Web3 VAPT Security Pentester

QuillAudits provides smart contract security audits and penetration testing services for blockchain projects to identify vulnerabilities before deployment.

Maintainer signals as of 9/25/2026

Office 104/105 Level 1, Emaar Square, Building 4 Sheikh Mohammed Bin Rashid Boulevard Downtown Dubai, P.O box: 416654, United Arab Emirates
About QuillAudits

QuillAudits delivers blockchain security solutions through comprehensive smart contract audits, penetration testing, and protocol analysis. With various projects audited across multiple blockchain ecosystems, the firm helps Web3 projects secure their code against vulnerabilities and exploits. Services cover Ethereum, Solana, Polygon, and other major blockchain platforms, providing detailed vulnerability reports and remediation guidance.

View jobs by QuillAudits

Skills

About the Role

You will perform vulnerability assessment and penetration testing of Web3 dApps, APIs, wallets, backend systems, and mobile applications. You will assess wallet integrations and Web3 authentication flows, identify attack vectors and application-security weaknesses, review mobile applications, and document findings with proof of concept, impact, reproduction steps, and remediation guidance.

Requirements

  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field, or equivalent experience
  • 2+ years of hands-on VAPT or application-security experience
  • Strong understanding of Web3, dApps, wallets, and blockchain
  • Strong Web2 and API security knowledge
  • Experience with Burp Suite and security testing tools
  • Experience testing Android and iOS security and reviewing source code
  • Familiarity with Solidity, EVM, Foundry, Hardhat, ethers.js, or viem is a plus

Responsibilities

  • Perform VAPT of Web3 dApps, APIs, wallets, and backend systems
  • Test wallet integrations, SIWE, signature verification, EIP-712, transaction flows, WalletConnect, and Web3 authentication
  • Identify Web3 attack vectors and business-logic flaws
  • Perform Web2 and API security testing
  • Conduct Android and iOS mobile application security testing
  • Review source code, secure storage, cryptography, and runtime behavior
  • Prepare technical reports with proof of concept, impact, severity, reproduction steps, and remediation

Benefits

  • Flexible working arrangements
  • Remote work
  • Five-day work week
  • Performance-based incentives
  • Global conferences and meetups
  • Company-paid workations twice a year

Hiring Process

Application review → technical challenge (task-based screening) → technical interview → founder's connect → offer

Web3 VAPT Security Pentester at QuillAudits | JobStash