Security Engineer
Movement Labs builds Move-based blockchain infrastructure that bridges the security of the Move programming language with Ethereum's ecosystem and liquidity.
Projects
About Movement Labs
Movement creates a network for developers to build applications using the Move programming language. By connecting with Ethereum, projects gain both security and performance benefits. Movement's platform supports a variety of applications including DeFi, gaming, and NFTs, with tools that make building safer and faster for developers of all experience levels.
Skills
About the Role
You will audit Move modules, protocol code, and consensus and networking layers for vulnerabilities. You will build security tooling, lead formal verification and threat-modeling work, manage bug bounty triage, coordinate incident response, and work with engineers and external security researchers to improve protocol security.
Requirements
- Demonstrated record of finding real vulnerabilities through audit reports, CVEs, bug bounties, security research, or CTF results
- Code-level security skills for Move modules or Solidity codebases
- Understanding of at least one smart contract VM: Move, EVM, or SVM
- Ability to write Move, Solidity, Rust, or Python for security tooling
- Knowledge of smart contract vulnerabilities, consensus security, BFT failure modes, cryptographic primitives, bridge security, and cross-chain security
- Experience with adversarial security analysis and security tooling automation
Responsibilities
- Audit Move modules, Solidity and Rust protocol code, and consensus and networking layers for vulnerabilities
- Design and build fuzzers, invariant tests, static analyzers, formal specifications, and runtime monitoring
- Drive formal verification using the Move Prover and write specifications for critical modules
- Threat-model consensus, execution, data availability, bridges, RPC, and validator infrastructure
- Use AI to scale code review, vulnerability triage, and exploit-pattern detection
- Own the bug bounty program and turn findings into fixes and regression tests
- Lead security incident response, root-cause analysis, post-mortems, and disclosure coordination
- Partner with engineering teams on secure-by-default APIs, code-review standards, and threat models
- Engage with auditors, researchers, white-hats, and the Move security community
- Monitor threats including bridge exploits, MEV, signature malleability, oracle manipulation, governance attacks, and validator collusion
