Staff Security Engineer @ Polymarket¶
Current Focus: Exchange Security Architecture, Security Operations & Supply Chain Integrity
Jul 2026 – Present · Remote
At Polymarket, the world's largest prediction market, I work within the security team defending a hybrid on-chain/off-chain exchange where markets settle real-world outcomes with real money at stake — alongside the US-regulated venue operating under the same roof. The attack surface spans the full spectrum: non-custodial smart contract infrastructure on Polygon (CTF Exchange), operational key material, a high-traffic web frontend, a multi-account cloud estate, and the vendor ecosystem behind all of it. My focus is helping make every layer of that surface hostile territory for an attacker — from the signing ceremony to the browser.
Security Operations & Detection¶
- SOC Operations — Cortex XSIAM & XDR: Triaging cases on the Cortex XSIAM platform end to end: causality-chain analysis to establish what actually executed, alert and IOC correlation, MITRE ATT&CK mapping, and true-positive / false-positive / benign-positive dispositioning. Response is scoped deliberately by blast radius and reversibility — the cheap reversible containment action first, the disruptive one only when the evidence carries it.
- Threat Hunting: Proactive hunting with XQL across endpoint, identity, and cloud telemetry, turning hunt results into standing detection content rather than one-off answers.
- Detection Engineering & Response Automation: Building and tuning detection rules and response playbooks, with a bias toward behavioural logic over static indicators that age out within weeks. On top of that sits an AI-assisted triage layer — an agent that digests an open case into a prioritised brief with a recommended disposition and fix-owner routing, while a human remains on every action that changes state. Read-only by design: the machine reads and reasons, the analyst executes.
- Nation-State Threat Research: Reverse engineering malware campaigns from actors targeting the crypto space — prioritising behavioural analysis over short-lived static indicators. I translate that tradecraft into durable detection logic that breaks the threat chain at execution time rather than after compromise.
- Incident Response: Response operations tuned to the current Web3 threat landscape — nation-state actors targeting key material, supply chain compromise of third-party scripts, and social engineering against privileged operators — with playbooks designed to kill the threat chain before funds move.
Exchange & Protocol Security¶
- Cryptographic Key Management: Architecting HSM-backed signing infrastructure for operational wallets — hardware-enforced key custody, policy-based transaction approval workflows, wallet segmentation by blast radius, and quorum controls that ensure no single compromised credential can move funds.
- On-Chain Threat Detection: Building monitoring coverage for the CTF Exchange architecture — order settlement correctness, atomic swap invariants between outcome tokens and collateral, operator key behaviour, and oracle-resolution integrity for market settlement. Correlating on-chain signals with infrastructure telemetry to separate real exploit activity from noise.
- Regulated Venue Security: Supporting the security of a US-regulated derivatives exchange stack — clearing, matching, FIX/ISV connectivity, and regulatory reporting — where the control expectations, change-management discipline, and evidentiary bar differ materially from crypto-native infrastructure.
Application, Cloud & Supply Chain¶
- Frontend & Supply Chain Integrity: Hardening the web application delivery pipeline against client-side attacks: Subresource Integrity (SRI) enforcement, strict Content Security Policy, third-party JavaScript governance, dependency pinning and provenance verification, and CI/CD pipeline integrity controls — treating the frontend as a first-class attack surface, not an afterthought.
- Application Security at Estate Scale: Security sweeps across an estate of hundreds of repositories spanning two GitHub organisations — org-wide secret scanning, static analysis, dependency and provenance auditing — plus the attribution work of establishing which team actually owns a given asset before a finding can be routed anywhere.
- Cloud Security at Organisation Scale: Working across a multi-account AWS Organization federated through IAM Identity Center, including cross-account asset attribution during triage — answering "which account owns this IP, this domain, this load balancer" as a prerequisite to responding to anything.
- Bug Bounty Program Operations: Running the receiving end of the public Cantina bug bounty program — first-pass triage of inbound findings, severity calibration and dispute handling, duplicate detection, routing by ownership across application and protocol teams, and researcher communication.
- Vendor & Third-Party Risk: Establishing security review gates for every external dependency that touches production — from npm packages to SaaS integrations — because in Web3, your perimeter includes everyone you trust.
Technical Stack¶
- Detection & Response: Cortex XSIAM, Cortex XDR, XQL, MITRE ATT&CK, detection engineering, response playbooks, AI-assisted triage automation.
- Security Architecture: HSM/KMS signing architectures, quorum and policy controls, CSP/SRI tooling, secret scanning, SAST.
- Web3: Solidity, Smart Contract Auditing, CTF/ERC-1155 outcome tokens, EIP-712 signed orders, Oracle security (UMA OO).
- Cloud & Ops: AWS (multi-account Organizations, IAM Identity Center), K8s, Docker, CI/CD supply chain security.
- Languages: Python, Solidity, TypeScript.