All remote jobs
Open role
Remote opportunity atConsensys

Senior Application Security Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
41Listing views
1Application actions
15 Sep 2026Apply before
Opportunity details

About this role.

AI Summary

This full-time Senior Application Security Engineer role supports MetaMask and embeds security throughout the software development lifecycle for web, mobile, backend, and API products. The engineer will triage bug-bounty reports, perform threat modeling and design/code reviews, validate patches, and develop automation and AI-assisted security tooling. Candidates need 6+ years of software and application-security experience, strong coding skills, and familiarity with JavaScript systems, Ethereum, decentralized applications, and crypto wallets. The organization is fully remote and distributed, requiring overlap with EU and US-Pacific time zones and strong independent collaboration. The US base pay range is $130,000–$218,000 USD, while compensation outside the US varies by location and experience.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a senior, security-critical role protecting a widely used crypto wallet and decentralized application platform. It requires deep hands-on application security expertise, strong engineering ability, effective vulnerability triage, and domain familiarity with Ethereum, wallets, and modern web/mobile attack surfaces.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$174,000
US market range$150k–$230k
AI insightThe posting explicitly discloses a US pay range of $130,000–$218,000 USD, excluding bonus, equity, and other benefits. For this full-time role, the stated base-pay range is treated as yearly; the offer median is $174,000. A competitive US market range for a senior application security engineer with Web3 and wallet-security responsibilities is estimated at $150,000–$230,000 annually, depending on location, depth of application-security expertise, and blockchain specialization.

Core skills

Skills and capabilities most closely associated with this opportunity.

Cover letter sample

Dear Hiring Team,

I am excited to apply for the Senior Application Security Engineer role supporting MetaMask. My background in application security includes threat modeling, secure design and code reviews, vulnerability triage, and partnering directly with engineering teams to remediate risk across web, API, and mobile systems.

I am particularly drawn to the opportunity to protect products that manage users’ assets and digital identities, and I would bring a practical, developer-focused approach to strengthening the SSDLC and security automation. I am comfortable operating independently in distributed teams while communicating clearly with engineers, product leaders, and external security researchers.

I would welcome the opportunity to help MetaMask build resilient, secure Web3 experiences at global scale.

Sample interview questions
How would you triage and manage a high-severity vulnerability submitted through a bug bounty program?

I would first validate reproducibility and assess the affected assets, attack preconditions, exploitability, user impact, and potential blast radius. I would assign severity using a consistent risk framework, communicate a concise remediation path to the owning team, validate the patch and potential bypasses, then capture preventive controls or tests for recurrence.

Describe your approach to threat modeling a new MetaMask feature.

I begin by mapping assets, trust boundaries, data flows, identities, privileged operations, and third-party dependencies. I then identify likely threats using a structured approach such as STRIDE, prioritize them by likelihood and impact, and turn the findings into concrete design requirements, security tests, and engineering tickets.

What security concerns would you prioritize when reviewing a JavaScript-based web or mobile application?

I would examine authentication and authorization boundaries, input validation, secret and key handling, dependency risk, API abuse controls, logging, and error handling. For JavaScript clients, I would also focus on XSS, unsafe message passing, injection risks, supply-chain exposure, browser-extension permissions, and secure handling of sensitive wallet interactions.

How do you influence product engineers to adopt secure development practices in a high-autonomy remote environment?

I would make security guidance actionable by providing minimal reproducible examples, clear risk context, recommended code patterns, and automated checks where possible. I would build trust through collaborative reviews, timely support during remediation, and metrics that show reduced recurrence rather than treating security as a gatekeeping function.

How would you safely introduce AI-assisted tooling for vulnerability analysis and remediation?

I would evaluate whether the proposed tooling reliably improves signal quality, protects sensitive source and vulnerability data, and integrates safely into the engineering workflow. I would use human review for consequential decisions, measure false positives and false negatives, restrict access and data retention, and continuously test the tooling against adversarial or unsafe outputs.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

Consensys is the leading blockchain and web3 software company. Founded by Joe Lubin, CEO of Consensys and Co-Founder of Ethereum in 2014, Consensys has been at the forefront of innovation, pioneering technological developments within the web3 ecosystem.

The financial system is being rebuilt on open, programmable infrastructure, and Consensys is helping power that transition. From MetaMask, the platform trusted by tens of millions of users worldwide, to Linea, the only 100% proven zkEVM rollup and an emerging home for institutional ETH capital, Consensys builds products and infrastructure that enable users, developers, and institutions to participate in the next generation of the internet.

Our mission is to unlock the collaborative power of communities by making the decentralized web universally easy to access, use, and build on.

Joining Consensys means working with a fully remote, globally distributed team of technologists, designers, cryptographers, product thinkers, and researchers who are building the next layer of the internet. You’ll be exposed to new ideas, emerging technologies, and complex challenges that push you to stay at the top of your game while helping scale products and infrastructure used by tens of millions of users and thousands of developers across the web3 ecosystem. You’ll join a network of builders that reaches the edge of our ecosystem. Consensys alumni have moved on to become tech entrepreneurs, CEOs, and team leads at tech companies.

About MetaMask

We’re building for a future where the internet and world economy empowers people through interactions based on consent, privacy, and free association. Where both communities and individuals flourish. To accomplish that, we’re working hard to make web3 accessible for everyone around the world.

MetaMask is both a crypto wallet and a gateway to the decentralized web. Our tools help people create communities, play video games, access financial services, make payments, invest in assets, protect against economic turmoil, and more. Our browser extension and mobile platforms meet the needs of millions of users and developers across the world.

Originally a humble key manager, today MetaMask serves over 30 million monthly active users as a decentralized application development platform, an aggregator of decentralized cryptocurrency exchanges, and a decentralized identity manager.

About the Role

MetaMask has experienced explosive user growth over the past year as a cryptographic key manager and web3 application development platform. As this user base continues to grow, an immense amount of trust is being placed in MetaMask as a tool that manages and wields their digital authority, controlling assets, identities and more. It is of highest importance to us that we keep our users as safe and secure as possible.

We are looking for a Senior Application Security Engineer to join our rapidly growing security team to help embed security into all phases of the software development lifecycle. You would work closely with development teams and product managers to ensure MetaMask products are designed and implemented to the highest security standards. Consenys’s application security team primarily supports MetaMask with opportunities to expand to additional products in the Consensys family.

To apply for this position, you must have:

  • 6+ years of experience building and securing software, including hands-on product or application security experience.
  • Experience securing modern backend systems, web applications, and APIs.
  • Experience performing threat modelling, security design reviews, and vulnerability assessment.
  • Experience securing JavaScript-based applications across web and/or mobile (Node.js, React, React Native preferred).
  • Strong coding skills, with the ability to work directly with engineers to identify and fix vulnerabilities or build secure solutions.
  • Familiarity with Blockchain technology (particularly Ethereum), Decentralized Applications and crypto wallets
  • Solid understanding of the modern web and mobile security landscape, including common attack vectors and mitigations.
  • Strong communication skills, with the ability to influence engineering decisions and collaborate effectively in a remote environment.
  • Self-driven and proactive, comfortable operating in a high-autonomy, distributed team.
  • Alignment with our mission and values.

Timezone: Most timezones will work. Regardless of where you are, some overlap with EU and US-Pacific time zones will be necessary.

Nice to have:

  • Experience working as a software developer.
  • Deep knowledge of Ethereum (and other blockchains), Decentralized Applications and crypto wallets.
  • Knowledge of smart contract implementation and security.
  • You’re a MetaMask user!

Responsibilities

  • Determine the root cause and severity of vulnerabilities reported to us through our bug bounty platform.
  • Interface with ethical hackers, triage reports, and guide product engineering teams to resolution.
  • Document identified vulnerabilities in a way that allows for our engineering team to take quick action.
  • Write code to support the development of security engineering projects, or fix vulnerabilities in MetaMask client applications. This includes the development of AI tooling for vulnerability determination and resolution in order to keep pace with the changing AI-powered vulnerability detection landscape.
  • Assess potential security vulnerabilities within our applications, and work with development teams to ensure remediation in our established SLAs.
  • Support product teams as they develop new features by conducting design reviews, threat modeling, security testing, and code reviews.
  • Identify gaps in MetaMask’s secure software development life cycle (SSDLC), and take initiative leading efforts to address them.
  • Participate and contribute to team meetings, roadmap planning, and discussions.
  • Validate that security patches address reported vulnerabilities and test for any potential bypasses
  • Proactively prevent future occurrences of a vulnerability through developing automation, security controls, and educating developers.
  • Pave your own path in how you want to make MetaMask more secure.

Don’t meet all the requirements? Don’t sweat it. We’re passionate about building a diverse team of humans and as such, if you think you’ve got what it takes for our chaotic-but-fun, remote-friendly, start-up environment—apply anyway, detailing your relevant transferable skills in your cover letter. While we have a pretty good idea of what we need, we’re ready for you to challenge our thinking on who needs to be in this role.

It is a requirement of employment in this position that applicants will be required to submit to background checks including but not limited to employment, education and criminal record checks. Further details will be provided to applicants that successfully meet the criteria for the position as determined by the company in its sole discretion. By submitting an application for employment, you are acknowledging and consenting to this requirement.

The salary range listed for this role applies to US-based candidates only. Compensation for candidates based outside the US (including Canada, EMEA, and LATAM) will be determined based on location, experience, and skills during the interview process, and may differ from the listed US range.

US pay range (not including bonus, equity or other benefits)

$130,000—$218,000 USD

In the rapidly evolving Web3 space, we believe that everyone is a builder. This expansive paradigm requires a range of backgrounds, talents, skills, and experiences to influence and shape the future. At Consensys, this diversity fuels our ability to shift control and redefine the realm of possibility. We are committed to ensuring that our technology empowers people and communities with economic and political agency through decentralized technologies. We welcome the range of perspectives and differences and celebrate them. We’re excited to see how your unique skills as a builder can contribute to our vision, drive innovation, and help us shape a more inclusive Web3.

Consensys is an equal opportunity employer. All employment decisions are made without regard to race, color, national origin, ancestry, sex, gender, gender identity or expression, sexual orientation, age, genetic information, religion, disability, medical condition, pregnancy, marital status, family status, veteran status, or any other characteristic protected by law. Consensys is aware of fraudulent recruitment practices and we encourage all applicants to review our best practices to protect yourself which can be found (https://consensys.io/careers/best-practices-to-avoid-recruitment-fraud/).

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.
Application method

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
or continue without an account
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent Salaries
Menu