Head of Blockchain Security
Summary
CoinDesk is hiring a Head of Blockchain Security in New York to own the security posture of blockchain infrastructure, custody systems, and smart contract protocols. Day to day this means leading audits of Solidity/Rust/Move contracts, building monitoring and automated detection systems, assessing custody and treasury controls, and running incident-response workflows.
You will own and strengthen the end-to-end security posture of blockchain infrastructure, custody systems, and smart contract protocols. You will lead smart contract reviews and audits, build monitoring and automated detection systems, advise stakeholders on technical risks, assess custody and treasury controls, and operate emergency-response workflows.
Responsibilities
- Lead architectural reviews and security audits of Solidity, Rust, and Move smart contracts
- Oversee external third-party audits for high-complexity releases
- Produce prioritized technical risk reports and advise protocol founders, engineering leads, and executive leadership
- Build, deploy, and maintain blockchain monitoring, alerting, and automated detection systems
- Design and operate automated emergency exit workflows
- Facilitate incident-response tabletop exercises
- Assess institutional custody systems, treasury controls, and third-party vendor infrastructure
- Build scalable security frameworks and processes
Requirements
- 7+ years of cybersecurity experience, including 5+ years in blockchain and smart contract security
- Experience assessing smart contracts written in Solidity, Rust, and/or Move
- Knowledge of C/C++, Linux, and cloud-native architectures including AWS, Azure, and GCP
- Senior-level penetration testing, application security, offensive security methodologies, design reviews, and threat modeling experience
- Expertise in applied cryptography, PKI, encryption, and network and protocol fundamentals
- Knowledge of institutional custody infrastructure and DeFi protocols across Ethereum, Solana, Stacks, and Sui
- Ability to communicate critical risks to technical and non-technical stakeholders
