Description

  • Perform security assessments on web, mobile, thick-client applications, and browser extensions.
  • Plan and execute external and internal network penetration tests.
  • Conduct security source code reviews across multiple languages and produce actionable findings.
  • Perform cloud security reviews of platforms such as AWS, Azure, and GCP.
  • Develop comprehensive penetration test reports tailored to both technical and non-technical audiences.
  • Research and develop new pentesting techniques, tools, and methodologies for applications in the blockchain/Web3 space.
  • Contribute to community-facing materials by developing tools, presentations, and blog posts.
  • Collaborate with clients and internal R&D to threat model, scan, audit, design, and enhance application security.

Requirements

  • Minimum of 4 years of experience in application security and penetration testing.
  • Passion for cryptocurrency, DeFi, and blockchain, with willingness to learn Web3 technologies such as smart contracts.
  • Experience in source code review for multiple languages, with strong understanding of JavaScript and TypeScript.
  • Experience in mobile application penetration testing.
  • Familiarity with cloud platforms and their security risks (AWS, Azure, GCP).
  • Experience programming with scripting languages such as Python and Bash.
  • Solid understanding of cryptography.
  • BS/MS/PhD in Computer Science or Information Security (or equivalent experience).
  • Strong spoken and written communication skills.
  • (Nice to have) Experience pentesting Web3 applications (crypto exchanges, wallets, DApps, key custodians), smart contract security audits, browser extension security, participation in bug bounties/audit contests, published security write-ups or talks, and certifications such as OSCP, OSWE, OSCE, or GWAPT.

Benefits

  • Target U.S. annual base salary range: $100,000 - $180,000 (final offer depends on skills and experience).
  • Remote work option (#LI-Remote).
  • Medical, vision, and dental insurance.
  • 401(k) plan with company matching.
  • Life and accidental death & dismemberment (AD&D) insurance.
  • HSA (with high deductible plan) and FSA, plus flexible paid time off and holidays.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Endpoint & Security Platforms Engineer

JustMarkets 1-10 Capital Markets

The Endpoint & Security Platforms Engineer will build and operate endpoint, server, and security-platform controls to protect company systems while maintaining reliable production operations.

Ansible Bash Elasticsearch Linux macOS PowerShell Puppet Python SIEM
3 hours, 10 minutes ago

Security Systems Technical Lead

Bogaard Group International 11-50 Professional Services

This full-time, fully remote Security Systems Technical Lead role embeds with a client’s Security Technology team to lead the design, deployment, optimization, and operational health of enterprise physical security systems.

4 hours, 25 minutes ago

Senior Engineer - Information Security

Commvault is seeking a Senior Engineer, Information Security to design, operate, and improve enterprise security technologies that protect users, endpoints, identities, systems, and data while advancing the organization’s security program.

Agile Cybersecurity Linux macOS
4 hours, 25 minutes ago

Data Privacy & Compliance Engineer - OneTrust

NTT DATA 100K+ IT Services

NTT DATA is seeking a remote Data Privacy & Compliance Engineer specializing in OneTrust to support a global client’s data discovery, governance, privacy automation, and compliance controls.

1 day, 4 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers