← 返回岗位列表中国IT/互联网fulltime

应用安全工程师

雇主

RootstockLabs

地点

远程 · 中国

待遇

面议

工作模式

远程

截止日期

12月12日

🤖 AI 简历匹配评估

检测你的简历与该岗位的匹配度,免费

免费评估

岗位摘要

NOTE: As part of our hiring process, we conduct background and reference checks at the to validate relevant experience, qualifications, location and professional history.

岗位职责

NOTE: As part of our hiring process, we conduct background and reference checks at the to validate relevant experience, qualifications, location and professional history.
ABOUT THE ROLE
As an Application Security Engineer at RootstockLabs, you will help secure our Bitcoin-secured DeFi infrastructure by reviewing code, smart contracts, and protocol changes, and by building the security automation that keeps our development lifecycle safe. You will work closely with development teams on threat modeling and architecture reviews, manage our bug bounty program end to end, and coordinate external security audits with third-party auditors. You will also research attack techniques relevant to our ecosystem (EVM, bridges, p2p) and translate them into concrete defenses, and support incident investigations when application-layer issues arise.
KEY RESPONSIBILITIES
Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects
Participate in design and architecture reviews; threat-model new products and features with development teams
Triage and validate bug bounty reports; assess severity and coordinate remediation with engineering
Collaborate on external security audits: scope engagements and work with third-party auditors through to the resolution of findings
Build and operate security automation, including AI-assisted code review, scanning, and findings-triage pipelines
Research attack techniques relevant to the ecosystem (EVM, bridges, p2p) and turn findings into concrete defenses: monitoring alerts, CI security checks, and hardening changes
Support incident investigations when application-layer issues arise
WHAT YOU BRING
3+ years of experience in Application Security or Security Engineering
Solid grasp of common vulnerability classes (OWASP Top 10) and secure code review in Java plus at least one of TypeScript/JavaScript, Python, Go, or Rust
Hands-on experience with blockchain security: smart contract auditing (Solidity/EVM) or protocol/node-level security
Experience building and operating security automation, AI-assisted workflows (LLM-based triage, code review, or scanning), SAST/DAST, dependency and secret scanning, and CI/CD security gates
Fluent English
NICE TO HAVE
Experience in bug bounty triage or vulnerability disclosure programs
Experience mitigating network-level attacks (p2p, eclipse, DoS) or analyzing consensus-level attack scenarios
Offensive security background (pentesting, red team, CTFs, exploit development)
Public security research: CVEs, bug bounty track record, audit reports, conference talks
Knowledge of C/C++ (for node/client codebases)
Experience with fuzzing (smart contracts or native code)
ROOTIES BENEFITS
At RootstockLabs, we don’t just offer a job, we offer a community. Here’s what you can expect when you join us:
Competitive compensation package and unique benefits designed to support your growth and well-being.
100% Remote Work working within a Central European to Argentinian time-zone window (UTC-3 to UTC+2, with about an hour's flexibility either side), and with access to global coworking spaces.
Work-Life Balance: Paid vacation and sick leave days
Continuous Learning: Access to training programs, language courses, and learning sponsorship annually.
Unique Projects: Work with cutting-edge blockchain technology in a global, diverse team.
ABOUT ROOTSTOCKLABS
RootstockLabs builds Bitcoin-secured DeFi infrastructure that enables companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale.
Market: Companies, financial institutions, and their customers
Product: Bitcoin-secured DeFi financial products
Distribution: B2B2C through regulated financial institutions
We operate at the intersection of crypto infrastructure and institutional finance, enabling compliant, scalable access to decentralized financial services powered by Bitcoin.
Originally posted on Himalayas

申请条件

3+ years of experience in Application Security or Security Engineering
Solid grasp of common vulnerability classes (OWASP Top 10)
Secure code review skills in Java
Secure code review skills in at least one of TypeScript/JavaScript, Python, Go, or Rust
Hands-on experience with blockchain security
Experience with smart contract auditing (Solidity)
Ability to perform security reviews of source code, smart contracts, and protocol changes
Ability to participate in design and architecture reviews
Ability to threat-model new products and features with development teams
Experience triaging and validating bug bounty reports
Ability to assess severity and coordinate remediation with engineering
Experience collaborating on external security audits, including scoping engagements and working with third-party auditors
Experience building and operating security automation (e.g., AI-assisted code review, scanning, findings-triage pipelines)
Knowledge of attack techniques relevant to EVM, bridges, and p2p ecosystems
Ability to translate research findings into concrete defenses (monitoring alerts, CI security checks, hardening changes)
Ability to support incident investigations for application-layer issues
Willingness to undergo background and reference checks

雇主简介

RootstockLabs 专注于比特币安全的 DeFi 基础设施,提供基于 EVM 的智能合约平台和协议开发。

对这个岗位感兴趣?

该岗位暂未开放在线申请,顾问可为您推荐同类岗位或申请指导

咨询不收取任何费用,顾问将为您推荐合适的岗位与申请方式

投递国内企业,你的简历符合 HR 筛选标准吗?

AI 自动评估你与该岗位的匹配度,3 分钟出结果

免费评估简历匹配度

数据来源:Himalayas

岗位信息来源于公开渠道,版权归原作者所有