Security Engineer

Stacks Labs

United States

Remote

USD 160,000 - 200,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
Life insurance
Disability insurance
Parental leave up to 16 weeks
Home/remote office stipend
Learning and development stipend
Open vacation policy
401(k) with match

Job summary

Stacks Labs is seeking a Security Engineer to work with the CTO to build secure systems including the sBTC signer network, the Stacks node, and smart contracts.

This is a fully remote role with a globally distributed engineering team. You’ll be hands-on, hunting vulnerabilities, writing tests, and shipping security as code.

You will review security-sensitive PRs, build AI-driven tooling, and lead incident response with blameless postmortems.

Qualifications

  • 5+ years in software engineering and security.
  • Strong programming foundation in Rust, Go, C, TypeScript, or Python.
  • Hands-on offensive or defensive security experience.
  • Ability to work remotely across time zones.
  • Fluency with AI tooling in security work.

Responsibilities

  • Threat model and attack our software, infrastructure, and contracts.
  • Build and run fuzzing, property-based, and adversarial test harnesses.
  • Coordinate internal red-team exercises and external audits.
  • Review security-sensitive PRs and build AI-driven security tooling.

Skills

Security engineering
Rust
Go
C
TypeScript
Python
Cryptography
Incident response
AI tooling

Job description

As a Security Engineer at Stacks Labs, you'll work with the CTO to help building secure systems, including the sBTC signer network, the Stacks node, our smart contracts, and the infrastructure and release pipeline that ship them.

You'll operate autonomously in a fully remote role, embedded with a globally distributed engineering team. This is a hands-on role for someone who would rather find and fix the bug instead of writing a slide about it.

As a Security Engineer at Stacks Labs, you'll work with the CTO to help building secure systems, including the sBTC signer network, the Stacks node, our smart contracts, and the infrastructure and release pipeline that ship them.

You'll operate autonomously in a fully remote role, embedded with a globally distributed engineering team. This is a hands-on role for someone who would rather find and fix the bug instead of writing a slide about it.

Outcomes You'll Drive
  • We find our vulnerabilities before anyone else does
  • You hunt through code, infrastructure, and deployments with an attack's mindset. The things you find get triaged, remediated, fixed.
  • Security that ships as code
  • Your work produces pull requests, hardened configs, detection rules, and tests. Engineers see you as someone who makes their systems better, not someone who slows them down.
  • A hardened perimeter where it matters
  • Key custody, secrets management, access control, CI/CD, and the software supply chain are locked down against the realistic threats to a system securing crypto-assets.
  • An AI-augmented security practice
  • LLMs and coding agents multiply your reach across code review, fuzzing, triage, and log analysis. You know exactly where they help, where they lie, and how to build systems that leverage them to scale things up.
  • Calm, rehearsed incident response
  • When something goes wrong there's a playbook, a clear owner, and a blameless postmortem that leaves the system stronger than before.
What You'll Do
Offense
  • Threat model and attack our software, infrastructure, and contracts. Write exploits against our own systems before adversaries do.
  • Build and run fuzzing, property-based, and adversarial test harnesses.
  • Run internal red-team exercises and coordinate external audits and bug bounty programs, triaging and validating what comes back.
Defense
  • Detection and monitoring: what does "compromised" look like, and how do we know within minutes rather than days?
  • Harden hosts, CI/CD, and the software supply chain. Audit dependencies and design reproducible builds and signed/attested releases.
  • Support incident response and post-incident reviews.
Engineering & Tooling
  • Review security-sensitive PRs across the codebase and pair with engineers on secure design.
  • Build AI-driven security tooling: agents for code review and dependency triage, LLM-assisted log analysis, automated first-pass audits of new contracts and integrations.
  • Write clear, actionable findings and advisories for internal teams, external signers, and partners.
What We're Looking For
  • Security is what you do for fun, not just for work. CTFs, bug bounties, side research, reading advisories at breakfast.
  • 5+ years in software engineering and ****a meaningful portion of it in security. Red team, blue team, appsec, detection engineering, or security research.
  • Solid programming foundation. You read and write production code (Rust, Go, C, TypeScript, Python, or similar), and you understand systems, networking, and cryptography.
  • Hands-on offensive or defensive experience: exploit development, pentesting, incident response, detection engineering, or hardening production systems.
  • Pragmatism. You measure yourself in closed attack paths and shipped fixes. You know risk matrices exist, but you don't lead with them.
  • Fluency with AI tooling. You use LLMs and coding agents daily in security work, you've built something with them, and you have grounded opinions about their failure modes.
  • Strong written communication. Findings, advisories, and design reviews that people actually read and act on.
  • Comfort working remotely and autonomously across time zones.
Nice to Have
  • Expertise in Rust, our primary language.
  • Bitcoin protocol internals, or experience auditing smart contracts (Clarity, Solidity, or similar).
  • Threshold signatures, MPC, or applied cryptography.
  • Security of distributed systems and consensus protocols.
  • Cloud and infrastructure security.
  • Experience building AI agents for security workflows, or securing systems that integrate LLMs.
  • A public track record: CVEs, published research, notable CTF placings, or bug bounty history.
What We Offer
  • Competitive compensation including $160,000-$200,000 USD base salary.
  • Stacks (STX) tokens - STX is the native cryptocurrency of the Stacks network.
  • Comprehensive health coverage and free life and disability insurance.
  • Up to 16 weeks of paid parental leave to support you through one of life's biggest transitions.
  • Monthly stipends for your home office or co-working space of choice.
  • Annual learning and development stipend to keep growing your skills.
  • An open vacation policy, take the days you need when you need.
  • 401(k) with a 3% match.
  • A high-ownership role shaping some of the most critical infrastructure in the Stacks ecosystem.
  • A fast-moving, focused team where strong engineering judgment is valued and where your work will ship quickly and visibly.
  • The chance to define engineering standards for one of the most ambitious Bitcoin L2 ecosystems, shaping how Bitcoin moves in and out of smart contracts.
  • A remote-first culture with flexibility, autonomy, and deep collaboration with product and engineering.

Stacks Labs is proud to be an equal opportunity employer and deeply cares about building a diverse team. Stacks Labs is committed to building an inclusive environment for people of all backgrounds. We do not discriminate on the basis of race, color, gender, sexual orientation, gender identity or expression, religion, disability, national origin, protected veteran status, age, or any other status protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Security Engineer: Build & Secure Crypto Infra
Remote Security Engineer: Build & Secure Crypto Infra

Stacks Labs • United States

Remote
USD 160,000 - 200,000
Health insurance
Life insurance
Disability insurance
+5
Security Automation Engineer
Security Automation Engineer

Stackline • Seattle (WA)

On-site
USD 140,000 - 160,000
Medical, dental, vision with HSA
401(k) with company match
PTO 20 days + 9 holidays
+2
Senior Software Engineer, Agentic Systems
Senior Software Engineer, Agentic Systems

StackHawk Inc. • Denver (CO), Northern (KY)

On-site
USD 150,000 - 200,000
Competitive compensation
Equity stake
Health, dental, vision 100% covered
+3
Senior Software Engineer - Encryption & PHI
Senior Software Engineer - Encryption & PHI

StackAI • United States

On-site
USD 248,000 - 282,000
Security Engineer, Bare Metal
Security Engineer, Bare Metal

Fluidstack • New York (NY)

On-site
USD 150,000 - 230,000
Senior Developer Relations Engineer
Senior Developer Relations Engineer

Trail of Bits • Northern (KY)

On-site
USD 160,000 - 200,000
Salary bonuses
Health, dental, vision insurance
401(k) match
+7
Forward Deployed AI Engineer (Python) - Remote - USA
Forward Deployed AI Engineer (Python) - Remote - USA

FullStack • Madison (WI)

Remote
USD 140,000 - 240,000
100% remote work
Health, dental, and vision insurance
401(k) with 4% match
+1
Regional Security Operations Lead
Regional Security Operations Lead

Fluidstack • Austin (TX)

On-site
USD 140,000 - 210,000
Health insurance
Retirement plan
Generous PTO
+1
Security Engineer, Infrastructure
Security Engineer, Infrastructure

Fluidstack • Austin (TX)

On-site
USD 170,000 - 220,000
Health, dental, and vision insurance
Generous PTO policy
Retirement plan
Full Stack Software Developer (Remote locations)
Full Stack Software Developer (Remote locations)

Halborn • Myrtle Point (OR)

On-site
USD 120,000 - 180,000