Senior Application Security Engineer

1 month, 3 weeks ago
Full-time
Senior
Cybersecurity
Consensys

Consensys

Consensys is a blockchain software company providing trusted web3 products. MetaMask, their flagship self-custodial wallet, serves over 100 million users for identity, asset management, and web3 exploration.

Internet Software & Services
251-1K
Founded 2014
$725M raised

Description

  • Determine the root cause and severity of vulnerabilities reported through the bug bounty platform.
  • Interface with ethical hackers, triage vulnerability reports, and guide engineering teams to resolution.
  • Document vulnerabilities clearly so engineering teams can act quickly.
  • Write code to support security engineering projects and fix vulnerabilities in MetaMask client applications.
  • Develop AI tooling to help determine and resolve vulnerabilities.
  • Assess security risks in applications and ensure remediation within established SLAs.
  • Support new feature development through design reviews, threat modeling, security testing, and code reviews.
  • Identify gaps in the secure software development lifecycle and lead efforts to address them.
  • Validate that security patches fully address reported vulnerabilities and check for bypasses.
  • Build automation, security controls, and developer education to prevent future vulnerabilities.

Requirements

  • 6+ years of experience building and securing software, including hands-on product or application security experience.
  • Experience securing modern backend systems, web applications, and APIs.
  • Experience performing threat modeling, security design reviews, and vulnerability assessment.
  • Experience securing JavaScript-based applications across web and/or mobile; Node.js, React, and React Native are preferred.
  • Strong coding skills with the ability to work directly with engineers to identify and fix vulnerabilities or build secure solutions.
  • Strong understanding of modern web and mobile security, including common attack vectors and mitigations.
  • Strong communication skills and the ability to influence engineering decisions in a remote environment.
  • Self-driven and proactive, with comfort operating in a high-autonomy, distributed team.
  • Alignment with Consensys’s mission and values.
  • Experience working as a software developer is preferred.
  • Familiarity with the Ethereum blockchain and decentralized applications is preferred.
  • Must be able to overlap with EU and US-Pacific time zones as needed.
  • Applicants must be willing to undergo background checks, including employment, education, and criminal record checks.

Benefits

  • US base salary range of $130,000 to $218,000, not including bonus, equity, or other benefits.
  • Remote-friendly work environment with distributed collaboration.
  • Opportunities for career growth and learning within MetaMask and Consensys.
  • High trust and autonomy in day-to-day work.
  • Exposure to new concepts, ideas, and frameworks across different projects.
  • Opportunity to contribute to products supporting one billion participants and 5 million developers.
  • Potential for bonus, equity, and other benefits.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Firefox Security Student Worker

Mozilla 251-1K Internet Software & Services

Mozilla’s Firefox Application Security Team is hiring a university student in Germany to help improve the security of Firefox and the broader web through application security work in Berlin.

C++ Python
9 hours, 31 minutes ago

Senior Application Security Engineer

Apollo.io 251-1K Professional Services

Apollo.io is hiring a Senior Application Security Engineer II to strengthen the secure development lifecycle and reduce application risk across product, platform, and AI-powered features at a fast-growing SaaS company.

Encryption GCP Linux OAuth Penetration Testing Python Ruby
10 hours, 46 minutes ago

Application Security Engineer

Nebius 51-250 Internet Software & Services

Nebius is hiring an Application Security Engineer to help secure its AI cloud platform by identifying vulnerabilities, improving secure development practices, and supporting application security across the software lifecycle.

Burp Suite Cybersecurity Go Java JavaScript Linux OpenID Connect Penetration Testing Python SAML
1 day, 9 hours ago

Senior Application Security Engineer - Southeast region (Remote)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is hiring a senior Application Security consultant to help client organizations strengthen and operationalize their AppSec programs through a mix of advisory work, hands-on engineering, and executive-level guidance.

AWS Azure CI/CD DevSecOps GCP Kubernetes Secrets Management
1 day, 10 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers