Avatar for APOLO - P2P CRYPTO LEARNING
We Have An Exclusive Investment: Unlocking Blockchain P2P Tutor/Student Potential
  • Top 1% of responders
    APOLO - P2P CRYPTO LEARNING is in the top 1% of companies in terms of response time to applications
  • Responds within a day
    Based on past data, APOLO - P2P CRYPTO LEARNING usually responds to incoming applications within a day
  • Early Stage
    Startup in initial stages
  • +1

Cybersecurity Engineer (Security Lead) for P2P Blockchain tutoring platform (equity based)

  • 1.0% – 1.0%
  • |Remote (
    Everywhere
    )
  • |5 years of exp
  • |Cofounder
Posted: 5 days ago• Recruiter recently active
Hires remotely in
Everywhere
Remote Work Policy

Remote only

Company Location
Visa Sponsorship

Not Available

Preferred Timezones
Hawaii, Alaska, Pacific Time, Mountain Time, Central Time, Eastern Time, Atlantic Time, Greenland, Brasilia Summer Time, Azores, Coordinated Universal Time, Central European Time, Eastern European Time, Turkey Time, Dubai Time, Maldives Time, Astana Time, Indochina Time, China Standard Time, Japan Standard Time, Brisbane, Vladivostok, Auckland, Wellington
Collaboration Hours
4:00 PM - 7:00 PM Coordinated Universal Time
RelocationNot Allowed
Skills
Cyber Security
Security
OWASP
Incident Response
DevSecOps

About the job

***********************************IMPORTANT NOTICE
THIS IS CURRENTLY A 100% EQUITY-BASED POSITION
NO SALARY OR CASH COMPENSATION IS OFFERED AT THIS STAGE
PLEASE DO NOT APPLY IF YOU ARE NOT SPECIFICALLY LOOKING FOR AN EQUITY-BASED STARTUP OPPORTUNITY
*********************************************************************

About APOLO P2P

APOLO P2P is the first global peer-to-peer tutoring marketplace focused exclusively on blockchain and cryptocurrency education.

The platform delivers live one-to-one tutoring sessions inside an integrated collaborative environment that includes video calls, shared browser sessions, collaborative code editors, whiteboards, trading charts, and document collaboration tools.

We are currently seeking a Cybersecurity Engineer / Security Lead to take ownership of security across the entire APOLO ecosystem.

This is not a passive advisory role. This is a hands-on ownership role responsible for defining, implementing, monitoring, and continuously improving the security posture of the platform across infrastructure, backend systems, DevSecOps, operational workflows, and application security.

Working Structure

• Equity-based founding-stage position
• Fully remote
• Team collaboration is synchronous, not asynchronous
• Core working hours are Monday to Friday from 4:00 PM UTC to 7:00 PM UTC
• Direct collaboration with Backend, DevOps, QA, Product, and Founder-level leadership
• Long-term strategic role with major ownership over platform security architecture

Role Overview

The Cybersecurity Engineer / Security Lead will be responsible for securing the APOLO platform end-to-end, including:

• Application security
• Infrastructure security
• DevSecOps integration
• Monitoring and incident response
• Authentication and authorization systems
• Real-time collaboration security
• Payment-related security flows
• User trust and abuse prevention systems

You will help design and enforce security standards across all technical departments while proactively identifying vulnerabilities, abuse vectors, operational risks, and architectural weaknesses.

APOLO operates on self-hosted infrastructure and internal operational systems rather than managed enterprise cloud ecosystems. The environment includes technologies such as:

• Django backend systems
• React frontend systems
• PostgreSQL databases
• Hetzner-hosted infrastructure
• Docker-based services
• Self-hosted operational tooling
• Internal collaborative systems and communication platforms

Key Responsibilities
Security Architecture & Platform Ownership

• Define and maintain the platform’s overall security architecture
• Identify and prioritize security risks across infrastructure, backend systems, frontend systems, APIs, operational tools, and user flows
• Establish secure architectural standards for:
• Authentication
• Authorization and RBAC systems
• Session management
• File uploads and attachments
• Real-time collaborative environments
• User-generated content
• Conduct threat modeling during feature planning and development phases
• Define and enforce secure development practices across engineering teams
• Maintain ownership of security-related technical decisions

Application Security (AppSec)

• Design and enforce protections against:
• SQL injection
• Command injection
• XSS
• CSRF
• Session hijacking
• Account takeover attempts
• API abuse
• Privilege escalation
• Design secure API standards including:
• Authentication systems
• Token handling
• Rate limiting
• Input and output validation
• Abuse prevention mechanisms
• Audit backend and frontend application flows for:
• Logic vulnerabilities
• Data exposure risks
• Abuse scenarios
• Misconfiguration risks

Payment & Transaction Security

• Help secure integrations with:
• Fiat payment providers
• Cryptocurrency payment providers including NOWPayments
• Ensure secure handling of:
• Webhooks
• Transaction verification
• Payment confirmation flows
• Design safeguards against:
• Fraudulent transactions
• Replay attacks
• Fake confirmations
• Abuse of wallet or session flows

Identity & Trust Systems

• Help secure tutor onboarding, KYC verification flows, and user trust systems
• Protect systems related to:
• Proctoring
• Video storage
• Identity validation
• Tutor verification
• Design safeguards against:
• Fake tutor accounts
• Identity spoofing
• Session impersonation
• Unauthorized access to recordings or sensitive user information

DevSecOps & Secure Development Lifecycle

• Integrate security processes into development and deployment pipelines
• Implement and maintain:
• Dependency scanning
• Secret detection
• Static analysis workflows
• Secure configuration standards
• Collaborate closely with DevOps to maintain:
• Secure infrastructure configurations
• Environment isolation
• Access management policies
• Secure deployment practices

Infrastructure Security

• Define access control policies for:
• Servers
• Databases
• Internal systems
• Administrative tools
• Audit infrastructure for:
• Exposure risks
• Misconfigurations
• Unauthorized access paths
• Help define:
• Firewall rules
• Network segmentation
• Internal security standards
• Zero-trust principles where appropriate

Monitoring, Logging & Incident Response

• Define security monitoring strategies and alerting systems
• Implement and maintain:
• Centralized logging
• Alerting workflows
• Security event visibility
• Lead incident response processes including:
• Detection
• Containment
• Investigation
• Remediation
• Post-incident analysis

Security Testing & Auditing

• Conduct regular security assessments and vulnerability reviews
• Coordinate or execute penetration testing activities
• Identify and prioritize:
• Security weaknesses
• Mitigation plans
• Remediation priorities
• Continuously improve the platform’s security posture as the platform scales

Internal Security Policies & Collaboration

• Define internal operational security standards and policies
• Help establish policies related to:
• Access permissions
• Administrative privileges
• Sensitive data handling
• Internal operational security
• Work closely with:
• Backend engineering
• DevOps
• QA
• Product teams
• Educate team members on secure development and operational practices

Requirements

• Strong experience in cybersecurity, application security, or security engineering
• Proven experience designing and maintaining secure architectures for production systems
• Strong understanding of:
• OWASP Top 10
• Authentication systems
• Authorization and RBAC
• API security
• Secure backend architecture
• Experience working with:
• Django
• Node.js
• Web application security
• CI/CD security integration
• Dockerized environments
• Experience with:
• Threat modeling
• Security monitoring
• Incident response
• Vulnerability management
• Strong analytical and problem-solving mindset
• Ability to proactively identify attack vectors and abuse scenarios
• Ability to work independently while collaborating closely with technical teams during synchronous working hours

Preferred Qualifications

• Experience securing self-hosted infrastructure environments
• Experience with:
• PostgreSQL security
• Reverse proxies
• Linux server hardening
• Container security
• Experience in EdTech, fintech, crypto, SaaS, or marketplace platforms
• Experience building security policies for startups or scaling platforms
• Familiarity with privacy and data protection principles

Why Join APOLO?

Joining APOLO at this stage provides the opportunity to define and own the security foundation of a global blockchain and cryptocurrency education platform from the ground up.

You will have:

• Major ownership over platform security architecture and operational security strategy
• Direct collaboration with the founding and engineering teams
• High technical influence across all infrastructure and development decisions
• Long-term strategic growth opportunities inside the company
• The opportunity to secure a next-generation educational marketplace operating in the blockchain sector

About the company

APOLO - P2P CRYPTO LEARNING company logo
We Have An Exclusive Investment: Unlocking Blockchain P2P Tutor/Student Potential11-50 Employees
  • Top 1% of responders
    APOLO - P2P CRYPTO LEARNING is in the top 1% of companies in terms of response time to applications
  • Responds within a day
    Based on past data, APOLO - P2P CRYPTO LEARNING usually responds to incoming applications within a day
  • Early Stage
    Startup in initial stages
  • Growing fast
    Showed strong hiring growth in the past month
Learn more about APOLO - P2P CRYPTO LEARNING image

Funding

AMOUNT RAISED
$200K
FUNDED OVER
1 round
Round
PRE
$200000
Pre-Seed - Jul 2022

Founders

Enrique Barba
Founder
Madeira
image
View the team image