Cybersecurity Engineer (Security Lead) for P2P Blockchain tutoring platform (equity based)
🌐 Remote💼 Full-time🗓 2026-06-25
Rewrite
## About the role
APOLO P2P is the first global peer-to-peer tutoring marketplace focused exclusively on blockchain and cryptocurrency education.
The platform delivers live one-to-one tutoring sessions inside an integrated collaborative environment that includes video calls, shared browser sessions, collaborative code editors, whiteboards, trading charts, and document collaboration tools.
We are currently seeking a Cybersecurity Engineer / Security Lead to take ownership of security across the entire APOLO ecosystem.
This is not a passive advisory role. This is a hands-on ownership role responsible for defining, implementing, monitoring, and continuously improving the security posture of the platform across infrastructure, backend systems, DevSecOps, operational workflows, and application security.
## Working Structure
- Equity-based founding-stage position
- Fully remote
- Team collaboration is synchronous, not asynchronous
- Core working hours are Monday to Friday from 4:00 PM UTC to 7:00 PM UTC
- Direct collaboration with Backend, DevOps, QA, Product, and Founder-level leadership
- Long-term strategic role with major ownership over platform security architecture
## Role Overview
The Cybersecurity Engineer / Security Lead will be responsible for securing the APOLO platform end-to-end, including:
- Application security
- Infrastructure security
- DevSecOps integration
- Monitoring and incident response
- Authentication and authorization systems
- Real-time collaboration security
- Payment-related security flows
- User trust and abuse prevention systems
You will help design and enforce security standards across all technical departments while proactively identifying vulnerabilities, abuse vectors, operational risks, and architectural weaknesses.
APOLO operates on self-hosted infrastructure and internal operational systems rather than managed enterprise cloud ecosystems. The environment includes technologies such as:
- Django backend systems
- React frontend systems
- PostgreSQL databases
- Hetzner-hosted infrastructure
- Docker-based services
- Self-hosted operational tooling
- Internal collaborative systems and communication platforms
## Key Responsibilities
### Security Architecture & Platform Ownership
- Define and maintain the platform's overall security architecture
- Identify and prioritize security risks across infrastructure, backend systems, frontend systems, APIs, operational tools, and user flows
- Establish secure architectural standards for:
- Authentication
- Authorization and RBAC systems
- Session management
- File uploads and attachments
- Real-time collaborative environments
- User-generated content
- Conduct threat modeling during feature planning and development phases
- Define and enforce secure development practices across engineering teams
- Maintain ownership of security-related technical decisions
### Application Security (AppSec)
- Design and enforce protections against:
- SQL injection
- Command injection
- XSS
- CSRF
- Session hijacking
- Account takeover attempts
- API abuse
- Privilege escalation
- Design secure API standards including:
- Authentication systems
- Token handling
- Rate limiting
- Input and output validation
- Abuse prevention mechanisms
- Audit backend and frontend application flows for:
- Logic vulnerabilities
- Data exposure risks
- Abuse scenarios
- Misconfiguration risks
### Payment & Transaction Security
- Help secure integrations with:
- Fiat payment providers
- Cryptocurrency payment providers including NOWPayments
- Ensure secure handling of:
- Webhooks
- Transaction verification
- Payment confirmation flows
- Design safeguards against:
- Fraudulent transactions
- Replay attacks
- Fake confirmations
- Abuse of wallet or session flows
### Identity & Trust Systems
- Help secure tutor onboarding, KYC verification flows, and user trust systems
- Protect systems related to:
- Proctoring
- Video storage
- Identity validation
- Tutor verification
- Design safeguards against:
- Fake tutor accounts
- Identity spoofing
- Session impersonation
- Unauthorized access to recordings or sensitive user information
### DevSecOps & Secure Development Lifecycle
- Integrate security processes into development and deployment pipelines
- Implement and maintain:
- Dependency scanning
- Secret detection
- Static analysis workflows
- Secure configuration standards
- Collaborate closely with DevOps to maintain:
- Secure infrastructure configurations
- Environment isolation
- Access management policies
- Secure deployment practices
### Infrastructure Security
- Define access control policies for:
- Servers
- Databases
- Internal systems
- Administrative tools
- Audit infrastructure for:
- Exposure risks
- Misconfigurations
- Unauthorized access paths
- Help define:
- Firewall rules
- Network segmentation
- Internal security standards
- Zero-trust principles where appropriate
### Monitoring, Logging & Incident Response
- Define security monitoring strategies and alerting systems
- Implement and maintain:
- Centralized logging
- Alerting workflows
- Security event visibility
- Lead incident response processes including:
- Detection
- Containment
- Investigation
- Remediation
- Post-incident analysis
### Security Testing & Auditing
- Conduct regular security assessments and vulnerability reviews
- Coordinate or execute penetration testing activities
- Identify and prioritize:
- Security weaknesses
- Mitigation plans
- Remediation priorities
- Continuously improve the platform's security posture as the platform scales
### Internal Security Policies & Collaboration
- Define internal operational security standards and policies
- Help establish policies related to:
- Acc
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.