Enable job alerts via email!

Application Security Engineer

IFT

United States

Remote

USD 120,000 - 160,000

Full time

3 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company in the decentralized web seeks an Application Security Engineer to enhance security protocols. The role demands expertise in secure coding and incident response within the blockchain space. Candidates should have at least 5 years of relevant experience and a deep understanding of Web3 technology.

Qualifications

  • 5+ years of experience in Web3 security engineering.
  • Experience with manual/automated code review techniques.
  • Knowledge of cryptographic protocols and blockchain security.

Responsibilities

  • Perform in-depth reviews of source code to identify vulnerabilities.
  • Collaborate with development teams to remediate security issues.
  • Prepare for external security audits and document findings.

Skills

Secure coding practices
Incident response capabilities
Code analysis
Penetration testing
Documentation skills

Tools

Static analysis tools
Dynamic analysis tools

Job description

*Only apply if you have several years of experience in Blockchain/Web3/Crypto*
About Vac:

Vac builds public good protocols for the decentralised web. We do applied research based on which we build protocols, libraries and publications.

The Vac Security service unit provides comprehensive support to IFT projects by conducting security audits and helping develop robust security plans. In addition to assisting IFT projects, the security team also supports other IFT services by offering expert guidance on security best practices and risk management strategies. This collaborative approach ensures that all aspects of the IFT ecosystem benefit from enhanced security measures.

By identifying potential vulnerabilities, assessing risks, and implementing effective security solutions tailored to specific needs, the Vac Security service unit plays a crucial role in strengthening the overall security posture of IFT.

The role:

We are looking for an Application Security Engineer to join our security service unit. In this role, you’ll perform in-depth reviews of critical code (with a focus on low-level languages like Rust, Nim, and C++), identify both code-level and protocol-level vulnerabilities, and support incident response efforts.

You’ll collaborate closely with development teams to remediate security issues and ensure best practices are followed. You’ll also play a key role in preparing for external security audits—defining audit scope, organising technical documentation, and working directly with auditors to ensure valuable and actionable results.

This is a hands-on position for someone passionate about secure software development and proactive risk mitigation.

Key responsibilities:
  • Perform in-depth manual and automated reviews of source code (with a focus on low-level languages such as Rust, Nim, and C++) to identify security vulnerabilities and logic flaws.
  • Analyse and review critical code paths for potential weaknesses.
  • Identify and assess both code-level vulnerabilities (e.g., buffer overflows, injection flaws) and protocol-level issues (e.g., insecure cryptographic implementations, protocol misconfigurations).
  • Execute incident response activities, including detection, analysis, containment, and recovery, while documenting findings and lessons learned for continuous improvement.
  • Collaborate with development and product teams to remediate identified vulnerabilities, provide security guidance, and ensure secure coding practices are followed.
  • Define clear audit objectives and scope for external audits, focusing on the most critical components and protocols.
  • Prepare and organise all relevant documentation (architecture diagrams, codebase, threat models, protocol specifications) to facilitate an efficient and valuable external audit process.
  • Engage with external auditors early to clarify expectations and provide necessary context, ensuring the audit delivers actionable results.
  • Address and remediate issues identified in previous audits, and document improvements to demonstrate ongoing security maturity.
You ideally will have:
  • Minimum of 5 years of experience in Web3 security engineering, with proven experience securing blockchain protocols, smart contracts, or cryptographic systems.
  • Expertise in secure coding practices, including identification of code/protocol-level vulnerabilities (e.g., buffer overflows, injection attacks) and code analysis/debugging.
  • Experience with manual/automated code review techniques and penetration testing in Web3 ecosystems.
  • Familiarity with cryptographic protocols, secure protocol design, and blockchain/distributed systems security.
  • Incident response capabilities (detection, analysis, containment, recovery).
  • Experience collaborating with development/product teams to remediate vulnerabilities, including SSDLC processes and external audit preparation.
  • Strong documentation and communication skills for technical materials and stakeholder interactions (internal teams, auditors).
  • Deep interest in blockchain technology and decentralisation.
  • Experience with static and dynamic analysis tools (e.g. CodeQL, Valgrind).
  • Knowledge of formal verification methods and tools.
  • Background in penetration testing or red teaming.
  • Ability to educate and train others on security best practices.
  • Contributions to open-source security projects or published security research.
Hiring process:
  • Interview with our POps team.
  • Interview with the Vac Security unit lead.
  • Take home assignment + discussion with a team member from the Vac Security unit.
  • Interview with a Vac team lead.
Compensation:

We are happy to pay in any mix of fiat/crypto.

Apply for this job

*

indicates a required field

First Name *

Last Name *

Email *

Phone

Resume/CV

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

Save your time! We are only considering candidates with professional experience in blockchain/crypto/web3 * Select...

Link to publicly available projects (e.g Github or LinkedIn) *

Would you be willing to accept part of your payment in Crypto? *

What are your pay expectations? (please provide a gross, annual amount in USD).Please note that we are able to make payments in a wide range of fiat currencies. *

I confirm I have read the privacy notice: * Select...

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Application Security Engineer

Prelim

Remote

USD 120,000 - 150,000

6 days ago
Be an early applicant

Senior Application Security Engineer

Promote Project

Ohio

Remote

USD 67,000 - 123,000

4 days ago
Be an early applicant

Senior Security Engineer, Application & Cloud

Rad AI

Remote

USD 150,000 - 180,000

6 days ago
Be an early applicant

Application Security Engineer

Physna

Remote

USD 110,000 - 220,000

8 days ago

Senior Security Engineer, Application Security

Trail of Bits

Remote

USD 150,000 - 200,000

6 days ago
Be an early applicant

Senior Application Security Engineer

Davita Inc.

Remote

USD 146,000 - 242,000

8 days ago

Software Security Engineer, Detection & Response Engineering (Remote, USA)

Grafana Labs

Remote

Remote

USD 157,000 - 196,000

3 days ago
Be an early applicant

Senior Application Security Engineer New Texas - Remote

Take-Two Interactive

Town of Texas

Remote

USD 90,000 - 130,000

8 days ago

Application Security Engineer

Pennylane

Remote

USD 125,000 - 259,000

30+ days ago