Description

  • Perform security assessments on web, mobile, thick-client applications, and browser extensions.
  • Plan and execute external and internal network penetration tests.
  • Conduct security source code reviews across multiple languages and produce actionable findings.
  • Perform cloud security reviews of platforms such as AWS, Azure, and GCP.
  • Develop comprehensive penetration test reports tailored to both technical and non-technical audiences.
  • Research and develop new pentesting techniques, tools, and methodologies for applications in the blockchain/Web3 space.
  • Contribute to community-facing materials by developing tools, presentations, and blog posts.
  • Collaborate with clients and internal R&D to threat model, scan, audit, design, and enhance application security.

Requirements

  • Minimum of 4 years of experience in application security and penetration testing.
  • Passion for cryptocurrency, DeFi, and blockchain, with willingness to learn Web3 technologies such as smart contracts.
  • Experience in source code review for multiple languages, with strong understanding of JavaScript and TypeScript.
  • Experience in mobile application penetration testing.
  • Familiarity with cloud platforms and their security risks (AWS, Azure, GCP).
  • Experience programming with scripting languages such as Python and Bash.
  • Solid understanding of cryptography.
  • BS/MS/PhD in Computer Science or Information Security (or equivalent experience).
  • Strong spoken and written communication skills.
  • (Nice to have) Experience pentesting Web3 applications (crypto exchanges, wallets, DApps, key custodians), smart contract security audits, browser extension security, participation in bug bounties/audit contests, published security write-ups or talks, and certifications such as OSCP, OSWE, OSCE, or GWAPT.

Benefits

  • Target U.S. annual base salary range: $100,000 - $180,000 (final offer depends on skills and experience).
  • Remote work option (#LI-Remote).
  • Medical, vision, and dental insurance.
  • 401(k) plan with company matching.
  • Life and accidental death & dismemberment (AD&D) insurance.
  • HSA (with high deductible plan) and FSA, plus flexible paid time off and holidays.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

ingénieur de sécurité principal

Shakepay 51-250 Diversified Financial Services

Shakepay recherche un ingénieur de sécurité principal pour protéger son infrastructure, ses produits et ses données clients tout en développant ses capacités de sécurité, d’observabilité et d’intelligence artificielle dans un environnement fintech réglementé.

AWS Bitcoin Git GitHub
19 hours, 55 minutes ago

Security Software Engineer II, Detection and Response

Pinterest 5K-10K Internet Software & Services

Pinterest is hiring a Security Engineer to strengthen detection and incident response capabilities, protect employees and infrastructure, and adapt security operations to emerging threats in a cloud-first environment.

Go Network Security Python Ruby SIEM TCP/IP
20 hours, 25 minutes ago

Principal Linux Security Engineer

CIQ 51-250 Internet Software & Services

CIQ is seeking a Linux security engineer to strengthen the security, compliance, vulnerability management, and release processes for enterprise Linux infrastructure supporting HPC, AI/ML, defense, and regulated workloads.

Ansible Linux
21 hours, 10 minutes ago

Lead Security Engineer

LawnStarter 11-50 Professional Services

LawnStarter is hiring a hands-on Lead Security Engineer to establish and lead security across its AWS-based marketplace, applications, payment systems, customer data, and compliance programs.

AWS CI/CD Datadog Encryption Kubernetes Laravel Network Security PHP React Secrets Management TypeScript
21 hours, 25 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers