MLabs

MLabs

MLabs is a Haskell, Rust, Blockchain, and AI consultancy specializing in mission-critical software development, cross-team collaboration, and cutting-edge value delivery for fintech, blockchain, and information technology sectors.

Internet Software & Services
11-50
Founded 2018

Description

  • Conduct end-to-end security assessments across blockchain systems, including cryptographic primitives, protocol architecture, smart contracts, and deployed infrastructure.
  • Own threat modeling and security architecture reviews across all stages of product development.
  • Identify vulnerabilities through hands-on code review, adversarial testing, and proof-of-concept exploit development.
  • Test native services, EVM-compatible contracts, cross-chain bridges, and consensus-layer components for real-world security issues.
  • Partner with core engineering teams to turn cryptographic and protocol risks into prioritized remediation work.
  • Define and enforce security gates before production deployment.
  • Build and improve security tooling, fuzzing infrastructure, and CI/CD security automation.
  • Track emerging blockchain and Web3 attack patterns and drive mitigation strategies across the codebase.

Requirements

  • Proven hands-on experience finding vulnerabilities and testing blockchain protocols, smart contracts, nodes, and APIs.
  • Strong threat modeling and security architecture review experience for distributed cryptographic systems.
  • Direct experience assessing cross-chain protocols, threshold signature schemes, or similar cryptographic systems with complex trust assumptions.
  • Experience auditing or breaking cross-chain bridges.
  • Deep working knowledge of applied cryptography, including BLS signatures, pairing-based schemes, polynomial commitments, and Fiat-Shamir constructions.
  • Ability to reason about cryptographic failure modes and trust model tradeoffs in production environments.
  • Mastery of blockchain security and secure coding practices across both EVM-compatible and non-EVM chains.
  • Experience with security testing tools such as static analysis, dynamic analysis, and fuzzing.
  • Experience building custom fuzzing harnesses or security test infrastructure.
  • Ability to read, review, and audit cryptographic code written in Rust and/or Java.
  • Understanding of memory safety, constant-time correctness, secret handling, and JNI-related security risks.
  • Preferred: Experience designing and operating grammar-aware fuzzing campaigns against gRPC, JSON-RPC, or protocol-level endpoints.
  • Preferred: Experience building classifier pipelines to isolate security signals from noise or other custom security automation.
  • Preferred: Prior security work on Ethereum consensus clients or production threshold signature systems.
  • Preferred: Experience integrating AI-assisted workflows into security review and triage.

Benefits

  • Competitive salary and compensation package, including $75K - $85K compensation.
  • Remote work across APAC and EU time zones.
  • Opportunity to work on enterprise Web3 infrastructure and cryptographic innovation.
  • Collaborative engineering environment focused on complex distributed systems challenges.
  • Flexible working arrangements.
  • Comprehensive professional growth opportunities.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
13 hours, 51 minutes ago

Senior Application Security Engineer

Canopy 51-250 Internet Software & Services

Canopy is hiring a Senior Application Security Engineer to help secure its remote Utah-based SaaS platform for accounting firms, with a focus on hardening infrastructure, applications, observability, and the software supply chain.

AWS CI/CD Kubernetes Network Security SIEM WAF
14 hours, 36 minutes ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
2 days, 13 hours ago

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
2 days, 14 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers