Security Engineer
You will audit Move modules, protocol code, and consensus and networking layers for vulnerabilities. You will build security tooling, lead formal verification and threat-modeling work, manage bug bounty triage, coordinate incident response, and work with engineers and external security researchers to improve protocol security.
Responsibilities
- Audit Move modules, Solidity and Rust protocol code, and consensus and networking layers for vulnerabilities
- Design and build fuzzers, invariant tests, static analyzers, formal specifications, and runtime monitoring
- Drive formal verification using the Move Prover and write specifications for critical modules
- Threat-model consensus, execution, data availability, bridges, RPC, and validator infrastructure
- Use AI to scale code review, vulnerability triage, and exploit-pattern detection
- Own the bug bounty program and turn findings into fixes and regression tests
- Lead security incident response, root-cause analysis, post-mortems, and disclosure coordination
- Partner with engineering teams on secure-by-default APIs, code-review standards, and threat models
- Engage with auditors, researchers, white-hats, and the Move security community
- Monitor threats including bridge exploits, MEV, signature malleability, oracle manipulation, governance attacks, and validator collusion
Requirements
- Demonstrated record of finding real vulnerabilities through audit reports, CVEs, bug bounties, security research, or CTF results
- Code-level security skills for Move modules or Solidity codebases
- Understanding of at least one smart contract VM: Move, EVM, or SVM
- Ability to write Move, Solidity, Rust, or Python for security tooling
- Knowledge of smart contract vulnerabilities, consensus security, BFT failure modes, cryptographic primitives, bridge security, and cross-chain security
- Experience with adversarial security analysis and security tooling automation