
- Top 1% of respondersAPOLO - P2P CRYPTO LEARNING is in the top 1% of companies in terms of response time to applications
- Responds within a dayBased on past data, APOLO - P2P CRYPTO LEARNING usually responds to incoming applications within a day
- Early StageStartup in initial stages
- +1
Cybersecurity Engineer (Security Lead) for P2P Blockchain tutoring platform (equity based)
- 1.0% – 1.0%
- |Remote (Everywhere)
- |5 years of exp
- |Cofounder
Remote only
Not Available
About the job
***********************************IMPORTANT NOTICE
THIS IS CURRENTLY A 100% EQUITY-BASED POSITION
NO SALARY OR CASH COMPENSATION IS OFFERED AT THIS STAGE
PLEASE DO NOT APPLY IF YOU ARE NOT SPECIFICALLY LOOKING FOR AN EQUITY-BASED STARTUP OPPORTUNITY*********************************************************************
About APOLO P2P
APOLO P2P is the first global peer-to-peer tutoring marketplace focused exclusively on blockchain and cryptocurrency education.
The platform delivers live one-to-one tutoring sessions inside an integrated collaborative environment that includes video calls, shared browser sessions, collaborative code editors, whiteboards, trading charts, and document collaboration tools.
We are currently seeking a Cybersecurity Engineer / Security Lead to take ownership of security across the entire APOLO ecosystem.
This is not a passive advisory role. This is a hands-on ownership role responsible for defining, implementing, monitoring, and continuously improving the security posture of the platform across infrastructure, backend systems, DevSecOps, operational workflows, and application security.
Working Structure
• Equity-based founding-stage position
• Fully remote
• Team collaboration is synchronous, not asynchronous
• Core working hours are Monday to Friday from 4:00 PM UTC to 7:00 PM UTC
• Direct collaboration with Backend, DevOps, QA, Product, and Founder-level leadership
• Long-term strategic role with major ownership over platform security architecture
Role Overview
The Cybersecurity Engineer / Security Lead will be responsible for securing the APOLO platform end-to-end, including:
• Application security
• Infrastructure security
• DevSecOps integration
• Monitoring and incident response
• Authentication and authorization systems
• Real-time collaboration security
• Payment-related security flows
• User trust and abuse prevention systems
You will help design and enforce security standards across all technical departments while proactively identifying vulnerabilities, abuse vectors, operational risks, and architectural weaknesses.
APOLO operates on self-hosted infrastructure and internal operational systems rather than managed enterprise cloud ecosystems. The environment includes technologies such as:
• Django backend systems
• React frontend systems
• PostgreSQL databases
• Hetzner-hosted infrastructure
• Docker-based services
• Self-hosted operational tooling
• Internal collaborative systems and communication platforms
Key Responsibilities
Security Architecture & Platform Ownership
• Define and maintain the platform’s overall security architecture
• Identify and prioritize security risks across infrastructure, backend systems, frontend systems, APIs, operational tools, and user flows
• Establish secure architectural standards for:
• Authentication
• Authorization and RBAC systems
• Session management
• File uploads and attachments
• Real-time collaborative environments
• User-generated content
• Conduct threat modeling during feature planning and development phases
• Define and enforce secure development practices across engineering teams
• Maintain ownership of security-related technical decisions
Application Security (AppSec)
• Design and enforce protections against:
• SQL injection
• Command injection
• XSS
• CSRF
• Session hijacking
• Account takeover attempts
• API abuse
• Privilege escalation
• Design secure API standards including:
• Authentication systems
• Token handling
• Rate limiting
• Input and output validation
• Abuse prevention mechanisms
• Audit backend and frontend application flows for:
• Logic vulnerabilities
• Data exposure risks
• Abuse scenarios
• Misconfiguration risks
Payment & Transaction Security
• Help secure integrations with:
• Fiat payment providers
• Cryptocurrency payment providers including NOWPayments
• Ensure secure handling of:
• Webhooks
• Transaction verification
• Payment confirmation flows
• Design safeguards against:
• Fraudulent transactions
• Replay attacks
• Fake confirmations
• Abuse of wallet or session flows
Identity & Trust Systems
• Help secure tutor onboarding, KYC verification flows, and user trust systems
• Protect systems related to:
• Proctoring
• Video storage
• Identity validation
• Tutor verification
• Design safeguards against:
• Fake tutor accounts
• Identity spoofing
• Session impersonation
• Unauthorized access to recordings or sensitive user information
DevSecOps & Secure Development Lifecycle
• Integrate security processes into development and deployment pipelines
• Implement and maintain:
• Dependency scanning
• Secret detection
• Static analysis workflows
• Secure configuration standards
• Collaborate closely with DevOps to maintain:
• Secure infrastructure configurations
• Environment isolation
• Access management policies
• Secure deployment practices
Infrastructure Security
• Define access control policies for:
• Servers
• Databases
• Internal systems
• Administrative tools
• Audit infrastructure for:
• Exposure risks
• Misconfigurations
• Unauthorized access paths
• Help define:
• Firewall rules
• Network segmentation
• Internal security standards
• Zero-trust principles where appropriate
Monitoring, Logging & Incident Response
• Define security monitoring strategies and alerting systems
• Implement and maintain:
• Centralized logging
• Alerting workflows
• Security event visibility
• Lead incident response processes including:
• Detection
• Containment
• Investigation
• Remediation
• Post-incident analysis
Security Testing & Auditing
• Conduct regular security assessments and vulnerability reviews
• Coordinate or execute penetration testing activities
• Identify and prioritize:
• Security weaknesses
• Mitigation plans
• Remediation priorities
• Continuously improve the platform’s security posture as the platform scales
Internal Security Policies & Collaboration
• Define internal operational security standards and policies
• Help establish policies related to:
• Access permissions
• Administrative privileges
• Sensitive data handling
• Internal operational security
• Work closely with:
• Backend engineering
• DevOps
• QA
• Product teams
• Educate team members on secure development and operational practices
Requirements
• Strong experience in cybersecurity, application security, or security engineering
• Proven experience designing and maintaining secure architectures for production systems
• Strong understanding of:
• OWASP Top 10
• Authentication systems
• Authorization and RBAC
• API security
• Secure backend architecture
• Experience working with:
• Django
• Node.js
• Web application security
• CI/CD security integration
• Dockerized environments
• Experience with:
• Threat modeling
• Security monitoring
• Incident response
• Vulnerability management
• Strong analytical and problem-solving mindset
• Ability to proactively identify attack vectors and abuse scenarios
• Ability to work independently while collaborating closely with technical teams during synchronous working hours
Preferred Qualifications
• Experience securing self-hosted infrastructure environments
• Experience with:
• PostgreSQL security
• Reverse proxies
• Linux server hardening
• Container security
• Experience in EdTech, fintech, crypto, SaaS, or marketplace platforms
• Experience building security policies for startups or scaling platforms
• Familiarity with privacy and data protection principles
Why Join APOLO?
Joining APOLO at this stage provides the opportunity to define and own the security foundation of a global blockchain and cryptocurrency education platform from the ground up.
You will have:
• Major ownership over platform security architecture and operational security strategy
• Direct collaboration with the founding and engineering teams
• High technical influence across all infrastructure and development decisions
• Long-term strategic growth opportunities inside the company
• The opportunity to secure a next-generation educational marketplace operating in the blockchain sector
About the company

APOLO - P2P CRYPTO LEARNING
- Top 1% of respondersAPOLO - P2P CRYPTO LEARNING is in the top 1% of companies in terms of response time to applications
- Responds within a dayBased on past data, APOLO - P2P CRYPTO LEARNING usually responds to incoming applications within a day
- Early StageStartup in initial stages
- Growing fastShowed strong hiring growth in the past month