Application Security Engineer
You will review source code, smart contracts, and protocol changes to identify and mitigate security risks. You will conduct threat modeling and architecture reviews, manage bug bounty reports, coordinate third-party audits, build security automation, research relevant attacks, and support application-layer incident investigations.
Responsibilities
- Perform security reviews of source code, smart contracts, and protocol changes
- Participate in design and architecture reviews and threat-model new products and features
- Triage and validate bug bounty reports, assess severity, and coordinate remediation
- Scope external security audits and work with third-party auditors to resolve findings
- Build and operate security automation for code review, scanning, and findings triage
- Research EVM, bridge, and peer-to-peer attack techniques and implement defenses
- Support application-layer incident investigations
Requirements
- 3+ years of experience in Application Security or Security Engineering
- Knowledge of OWASP Top 10 and secure code review in Java
- Knowledge of at least one of TypeScript, JavaScript, Python, Go, or Rust
- Hands-on blockchain security experience, including Solidity/EVM smart contract auditing or protocol/node-level security
- Experience with security automation, AI-assisted workflows, SAST/DAST, dependency scanning, secret scanning, and CI/CD security gates
- Fluent English
- Background and reference checks to validate experience, qualifications, location, and professional history
Benefits
- 100% remote work
- Access to global coworking spaces
- Paid vacation
- Paid sick leave