Назад
3 дня назад

Senior Application Security Engineer (Blockchain)

130 000 - 218 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Страна
US/Europe
vacancy_detail.hirify_telegram_tooltipВакансия из Telegram канала -

Мэтч & Сопровод

Покажет вашу совместимость и напишет письмо

Описание вакансии

TL;DR
Senior Application Security Engineer (Blockchain): Embedding security throughout the software development lifecycle for web, mobile, backend, and decentralized applications with an accent on vulnerability assessment, threat modeling, code review, and security testing. Focus on determining bug bounty root causes, developing AI-powered vulnerability tooling, validating patches, and building automation to prevent recurring security issues.

Senior Application Security Engineer

Company

MetaMask

Conditions

5 days agoSalary: 130K - 218K

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will embed security throughout the software development lifecycle and partner with engineers and product managers to design and implement secure products. You will assess, triage, document, and remediate vulnerabilities; conduct threat modeling, design reviews, security testing, and code reviews; validate patches; and build automation and security controls to prevent recurring issues.

Requirements

  • 6+ years of experience building and securing software, including product or application security experience
  • Experience securing modern backend systems, web applications, and APIs
  • Experience performing threat modeling, security design reviews, and vulnerability assessment
  • Experience securing JavaScript-based web or mobile applications
  • Strong coding skills
  • Familiarity with blockchain technology, Ethereum, decentralized applications, and crypto wallets
  • Understanding of web and mobile security attack vectors and mitigations
  • Strong communication and remote collaboration skills
  • Ability to overlap with EU and US-Pacific time zones

Responsibilities

  • Determine the root cause and severity of bug bounty vulnerabilities
  • Interface with ethical hackers, triage reports, and guide engineering teams to resolution
  • Document identified vulnerabilities for engineering action
  • Write code for security engineering projects and vulnerability fixes
  • Develop AI tooling for vulnerability determination and resolution
  • Assess application vulnerabilities and ensure remediation within established SLAs
  • Conduct design reviews, threat modeling, security testing, and code reviews
  • Identify and address gaps in the secure software development lifecycle
  • Participate in team meetings, roadmap planning, and discussions
  • Validate security patches and test for potential bypasses
  • Develop automation and security controls and educate developers to prevent recurring vulnerabilities

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник -