Search...

Senior Security Engineer

CertiK logo
CertiK

CertiK is a leading blockchain and Web3 security auditor that provides smart contract auditing and a comprehensive suite of security tools for the crypto industry. Founded in late 2017 by professors from Columbia University and Yale University, CertiK has grown into the largest Web3 security service provider with headquarters in New York. The company’s services help blockchain projects, exchanges, and enterprises strengthen their security, and CertiK is trusted by major industry players worldwide (e.g. Binance, OKX, Polygon, etc.) to audit and monitor their systems.

New York, USA
200 Employees

Projects

About CertiK

CertiK specializes in blockchain cybersecurity, leveraging formal verification techniques and AI technology to secure smart contracts and blockchain protocols across the Web3 ecosystem. The company offers end-to-end security solutions including smart contract and blockchain audits, on-chain monitoring (through its Skynet platform), penetration testing, compliance/AML tools, and advisory services, covering the entire project lifecycle from development to post-deployment. One of the fastest-growing firms in the crypto security sector, CertiK has served nearly 4,000 clients and helped secure over $360 billion worth of digital assets by detecting tens of thousands of vulnerabilities in code. Its clients range from DeFi protocols and layer-1 blockchains to exchanges and wallets – notable examples include projects like Aave, Polygon, Binance Smart Chain, Terra, and more. Backed by top investors such as Sequoia Capital, Tiger Global, Coatue, and Goldman Sachs, CertiK has established itself as a market leader in blockchain security. The company’s mission is to “secure the Web3 world,” applying cutting-edge academic research to real-world blockchain applications to improve safety and trust in the crypto ecosystem.

View jobs by CertiK

Skills

About the Role

You will work with external blockchain developers to audit codes and secure products including smart contracts, protocols and apps. You will establish and enforce security policies, manage vulnerabilities, respond to incidents and write analysis reports. You will monitor security breaches and defend systems from cyberattacks. You will conduct penetration tests on web and mobile apps (Android and iOS), and perform external and internal network security assessments. You will review source code and security design, conduct threat modeling, and provide guidance to software development teams. You will contribute to internal security tools and create new ones to improve security services. You will use static and dynamic analyses to identify flaws or vulnerabilities in smart contracts and propose recommendations. You will assess sandbox, VM, network, and core distributed-system code, identify vulnerabilities, and build PoC exploits. You will conduct security research, publish findings in technical blog posts and speak at conferences/tech talks/X Spaces, showcasing your expertise.

Requirements

  • Master's degree in Security Informatics/Cybersecurity or a related field.
  • In-depth knowledge of Solidity/smart contract security/cryptography/blockchain technology.
  • Technical expertise in Web3 security, threat/vulnerability management, penetration testing & security review for programs written in Java/JavaScript/Python/C/C++/PHP/Go.
  • Familiar with cloud platforms such as AWS/Azure/GCP & proficient in Python/JavaScript.

Responsibilities

  • Work with external blockchain developers to audit codes & secure products (smart contracts, protocols & apps/Dapps).
  • Establish/enforce security policies, manage security vulnerabilities, respond to incidents and write analysis reports.
  • Monitor security breaches, defend systems from cyberattacks & provide technical consulting services in cybersecurity.
  • Conduct penetration tests on web/mobile (Android & iOS) & client application, perform external/internal network security assessment.
  • Review source code/security design, conduct threat modeling & provide guidance to software development teams.
  • Contribute to internal security tools & create new ones for improving security services with best engineering practices.
  • Use static/dynamic analyses to identify flaws or vulnerabilities in smart contracts & propose recommendations.
  • Assess sandbox/VM/network/core distributed-system code, identify vulnerabilities & build PoC exploits.
  • Conduct security research, publish findings in technical blog posts & speak at conferences/tech talks/X Spaces, showcasing technical expertise/insights.

Benefits

  • Medical, vision, and dental insurance
  • 401(k) plan with company matching
  • Life and accidental death and dismemberment insurance
  • Health Savings Account (HSA) with a high deductible plan
  • Flexible Spending Account (FSA)
  • Flexible paid time off and holidays
  • Variable commission program for business development sales roles