Senior Application Security Engineer
Consensys builds the consumer platform, developer, enterprise, and agentic infrastructure, and protocol software powering the transition to decentralized finance.
Maintainer signals as of 9/2/2026
Funding history
Projects
About Consensys
Consensys Software Inc. is an Ethereum-focused blockchain software company operating consumer applications, transaction execution services, developer infrastructure, staking infrastructure, Layer 2 technology, and protocol-level software including MetaMask, Infura, Linea, Consensys Staking, Teku, Besu, and Web3Signer.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
Embed security into the software development lifecycle for MetaMask products by reviewing designs, performing threat modeling, conducting security testing and code reviews, triaging vulnerabilities, fixing security issues, building automation and tooling, validating patches, and driving remediation.
Requirements
- 6+ years building and securing software, with at least 4 years in product or application security
- Experience securing server-side applications and environments
- Experience performing security design reviews, threat modeling, and security testing
- Experience working with or securing JavaScript and Node.js applications in modern web environments
- Strong coding skills in modern application stacks, ideally JavaScript and Node.js
- Experience securing web applications and APIs
- Solid written and verbal communication skills
- Proactive and self-driven with ability to work effectively in a remote environment
- Relevant knowledge of modern web and mobile application security landscape, real-world attacks and mitigations
Responsibilities
- Determine root cause and severity of reported vulnerabilities
- Triage bug bounty reports and interface with ethical hackers
- Guide product engineering teams to remediation
- Document identified vulnerabilities to enable rapid engineering action
- Write code to support security engineering projects and fix client vulnerabilities
- Develop AI tooling for vulnerability determination and resolution
- Assess application security and ensure remediation within SLAs
- Conduct design reviews, threat modeling, security testing, and code reviews
- Identify gaps in the SSDLC and lead remediation efforts
- Validate security patches and test for potential bypasses
- Develop automation, security controls, and educational materials to prevent recurrence
Benefits
- Comprehensive competitive benefits package
- Equity
- Access to Consensys Advance Program and Coursera learning modules
- Unlimited vacation/holidays
- Flexible working arrangements
- Remote-first work
