Search...
Urgently Hiring

Product Security Engineer

Skills

About the Role

You will conduct end-to-end security assessments of blockchain-based systems from cryptographic primitive design and protocol architecture through smart contract implementation and deployed infrastructure. You will find real vulnerabilities through hands-on review adversarial testing and proof-of-concept exploit development rather than relying on automated scanning. You will design adversarial test cases and proof-of-concept exploits for native blockchain services, EVM-compatible contracts, cross-chain bridges, and consensus-layer components. You will own threat modeling and security architecture reviews across product phases. You will define and enforce security gates before new components reach production. You will partner with engineering teams to translate cryptographic and protocol-level risks into concrete remediation work. You will build and improve security tooling, fuzzing infrastructure, and CI/CD security automation to scale security coverage. You will track emerging blockchain and web3 attack patterns, map them to the internal codebase, and drive proactive mitigation before threats materialize.

Requirements

  • Hands-on vulnerability discovery and security testing across blockchain protocols, smart contracts, nodes, and APIs.
  • A track record of catching real bugs, not just running automated scans.
  • Strong threat modeling and security architecture review experience applied to distributed cryptographic systems.
  • Experience assessing cross-chain protocols, threshold signature schemes, or other cryptographic systems with complex trust assumptions.
  • Deep working knowledge of applied cryptography, including BLS signatures, pairing-based schemes, polynomial commitments, and Fiat-Shamir constructions.
  • Ability to reason about cryptographic failure modes and how they show up in production systems.
  • Direct experience auditing or breaking a cross-chain bridge.
  • Ability to reason through trust model tradeoffs, including state proof, multisig, and oracle attestation models, and what each means for the attack surface.
  • Nice-to-haves: Experience designing and operating grammar-aware fuzzing campaigns against gRPC JSON-RPC, or protocol-level endpoints.
  • Nice-to-haves: Experience building classifier pipelines to distinguish security signal from noise.
  • Nice-to-haves: Prior work on Ethereum consensus client security.
  • Nice-to-haves: Prior work on production threshold signature systems.
  • Nice-to-haves: Experience building security automation tooling.
  • Nice-to-haves: Experience integrating AI-assisted workflows into security review and triage processes.

Responsibilities

  • Conduct end-to-end security assessments of blockchain-based systems from cryptographic primitive design and protocol architecture through smart contract implementation and deployed infrastructure.
  • Find real vulnerabilities through hands-on review adversarial testing and proof-of-concept exploit development rather than relying on automated scanning.
  • Design adversarial test cases and proof-of-concept exploits for native blockchain services, EVM-compatible contracts, cross-chain bridges, and consensus-layer components.
  • Own threat modeling and security architecture reviews across product phases.
  • Define and enforce security gates before new components reach production.
  • Partner with engineering teams to translate cryptographic and protocol-level risks into concrete remediation work.
  • Build and improve security tooling, fuzzing infrastructure, and CI/CD security automation to scale security coverage.
  • Track emerging blockchain and web3 attack patterns, map them to the internal codebase, and drive proactive mitigation before threats materialize.