediation.

This is a hands-on, high-impact role spanning architecture, source code, testing, and production systems across Phantom’s mobile, web, and backend products. You’ll work directly with engineering and product teams, lead complex security initiatives, and build capabilities that scale across the company. At the Staff level, you’ll set technical direction and raise the bar for how Phantom designs, builds, and ships secure products.

This role is fully remote and open to candidates based in the US, UK and Canada.

Responsibilities

Product Security Ownership: Partner with engineering teams to identify and address security risks across Phantom’s mobile applications, web products, APIs, and backend services.

Architecture and Threat Modeling: Lead security reviews for new products and major architectural changes, with particular attention to authorization boundaries, sensitive data, transaction integrity, key material, and third-party integrations.

Secure Product Development: Embed practical security controls into the software development lifecycle, from design and implementation through testing, release, and production operation.

Code Review and Security Testing: Perform AI assisted security code reviews and targeted testing of high-risk features. Build repeatable approaches that help find vulnerabilities before they reach production.

Security Tooling: Develop and improve tooling that gives engineers fast, actionable security feedback without creating unnecessary friction. Use automation and AI-assisted workflows where they materially improve coverage or speed.

Software Supply Chain Security: Harden CI/CD, build, and release systems against supply chain threats, including dependency risk, secrets exposure, build provenance, artifact integrity, and compromised developer or automation workflows.

Vulnerability Management: Triage findings from internal testing, researchers, bug bounty submissions, and third-party assessments. Work with owners to determine real-world impact and drive issues through verified remediation.

Incident Response: Support the investigation of product security incidents and suspicious activity. Turn lessons from incidents into durable improvements to product architecture, detection, and engineering standards.

Technical Leadership: Establish product security patterns and expectations across engineering. At the Staff level, lead ambiguous, cross-functional initiatives and influence architecture beyond any single product team.

Qualifications

5+ years of experience in product security, application security, security engineering, or software engineering, including experience operating at a senior or staff level.

Strong understanding of web, mobile, API, and distributed-system security, including authentication, authorization, session management, cryptography, and common vulnerability classes.

Hands-on experience building or applying AI-assisted security tooling to test applications and APIs, combining automated analysis with source-code review and manual validation.

Demonstrated ability to review production code in one or more languages such as TypeScript, JavaScript, Rust, Python and Go.

Experience securing software supply chains and CI/CD systems, including dependencies, build infrastructure, secrets, artifacts, signing, and release integrity.

Experience threat modeling complex products and translating security risks into concrete engineering requirements.

Strong judgment when evaluating exploitability, business impact, and appropriate remediation.

Requirements

  • ·5+ years of experience in product security, application security, security engineering, or software engineering, including experience operating at a senior or staff level.
  • ·Strong understanding of web, mobile, API, and distributed-system security, including authentication, authorization, session management, cryptography, and common vulnerability classes.
  • ·Hands-on experience building or applying AI-assisted security tooling to test applications and APIs, combining automated analysis with source-code review and manual validation.
  • ·Demonstrated ability to review production code in one or more languages such as TypeScript, JavaScript, Rust, Python and Go.
  • ·Experience securing software supply chains and CI/CD systems, including dependencies, build infrastructure, secrets, artifacts, signing, and release integrity.

Benefits

  • ·Competitive salary and equity
  • ·Eligibility to participate in the company’s performance bonus program
  • ·Comprehensive medical, dental, and vision insurance with 100% coverage
  • ·Stipend for your ideal remote setup
  • ·Flexible hours and a supportive remote environment

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Phantom, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 2d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$200,000–$250,000 a week · You'll be taken to the employer's careers page.