Smart Contract Security Engineer

1 week ago
Full-time
Senior
Cybersecurity
Law360

Law360

Law360 is a premier online media company offering in-depth legal news and analysis on litigation, policy, and deals, serving as a vital resource for legal professionals globally.

Media
251-1K
Founded 2004

Description

  • Lead end-to-end security audits of Veda’s smart contract systems, including the BoringVault architecture, cross-chain bridge integrations, and DeFi composability patterns.
  • Identify novel attack vectors in vault accounting logic, share pricing mechanisms, and multi-strategy capital allocation systems.
  • Partner with external audit firms to coordinate comprehensive reviews and address findings.
  • Evolve smart contract security standards, testing methodologies, and deployment practices.
  • Mentor smart contract engineers on secure coding patterns, gas optimization trade-offs, and defense-in-depth strategies.
  • Serve as the security subject matter expert in architecture discussions and design reviews.
  • Build and maintain custom security tools such as fuzzing harnesses, invariant testing frameworks, and symbolic execution pipelines.
  • Research emerging DeFi attack patterns and translate findings into defensive measures.
  • Design and implement real-time monitoring systems for on-chain anomaly detection.
  • Lead on-chain security incident response, including root cause analysis, remediation, and maintenance of runbooks and escalation procedures.

Requirements

  • 3+ years writing and auditing production Solidity code.
  • Deep understanding of EVM architecture, opcode-level behavior, gas mechanics, and storage patterns.
  • Proven experience conducting security audits or vulnerability research in DeFi protocols.
  • Experience performing comprehensive smart contract audits from threat modeling through remediation validation.
  • Hands-on experience with testing and analysis tools such as Foundry, Echidna, Slither, Manticore, or similar frameworks.
  • Exceptional written communication skills for technical and non-technical stakeholders.
  • Professional experience at a tier-1 audit firm, a security role at a leading DeFi protocol, or top placements in competitive audit contests.
  • Familiarity with MEV infrastructure, mempool analysis, and transaction ordering dependencies.
  • Understanding of cross-chain security challenges including bridge architecture, message verification, and multi-chain state synchronization.
  • Track record of discovering high-severity vulnerabilities in production DeFi protocols.
  • Active participation in security communities such as competitive CTFs, bug bounties, or published research is preferred.
  • Experience with symbolic execution and formal verification methods is preferred.
  • Experience with non-EVM environments such as Solana or Move is preferred.

Benefits

  • Medical, dental, and vision coverage for employees.
  • Health coverage support for international contractors through appropriate local or global plans.
  • Flexible time off with no tracked vacation days.
  • Remote-first, async work environment with autonomy over micromanagement.
  • Paid parental leave for new parents, including primary and secondary caregivers.
  • Learning and development stipends for courses, conferences, and other growth opportunities.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Software Engineer I - Secure Platform Operations (Remote Eligible)

Smartsheet 1K-5K Internet Software & Services

Smartsheet is hiring a Software Engineer I to join its global Secure Platform Operations team in the U.S. to help build and secure scalable platform infrastructure, automate operational work, and improve developer experience in a multi-cloud environment.

AWS Bash CI/CD DNS Docker GitHub GitLab Go HTTP Kubernetes Linux Python TCP/IP Terraform Unix
1 minute ago

Senior Software Engineer - IAM

Affirm 1K-5K Diversified Financial Services

Affirm is seeking a software engineer to evolve its enterprise identity platform, building automation and AI-assisted workflows around SailPoint and Auth0 in a remote role based in Spain.

AWS Buildkite CI/CD GitHub JIRA Python Terraform
1 minute ago

Manager, Vulnerability & Data Security

Marqeta 251-1K Diversified Financial Services

Marqeta is hiring an Information Security Manager to lead vulnerability management and build a data security program for its fully cloud-based environment.

AWS Azure CI/CD Databricks DevSecOps GCP SIEM Snowflake
1 minute ago

Staff Security Engineer

Mozilla 251-1K Internet Software & Services

Mozilla is hiring an Incident Responder to monitor, investigate, and mitigate security attacks across its products and services, helping protect users and maintain the integrity of a global, privacy-focused internet platform.

AWS Azure GCP Heroku SIEM Splunk
31 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers