Remote job
Security Researcher
Job details
About this role
Role overview Lead security work across financial software built around Bitcoin, covering application code, cloud infrastructure, and engineering practices. The role combines hands-on vulnerability research with threat modeling, incident response, and support for engineers contributing to open-source projects.
Responsibilities - Lead threat-modeling sessions for new features and help teams build security into designs. - Review Rust code manually and with automated tools; investigate vulnerabilities and handle responsible disclosure. - Strengthen cloud and Kubernetes deployments through controls for access, network boundaries, and secrets. - Add static and dynamic analysis, secret scanning, and dependency checks to CI/CD workflows. - Triage security alerts, maintain detection rules, and lead incident reviews. - Share research with open-source communities and coach engineers in secure coding.
Requirements - At least five years of application or cloud security experience, with documented vulnerability discoveries. - Rust proficiency or a strong commitment to becoming proficient. - Knowledge of Bitcoin and Lightning protocols. - Experience with cloud platforms, Kubernetes, Terraform, and CI/CD. - Familiarity with SAST/DAST, fuzzing, and CodeQL, plus threat modeling and penetration testing skills. - Strong written and spoken English, and experience working remotely across time zones.
Nice to have - Spanish proficiency or experience with MPC wallets or custody models. - Adaptability in a startup environment.
Benefits and work setup - Remote-first work with an international team and opportunities to contribute to open-source projects. - Optional Bitcoin compensation and possible relocation assistance with visa support.