About this role.
CertiK is hiring a junior Blockchain Security Engineer to support audits of smart contracts, blockchain protocols, and decentralized applications. The role combines vulnerability assessment, guided security research, and contributions to internal security tooling and audit methodologies. Candidates need foundational blockchain experience across EVM, Solana, Move, nodes, SDKs, or related decentralized infrastructure, plus proficiency in languages such as Rust, Go, Solidity, or Python. This is a US-remote, full-time opportunity with a disclosed annual salary range of $102,000 to $180,000. Strong academic grounding in computer science, mathematics, information security, cryptography, or demonstrated Web3 security achievements is advantageous.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
4/5Pace & Pressure
4/5Autonomy Level
3/5Communication Load
4/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would first understand the protocol's intended behavior, trust boundaries, privileged roles, and asset flows. Then I would review the code systematically for common issues such as access-control flaws, reentrancy, unsafe external calls, oracle manipulation, arithmetic assumptions, and upgradeability risks, while creating test cases or proofs of concept for suspected issues. Finally, I would document findings with severity, impact, reproduction steps, and practical remediation guidance.
Reentrancy occurs when a contract makes an external call before updating its internal state, allowing the recipient to call back into the original function and potentially repeat an action such as withdrawing funds. Common mitigations include following checks-effects-interactions, using reentrancy guards, minimizing external calls, and employing pull-payment patterns where appropriate.
I would identify critical assets, actors, privileged roles, external dependencies, entry points, and trust assumptions. I would map attack paths involving smart contracts, off-chain services, bridges, wallets, governance, and oracle integrations, then assess likelihood and impact for each risk. The output would prioritize mitigations, monitoring controls, and test scenarios for the highest-risk assumptions.
For EVM contracts, I would focus on Solidity or Vyper semantics, call behavior, storage layout, delegatecall, proxy patterns, and gas-related execution assumptions. For Solana programs, I would closely examine account ownership, signer validation, program-derived addresses, account initialization, serialization, cross-program invocations, and rent or authority handling. In both cases, I would validate that authorization and state transitions match the protocol's intended invariants.
I would provide a concise title and severity assessment, explain the affected components and security impact, and include a minimal reproducible proof of concept where possible. I would clearly state assumptions, recommend a prioritized fix, and identify any regression tests or monitoring measures needed. During discussion, I would remain collaborative and ensure the team understands both the technical root cause and the business risk.
About the Company
CertiK is the largest blockchain security auditor and provides a comprehensive suite of tools to secure the industry at scale. To date, CertiK has worked with over 4,900 Enterprise clients, secured over $557 billion worth of digital assets, and has detected over 18,000 vulnerabilities in blockchain code. Our clients include leading projects such as OKX, Tether, Ripple, and Pancakeswap. Our investors include top VCs like Tiger Global, Coatue Management, Shunwei Capital and Hillhouse Capital as well as industry leaders like Coinbase Ventures and Binance.
About the Role
We are seeking a Junior Blockchain Security Engineer with a strong security mindset and foundational technical expertise across smart contracts, blockchain nodes, and decentralized infrastructure. In this role, you will support Web3 projects by assisting in code audits, contributing to security tools, and conducting research under guidance. If you are eager to grow your career in blockchain security and passionate about securing decentralized technologies, we’d love to hear from you.
Responsibilities
- Audit and review codebases for smart contracts, blockchain protocols, and decentralized applications (dApps) to identify and remediate vulnerabilities.
- Conduct guided security research, explore new attack vectors, and deliver actionable insights.
- Contribute to the design, development, and maintenance of internal security tools and frameworks.
- Support improvements to internal processes, methodologies, and service offerings, ensuring high-quality delivery for clients.
Requirements
- Bachelor’s, Master’s, or PhD in Mathematics, Computer Science, or Information Security.
- At least 1 years of hands-on experience with blockchain technologies, including: Smart contracts (EVM chains, Solana, Move, etc.), Blockchain protocols (nodes, SDKs, Cosmos, etc.)
- Experience in threat modeling, risk assessment, and security analysis.
- Proficiency in one or more programming languages: Rust, Go, Solidity, Python, etc.
- Passion for Cryptocurrency, DeFi, and Blockchain technologies.
Preferred Qualifications
- Solid academic or practical background in Mathematics, Cryptography, or Cybersecurity.
- Demonstrated experience conducting audits and collaborating with leading Web3 protocols.
- Recognized achievements such as published CVEs, or strong placements in Attackathons, Bug Bounties, or Audit Contests.
Compensation
Additional Information
Compensation
Target annual salary for this role performed in the US is $102,000 – $180,000. The exact compensation at which this job is filled will be determined by the skills and experience of qualified candidates.
CertiK accepts applications for this position on an ongoing basis. CertiK is proud to offer medical, vision, and dental insurance, 401(k) plan with company matching, life and accidental death and dismemberment insurance, HSA (with high deductible plan), FSA, and other benefits to all full-time employees, along with flexible paid time off and holidays. CertiK also offers a variable commission program for business development sales roles.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. CertiK is proud to be an equal opportunity employer. We will not discriminate against any applicant or employee on the basis of age, race, color, creed, religion, sex, sexual orientation, gender, gender identity or expression, medical condition, national origin, ancestry, citizenship, marital status or civil partnership/union status, physical or mental disability, pregnancy, childbirth, genetic information, military and veteran status, or any other basis prohibited by applicable federal, state or local law.
CertiK will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements. https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf
All CertiK employees are expected to actively support diversity on their teams, and in the Company.
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.






