Principal Security Engineer, Detection & Response
Overview
As a Principal Security Engineer at Circle, you will steer detection and response across blockchain, cloud, and AI surfaces to protect Circle’s platform and customers. You’ll lead security initiatives that span USDC issuance, Arc, and our AWS-based infrastructure, shaping how we detect and respond to complex threats. You will collaborate with cross-functional teams, own key security deliverables, and mentor others in a fast-evolving environment. Your work will directly influence the resilience of Circle’s security program and its mission to enable a more open digital economy.
ResponsibilitiesIdentify and respond to emerging security threats across cloud, endpoint, blockchain, and AI domainsBuild detection and response for blockchain/crypto-native threats (on-chain anomalies, wallet abuse, smart contract abuse)Develop cloud-native detection (IAM, identity federation, container lateral movement, runtime exploitation, misconfigurations)Extend AI risk detection (shadow AI, unauthorized AI integrations, MCP/tool abuse)Advance AI deployment to SOC workflows (detection triage, enrichment, analyst acceleration)Maintain core tooling (SIEM and orchestration platforms)Identify gaps and work with partners to improve visibility through logging and detectionLead incidents and coordinate cross-team investigationsDevelop detection techniques for anomalous behaviors and attacksProvide security guidance across the organizationSupport threat modeling, vulnerability scans, audits, and custom tool buildingTake on-call shifts (every 3rd week, occasional weekends)Lead and respond to incidents with collaboration across teamsEnsure detection coverage and incident responsiveness across environmentsMentor and collaborate with security teammates
Key requirements10+ years of experience in detection, response, or security engineering3+ years of experience commanding security incidents involving engineering teamsDeep cloud security knowledge in AWS (IAM, identity federation, KMS, EKS) and CSPM tooling (e.g., Wiz)Experience with blockchain/crypto-native threats (wallet/custody attack patterns, on-chain monitoring, smart contract abuse)Hands-on experience with AI tooling to address threats and manage risks like shadow AI and agentic workflowsExtensive knowledge of SIEM, Case Management, and SOAR solutions (e.g., Panther, Tines)Programming experience in Python, Golang, or similarExperience with Detections As CodeStrong collaboration, multi-tasking, and communication skillsFamiliarity with macOS file systems and memory, and general security toolingcollaborative under pressurestrong communicationself-motivated problem-solverAWS security (IAM, KMS, EKS)GCP/OCI familiarity (preferred)blockchain security and on-chain monitoring