Remote job
Application Security Engineer
Job details
About this role
Role overview Join a security team protecting Bitcoin-secured decentralized finance infrastructure. The role blends application security engineering with blockchain-specific expertise, including smart contract review, protocol security analysis, and security automation across the development lifecycle. Expect close collaboration with engineering on threat modeling, audit coordination, and incident response.
Responsibilities - Conduct security reviews of source code, smart contracts, and protocol changes across DeFi projects - Lead design and architecture reviews, threat-modeling new products and features alongside developers - Triage and validate bug bounty submissions, assess severity, and drive remediation with engineering teams - Scope and manage external security audits, working with third-party auditors through to resolution - Build and operate security automation, including AI-assisted code review, scanning pipelines, and findings triage - Research ecosystem-relevant attack techniques (EVM, bridges, peer-to-peer) and translate findings into monitoring alerts, CI security checks, and hardening changes - Support incident investigations involving application-layer issues
Requirements - Three or more years of experience in application security or security engineering - Strong grasp of common vulnerability classes (OWASP Top 10) and secure code review in Java, plus at least one of TypeScript/JavaScript, Python, Go, or Rust - Hands-on blockchain security experience such as smart contract auditing (Solidity/EVM) or protocol/node-level security - Practical experience building security automation, AI-assisted workflows (LLM-based triage, code review, or scanning), SAST/DAST, dependency and secret scanning, and CI/CD security gates - Fluent written and spoken English
Nice to have - Bug bounty triage or vulnerability disclosure program experience - Familiarity mitigating network-level attacks (peer-to-peer, eclipse, DoS) or analyzing consensus-level attack scenarios - Offensive security background in pentesting, red team, CTFs, or exploit development - Public security research output such as CVEs, bug bounty reports, audit reports, or conference talks - Knowledge of C/C++ for node or client codebases - Experience with fuzzing applied to smart contracts or native code
Benefits and work setup - Competitive compensation package with tailored benefits - Fully remote position within a Central European to South American time-zone window (roughly UTC-3 to UTC+2, with some flexibility), plus access to global coworking spaces - Paid vacation and sick leave to support work-life balance - Annual learning sponsorship covering training programs, language courses, and continuous education - Opportunity to work on blockchain technology projects within a globally distributed, diverse team