Remote job
Protocol Security Researcher
Job details
About this role
Role overview This position focuses on strengthening internal protocol security for a major onchain lending platform. The work spans smart contract review, adversarial analysis, and proactive risk modeling across deployed lending systems and their supporting infrastructure. It is a continuous security function rather than a traditional point-in-time audit role, aimed at understanding and reducing protocol risk over time.
Responsibilities - Review major protocol changes prior to external audit or deployment - Conduct attacker-driven analysis of smart contracts, mechanisms, and integrations - Join early design and architecture discussions to influence security-relevant decisions - Identify risks in adjacent systems including assets, bridges, oracles, adapters, and critical dependencies - Contribute to AI-assisted security tooling and assess effectiveness in real review workflows - Convert review findings into reusable invariants, assumptions, and testing or monitoring ideas - Collaborate with monitoring and incident workflows to keep context current across deployed systems
Requirements - Strong smart contract security background with hands-on experience reviewing deployed DeFi protocols - Familiarity with lending market mechanics, onchain financial primitives, and associated risk surfaces - Ability to reason about severity, exploitability, and economic impact of findings - Clear written communication skills to explain risk, uncertainty, and trade-offs to engineers and non-security stakeholders - Good judgment about when a finding matters and how to prioritize review throughput
Nice to have - Experience with formal methods, fuzzing, invariant testing, or custom security tooling - Building internal tools for security review, code understanding, or knowledge management - Working with external audit firms or leading audit engagements - Familiarity with governance payloads, upgrade systems, permissioning, and incident response - Open-source security research, published findings, CTFs, bug bounties, or prior public vulnerability work