Product Security Manager
Job Description
<p><b style="font-size: 16px;">About MoonPay</b></p><p><br></p><p><span style="font-size: 16px;">Hi, weâre MoonPay. Weâre here to onboard the world to the decentralized economy by making digital money move as universally and effortlessly as the internet.</span></p><p><br></p><p><b style="font-size: 16px;">Why?</b></p><p><br></p><p><span style="font-size: 16px;">Because crypto, stablecoins and blockchain arenât just technologies. Theyâre tools for global financial empowerment. They give people and businesses more control over their money, their digital assets, and their future, opening access to legacy financial systems that have been out of reach for many.</span></p><p><br></p><p><b style="font-size: 16px;">What we do</b></p><p><span style="font-size: 16px;">MoonPay is a unified payments platform for digital currency. We make it easy for anyone, anywhere, to buy, sell, swap and pay in digital currencies as easy as sending an email. That simplicity is intentional, our focus is reducing complexity so people can participate confidently, without needing to be crypto experts. We power the entire flow between fiat and crypto end to end, with compliance, identity checks, fraud prevention, and settlement all built in. This end-to-end approach reflects how we work internally: with accountability, rigor, and trust built into everything we ship.</span></p><p><br></p><p><b style="font-size: 16px;">Proven at scale</b></p><p><br></p><p><span style="font-size: 16px;">Trusted by over 30 million customers and over 500 ecosystem partners, our secure, enterprise-grade platform is driving mainstream crypto adoption worldwide. Behind those numbers are millions of real people and organizations relying on MoonPay every day. </span></p><p><br></p><p><span style="font-size: 16px;">We collaborate with innovative brands and projects to build secure, scalable solutions for a blockchain-powered future. This is an opportunity to help shape systems, not just scale them. And weâre committed to doing it right. Fully licensed in the U.S. and regulated across the UK, EU, Canada, and Australia, because trust and compliance are non-negotiable. </span></p><p><br></p><p><span style="font-size: 16px;">But weâre just getting started. Weâve launched a consumer app that makes crypto accessible, intuitive, and usable for everyone, and itâs growing fast. Weâre iterating every day to make it the best it can be. </span></p><p><br></p><p><span style="font-size: 16px;">If you believe financial freedom should be for everyone. If you believe in building a fairer, more open financial system - we want you with us. To build systems that benefit all, we need contributions from all, regardless of background. </span></p><p><br></p><p><span style="font-size: 16px;">Come build the future of payments and the decentralized economy with MoonPay. Letâs make financial freedom and autonomy the new normal.</span></p>\n<p></p><p><br></p><b>About the Opportunity </b><div>
<p>As the Product Security Manager, you will play a pivotal role in securing the infrastructure that powers the Web3 economy. You will lead and scale two high-impact teams: Application Security and Vulnerability Management & Automation.</p>
<br>Your mission is to ensure that security is woven into the fabric of our product development lifecycle, empowering our engineers to build fast without compromising on safety. You will be a mentor, a strategist, and a leader helping MoonPay maintain its reputation as the most trusted brand in the space.<br><br>You are a natural leader able to influence different parts of the business with security initiatives and negotiate the best security solutions for new challenges and unexplored territories</div><p><br></p><b>What you will do</b><div>
<ul>
<li>
<p><strong>Lead and Mentor:</strong> Oversee the day-to-day operations and career development of the Application Security and Vulnerability Management & Automation teams.</p>
</li>
<li>
<p><strong>Security Strategy:</strong> Define the roadmap for product security, focusing on scalable automation and proactive defense mechanisms.</p>
</li>
<li>
<p><strong>Vulnerability Management:</strong> Drive the end-to-end lifecycle of vulnerability discovery, triaging, and remediation across our entire ecosystem.</p>
</li>
<li>
<p><strong>Application Security: </strong>Improve security tooling (SAST, DAST, SCA) into CI/CD pipelines and lead threat modeling sessions and penetration testing for new features.</p>
</li>
<li>
<p><strong>Cross-Functional Collaboration:</strong> Partner with Engineering and Product leaders and help and influence with security topics new business units and acquisitions to prioritize security debt and promote a culture of Security by Design.</p>
</li>
<li>
<p><strong>Incident Response:</strong> Lead high-priority security incidents and investigations and improve processes, manage team rotas and escalations.</p>
</li>
<li>
<p><strong>Regulatory and Compliance: </strong>Support organisation maintain or acquire new critical certifications such as SOC2, PCI, CIS TOP 18, ISO27001.</p>
</li>
</ul>
</div><p><br></p><b>About You </b><div>
<ul>
<li>
<p><strong>Experienced Leader:</strong> You have a proven track record of managing technical security teams in high-growth, cloud-native environments.</p>
</li>
<li>
<p><strong>Adaptive in Ambiguity:</strong> As our team moves at a very fast pace, you must be comfortable navigating ambiguity and resolving unclear or evolving topics effectively.</p>
</li>
<li>
<p><strong>Technical Depth:</strong> You possess a strong background in application security, penetration testing and software engineering.</p>
</li>
<li>
<p><strong>Automation Mindset:</strong> You believe that manual processes are bugs and have experience building or implementing automated security scanning and reporting tools.</p>
</li>
<li>
<p><strong>Strategic Thinker:</strong> You can balance immediate tactical needs with long-term security goals.</p>
</li>
<li>
<p><strong>Web3 Enthusiast:</strong> You are curious about (or experienced in) blockchain technology, smart contract security, and the unique challenges of the Web3 landscape.</p>
</li>
</ul>
</div><p><br></p><b>What you will be working with/onâ¦</b><div>
<p>The Product Security team operates within a cutting-edge technological environment and focuses on several critical areas to ensure the highest level of security for our platform and products.</p>
<ul>
<li>
<p><strong>Modern Tech Stack and Infrastructure: </strong>We leverage an advanced cloud infrastructure designed for high scalability and resilience. Our development and deployment processes are built upon robust CI/CD environments, necessitating security integration at every stage, from code commit to production deployment. This involves securing containers, serverless components, and sophisticated cloud-native networking configurations.</p>
</li>
<li>
<p><strong>Scalable Automation Frameworks:</strong> To effectively manage security risks across a rapidly expanding codebase and infrastructure, we utilize and develop both custom-built and industry-standard tools for vulnerability management. This includes automated security testing, dependency scanning, misconfiguration detection, and streamlined vulnerability triage and remediation workflows, all designed to operate effectively at scale.</p>
</li>
<li>
<p><strong>Securing the Next Generation of Features:</strong> A major strategic focus is on securing our next generation of AI-enabled features. This involves proactive security measures related to Large Language Models (LLMs) and other AI components. Our goal is to ensure data privacy and integrity within all model interactions and maintain compliance with responsible AI principles.</p>
</li>
<li>
<p><strong>Diverse and Proactive Application Security Services:</strong> We offer a full spectrum of proactive security guidance and services tailored to the needs of various engineering and business lines. This includes comprehensive penetration testing (both internal and external), in-depth threat modeling during the design phase of new features, security architecture reviews, and the development of secure coding standards. These services are provided across a wide variety of applications and business lines, from core financial services to new user-facing products.</p>
</li>
<li>
<p><strong>Continuous Improvement and Security Posture Enhancement:</strong> We maintain a strong commitment to the principle of continuous improvement. This involves constantly exploring and identifying opportunities to level up the security posture across the entire organization. This includes enhancing tooling, refining processes, developing and delivering security training to engineering teams, and driving large-scale security initiatives.</p>
</li>
<li>
<p><strong>Secure Development Lifecycle Guidance:</strong> A core responsibility is to guide engineering teams on adopting best practices for the secure development and deployment of their applications. This encompasses promoting a security-first culture, embedding security requirements into the SDLC, providing timely consultation on security issues, and helping teams implement security controls effectively.</p>
</li>
</ul>
</div><p><br></p><p></p>\n<div>$209.66 - $220.70 a year</div>\n<p><b style="font-size: 24px">BLOCK Values </b></p><p><br></p><p><span style="font-size: 16px">Weâre looking for people who live our core values, those who strive for excellence and want to leave a lasting legacy on the global financial system. Our values:</span></p><p><br></p><p><b><span style="font-size: 16px">B</span></b><span style="font-size: 16px"> - Be Hungry</span></p><p><b><span style="font-size: 16px">L</span></b><span style="font-size: 16px"> - Level Up</span></p><p><b><span style="font-size: 16px">O</span></b><span style="font-size: 16px"> - Own It</span></p><p><b><span style="font-size: 16px">C</span></b><span style="font-size: 16px"> - Crypto Curious</span></p><p><b><span style="font-size: 16px">K</span></b><span style="font-size: 16px"> - Kaizen</span></p><p><br></p><p><span style="font-size: 16px">Research has shown that women are less likely than men to apply for this role if they do not have experience in 100% of these areas. Please know that this list is indicative, and that we would still love to hear from you even if you feel that you are only a 75% match. Skills can be learnt, diversity cannot.</span></p><p><br></p><p><span style="font-size: 24px"><b>Benefits & Perks ð¡</b></span></p><p><br></p><p><b style="font-size: 12pt">ð°</b><b style="font-size: 16px">Competitive salary package </b></p><p><br></p><p><b style="font-size: 12pt">ð¤ </b><b style="font-size: 16px">Equity package: </b><span style="font-size: 16px">We believe financial freedom starts with our employees, so all employees have ownership at MoonPay</span></p><p><br></p><p><span style="font-size: 16px">ð </span><b style="font-size: 16px">Pay for performance equity bonus: </b><span style="font-size: 16px">Those who drive outsized outcomes receive outsized rewards </span></p><p><br></p><p><b>ð <span style="font-size: 16px">Moonshot award.</span></b><span style="font-size: 16px"> We honor exceptional impact - 10 employees twice a year, each earning a $250,000 equity grant.</span></p><p><br></p><p><span style="font-size: 16px">ð </span><b style="font-size: 16px">Unlimited holidays: </b><span style="font-size: 16px">We give you the autonomy to choose when to work (and when to switch off)</span></p><p><br></p><p><span style="font-size: 16px">ð </span><b style="font-size: 16px">Hybrid working schedule: </b><span style="font-size: 16px">Work fully remotely or your nearest Moonbase, the choice is yours </span></p><p><br></p><p><span style="font-size: 16px">𩺠</span><b style="font-size: 16px">Private Healthcare benefits: </b><span style="font-size: 16px">To protect you and your loved ones </span></p><p><br></p><p><span style="font-size: 16px">ð¼ </span><b style="font-size: 16px">Enhanced parental leave: </b><span style="font-size: 16px">So you can spend more time with your loved ones without a second thought</span></p><p><br></p><p><span style="font-size: 16px">ð </span><b style="font-size: 16px">Annual training budget: </b><span style="font-size: 16px">We support your training journey every step of the way </span></p><p><br></p><p><span style="font-size: 16px">ðª </span><b style="font-size: 16px">Home office setup allowance: </b><span style="font-size: 16px">Create the home office of your dreams </span></p><p><br></p><p><span style="font-size: 16px">ð </span><b style="font-size: 16px">Remote working allowance: </b><span style="font-size: 16px">Those working fully remotely get a little extra for utilities </span></p><p><br></p><p><span style="font-size: 16px">ð° </span><b style="font-size: 16px">Monthly budget to spend on our products and zero fee crypto transactions: </b><span style="font-size: 16px">Cultivate your inner DEGEN </span></p><p><br></p><p><span style="font-size: 16px">ð° </span><b style="font-size: 16px">Employee referral programme: </b><span style="font-size: 16px">Great people know great people, refer them to receive 10K in USDC </span></p><p><br></p><p><span style="font-size: 16px">âï¸ </span><b style="font-size: 16px">Regular remote company offsites: </b><span style="font-size: 16px">Meet your colleagues regularly for high impact in person sessions and hackathons </span></p><p><br></p><p><b style="font-size: 16px">ð Working in a disruptive and fast-growing company where excellence is rewarded </b></p><p><br></p><p><br></p><p><br></p><p><b><u><span style="font-size: 18px">Commitment To Diversity</span></u></b></p><p><br></p><p><span style="font-size: 16px">At MoonPay we believe that every voice matters. We strive to create a mindful and respectful environment where everyone can bring their authentic self to work, and experience a culture that is free of harassment, racism, and discrimination. Thatâs why we are committed to diversity and inclusion in the workplace and are a proud equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status or any other characteristic protected by law. This policy applies to all employment practices within our organization, including, but not limited to, hiring, recruiting, promotion, termination, layoff, and leave of absence. </span></p><p><br></p><p><span style="font-size: 16px">MoonPay is also committed to providing reasonable accommodations in our job application procedures for qualified individuals with disabilities. Please inform our Talent Team if you need any assistance completing any forms or to otherwise participate in the application process.</span></p><p><br></p><br/><br/>Please mention the word **COMPREHENSIVE** and tag RMjYwMDoxNzAyOjJlOTA6OWJjMDplYzVkOjk3NzM6MWEyYzpkYmY1 when applying to show you read the job post completely (#RMjYwMDoxNzAyOjJlOTA6OWJjMDplYzVkOjk3NzM6MWEyYzpkYmY1). This is a beta feature to avoid spam applicants. Companies can search these words to find applicants that read this and see they're human.
Required Skills
Requirements
Employment Type
Remote
Category
security, manager, design, web3, crypto
About MoonPay
Location: United States (East Coast Time Zone) - Remote
Industry: security, manager, design, web3, crypto