Application Security Engineer
Rootstock is a Bitcoin sidechain and Layer 2 network that enables EVM-compatible smart contracts and decentralized applications secured by Bitcoin proof-of-work. It provides Bitcoin-native DeFi infrastructure, including rBTC, bridges, developer tools, and ecosystem support for builders, users, and institutions.
Maintainer signals as of 9/2/2026
Funding history
Investors
Projects
About Rootstock
Rootstock operates an EVM-compatible Bitcoin sidechain secured through merged mining and Bitcoin proof-of-work. Its infrastructure enables smart contracts, decentralized applications, Bitcoin-backed rBTC, DeFi use cases, cross-chain bridges, RPC access, an explorer, developer documentation, grants, and community programs. Rootstock serves developers building on Bitcoin, users accessing Bitcoin DeFi, and institutions exploring Bitcoin-secured financial infrastructure.
Skills
About the Role
You will review source code, smart contracts, and protocol changes to identify and mitigate security risks. You will conduct threat modeling and architecture reviews, manage bug bounty reports, coordinate third-party audits, build security automation, research relevant attacks, and support application-layer incident investigations.
Requirements
- 3+ years of experience in Application Security or Security Engineering
- Knowledge of OWASP Top 10 and secure code review in Java
- Knowledge of at least one of TypeScript, JavaScript, Python, Go, or Rust
- Hands-on blockchain security experience, including Solidity/EVM smart contract auditing or protocol/node-level security
- Experience with security automation, AI-assisted workflows, SAST/DAST, dependency scanning, secret scanning, and CI/CD security gates
- Fluent English
- Background and reference checks to validate experience, qualifications, location, and professional history
Responsibilities
- Perform security reviews of source code, smart contracts, and protocol changes
- Participate in design and architecture reviews and threat-model new products and features
- Triage and validate bug bounty reports, assess severity, and coordinate remediation
- Scope external security audits and work with third-party auditors to resolve findings
- Build and operate security automation for code review, scanning, and findings triage
- Research EVM, bridge, and peer-to-peer attack techniques and implement defenses
- Support application-layer incident investigations
Benefits
- 100% remote work
- Access to global coworking spaces
- Paid vacation
- Paid sick leave
