Senior Application Security Engineer
MetaMask is an active Consensys-developed self-custodial crypto wallet and onchain finance platform available through browser extensions and mobile apps.
Maintainer signals as of 9/2/2026
Projects
About MetaMask
MetaMask provides self-custodial digital-asset management and access to decentralized applications. Its current platform includes wallet functionality, token swaps, trading, payments, earning, MetaMask Card, security features, Snaps, Agent Wallet, and developer tooling. MetaMask is a Consensys product and brand rather than an independently evidenced legal entity.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will embed security throughout the software development lifecycle and partner with engineers and product managers to design and implement secure products. You will assess, triage, document, and remediate vulnerabilities; conduct threat modeling, design reviews, security testing, and code reviews; validate patches; and build automation and security controls to prevent recurring issues.
Requirements
- 6+ years of experience building and securing software, including product or application security experience
- Experience securing modern backend systems, web applications, and APIs
- Experience performing threat modeling, security design reviews, and vulnerability assessment
- Experience securing JavaScript-based web or mobile applications
- Strong coding skills
- Familiarity with blockchain technology, Ethereum, decentralized applications, and crypto wallets
- Understanding of web and mobile security attack vectors and mitigations
- Strong communication and remote collaboration skills
- Ability to overlap with EU and US-Pacific time zones
Responsibilities
- Determine the root cause and severity of bug bounty vulnerabilities
- Interface with ethical hackers, triage reports, and guide engineering teams to resolution
- Document identified vulnerabilities for engineering action
- Write code for security engineering projects and vulnerability fixes
- Develop AI tooling for vulnerability determination and resolution
- Assess application vulnerabilities and ensure remediation within established SLAs
- Conduct design reviews, threat modeling, security testing, and code reviews
- Identify and address gaps in the secure software development lifecycle
- Participate in team meetings, roadmap planning, and discussions
- Validate security patches and test for potential bypasses
- Develop automation and security controls and educate developers to prevent recurring vulnerabilities
