Search...

Product Security Engineer

Hashgraph logo
Hashgraph

A fast-growing software company providing technical and product development and marketing support for the Hedera network, as well as community and enterprise solutions that enable faster app development. Composed of an international team of builders and innovators including Hedera Co-founders Mance Harmon, and the inventor of hashgraph, Dr. Leemon Baird. Hashgraph is a technology company that has developed the Hashgraph consensus algorithm, a system for replicated state machines with guaranteed Byzantine fault tolerance. They also offer HashSphere, a private, permissioned DLT network built with Hedera technology.

Distributed
About Hashgraph

As the team providing engineering and support for the core Hedera platform, Hashgraph sits at the intersection of old and new. We enable a sustainable, scalable, and secure decentralized infrastructure for building a wide range of applications and enterprise solutions, from financial services to supply chain management and beyond. Hashgraph delivers open source engineering and support for the core network platform, including Hedera Consensus Service, Hedera Token Service, and Hedera Smart Contract Service. We also build and deliver open-source tools for the overall benefit of the Hedera community, such as HashScan, a ledger explorer for the Hedera public ledger. Hashgraph also develops APIs and open source components for services including: loyalty token management, bond issuances, NFT marketplaces, and peer-to-peer payments. Hashgraph provides resources such as blogs, videos, case studies, and papers to help users navigate the digital economy. Their offerings include HashSphere, a private, permissioned DLT network currently in beta, which is built with enterprise-grade Hedera technology. The company, formerly Swirlds Labs, rebranded to Hashgraph to signify a return to its Hedera roots. At its core is the Hashgraph consensus algorithm, a system designed for replicated state machines that guarantees Byzantine fault tolerance.

View jobs by Hashgraph

Skills

About the Role

You will conduct end-to-end security assessments of blockchain-based systems, from cryptographic primitive design and protocol architecture through smart contract implementation and deployed infrastructure. You will find real vulnerabilities through hands-on review, adversarial testing, and proof-of-concept exploit development, not just automated scanning. You will design adversarial test cases and proof-of-concept exploits for Hedera-native services, EVM-compatible contracts, cross-chain bridges, and consensus-layer components. You will own threat modeling and security architecture reviews across product phases. You will define and enforce security gates before new components reach production. You will partner directly with engineering teams to translate cryptographic and protocol-level risks into concrete, prioritized remediation work. You will build and improve security tooling, fuzzing infrastructure, and CI/CD security automation to scale security coverage without scaling headcount. You will track emerging blockchain and web3 attack patterns, map them to the internal codebase, and drive proactive mitigation before threats materialize.

Requirements

  • Hands-on vulnerability discovery and security testing across blockchain protocols, smart contracts, nodes, and APIs.
  • A track record of catching real bugs, not just automated scans.
  • Strong threat modeling and security architecture review experience applied to distributed cryptographic systems.
  • Experience assessing cross-chain protocols, threshold signature schemes, or other cryptographic systems with complex trust assumptions.
  • Deep working knowledge of applied cryptography, including BLS signatures, pairing-based schemes, polynomial commitments, and Fiat-Shamir constructions.
  • Ability to reason about cryptographic failure modes and how they show up in production systems.
  • Direct experience auditing or breaking a cross-chain bridge.
  • Ability to reason through trust model tradeoffs, including state proof, multisig, and oracle attestation models, and what each means for the attack surface.
  • Blockchain security and secure coding practices across EVM-compatible and non-EVM chains.
  • Security testing tooling, including static analysis, dynamic analysis, and fuzzing.
  • Experience developing custom fuzzing harnesses or security test infrastructure.
  • Ability to read and audit Rust and/or Java cryptographic code.
  • Understanding of memory safety, constant-time correctness, secret handling, and security risks at JNI boundaries.
  • Experience designing and operating grammar-aware fuzzing campaigns against gRPC, JSON-RPC, or protocol-level endpoints.
  • Experience building classifier pipelines to distinguish security signal from noise.
  • Prior work on Ethereum consensus client security.
  • Prior work on production threshold signature systems.
  • Experience building security automation tooling.
  • Experience integrating AI-assisted workflows into security review and triage processes.

Responsibilities

  • Conduct end-to-end security assessments of blockchain-based systems, from cryptographic primitive design and protocol architecture through smart contract implementation and deployed infrastructure.
  • Find real vulnerabilities through hands-on review, adversarial testing, and proof-of-concept exploit development, not just automated scanning.
  • Design adversarial test cases and proof-of-concept exploits for Hedera-native services, EVM-compatible contracts, cross-chain bridges, and consensus-layer components.
  • Own threat modeling and security architecture reviews across product phases.
  • Define and enforce security gates before new components reach production.
  • Partner directly with engineering teams to translate cryptographic and protocol-level risks into concrete, prioritized remediation work.
  • Build and improve security tooling, fuzzing infrastructure, and CI/CD security automation to scale security coverage without scaling headcount.
  • Track emerging blockchain and web3 attack patterns, map them to the internal codebase, and drive proactive mitigation before threats materialize.
Product Security Engineer at Hashgraph | JobStash