Назад
Company hidden
10 дней назад

Protocol Security Researcher (DeFi)

Формат работы
remote (Global)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US/Europe
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Protocol Security Researcher (DeFi): Assessing Aave protocol changes, smart contracts, integrations, and critical dependencies with an accent on attacker-driven analysis, protocol-level failure modes, and AI-assisted security review. Focus on identifying exploitable risks, defining reusable invariants and monitoring ideas, and collaborating with auditors and incident response teams.

Location: London, England; Remote in Europe, Asia, or the US. Workplace: Hybrid.

Company

Builds the Aave Protocol, an onchain lending market connecting decentralized finance with individuals, traditional finance, and fintech.

What you will do

  • Review major Aave protocol changes before external audits or deployment.
  • Perform attacker-driven analysis of smart contracts, protocol mechanisms, integrations, and adjacent infrastructure.
  • Contribute to design and architecture discussions and influence security-relevant decisions.
  • Identify risks in assets, bridges, oracles, adapters, and other critical dependencies.
  • Develop and evaluate AI-assisted security tooling for real review workflows.
  • Translate findings into reusable knowledge, invariants, testing, monitoring, and incident-response requirements while collaborating with external auditors.

Requirements

  • 5+ years of relevant security experience.
  • Strong background in smart contract security and the ability to independently review complex codebases.
  • Strong understanding of DeFi mechanisms, including lending, liquidations, accounting, oracles, collateral, governance, and integrations.
  • Ability to reason about protocol-level failure modes and explain how issues could be exploited.
  • Active use of AI to improve security research, review quality, or review throughput.
  • Clear written communication and sound judgment regarding severity, exploitability, and trade-offs.

Nice to have

  • Experience with formal methods, fuzzing, invariant testing, or custom security tooling.
  • Experience building internal tools for security review, code understanding, or knowledge management.
  • Experience working with external audit firms or leading audit engagements.
  • Familiarity with governance payloads, upgrade systems, permissioning, and incident response.
  • Open-source security research, published findings, CTFs, bug bounties, or public vulnerability research.

Culture & Benefits

  • Global team focused on building trusted and reliable financial products.
  • High standards for quality, craftsmanship, and attention to detail.
  • Lean, focused teams with fast execution and long-term thinking.
  • Equal-opportunity workplace that values diversity, safety, and individual identity.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →