About this role.
CertiK seeks a senior blockchain security engineer to audit smart contracts, blockchain protocols, nodes, and decentralized applications. The role combines hands-on vulnerability assessment, client security consultation, independent research, and development of internal security tooling. Candidates need at least three years of relevant engineering or security experience and two years of blockchain experience across ecosystems such as EVM, Solana, Move, Cosmos, or SDKs. Strong threat-modeling, risk-analysis, and Rust, Go, Solidity, or Python skills are central to success in this US remote full-time position.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
5/5Pace & Pressure
4/5Autonomy Level
5/5Communication Load
4/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would first establish the protocol’s intended invariants, trust boundaries, privileged roles, and asset flows. I would then review architecture and dependencies, perform manual code analysis for common and protocol-specific vulnerabilities, create adversarial test cases and fuzzing or invariant tests, and prioritize findings by exploitability and impact. Finally, I would provide reproducible proofs of concept and clear remediation recommendations, then validate fixes through a follow-up review.
I would identify assets, actors, entry points, trust assumptions, and dependencies such as peer-to-peer networking, RPC endpoints, consensus components, and key management. I would evaluate threats including denial of service, consensus manipulation, eclipse attacks, malformed-message handling, authorization failures, and dependency compromise. The resulting model would map mitigations to each risk and define tests or monitoring controls that verify those mitigations.
Bridges require close examination of validator or relayer trust models, message authenticity, replay protection, finality assumptions, signature verification, upgradeability, and withdrawal accounting. I would verify that messages cannot be forged, replayed, reordered unsafely, or processed before sufficient source-chain finality. I would also assess key compromise scenarios and ensure controls such as threshold signing, rate limits, pausability, and monitored anomaly detection are appropriate.
I would maintain a structured workflow that protects client deadlines while reserving focused time for research that improves audit coverage and tooling. Research findings should be translated into reusable detection methods, testing patterns, or audit checklists whenever possible. For clients, I would communicate risks precisely, explain business impact without unnecessary alarm, and provide actionable remediation paths.
Rust and Go allow an auditor to understand and assess node implementations, SDK behavior, networking code, cryptographic integrations, and concurrency risks beyond smart contracts. I can use that expertise to build targeted test harnesses, static-analysis checks, fuzzers, or proof-of-concept exploits. It also helps distinguish application-layer issues from underlying protocol or client implementation weaknesses.
About the Role:
We are seeking a Senior Blockchain Security Engineer with a strong security mindset and deep technical expertise across smart contracts, blockchain nodes, and decentralized infrastructure. You will play a critical role in safeguarding Web3 projects by auditing code, building security tools, and driving research. If you have hands-on experience in Web3 and are passionate about advancing the security of decentralized technologies, we’d love to hear from you.
Responsibilities
- Audit and review codebases for smart contracts, blockchain protocols, and decentralized applications (dApps) to identify and remediate vulnerabilities.
- Work closely with external blockchain teams to enhance the security of their products by providing expert security consultation and implementing remediation strategies.
- Conduct independent security research, explore new attack vectors, and deliver actionable insights.
- Design, develop, and maintain internal security tools and frameworks to strengthen our security services.
- Continuously improve internal processes, methodologies, and service offerings while ensuring high client satisfaction and long-term partnerships.
Requirements
- Bachelor’s, Master’s, or PhD in Mathematics, Computer Science, or Information Security.
- Minimum 3 years of professional experience as a Software Engineer, Security Engineer, or in a related role.
- At least 2 years of hands-on experience with blockchain technologies, including: Smart contracts (EVM chains, Solana, Move, etc.), Blockchain protocols (nodes, SDKs, Cosmos, etc.)
- Strong expertise in threat modeling, risk assessment, and security analysis.
- Proficiency in one or more programming languages: Rust, Go, Solidity, Python, etc.
- Passion for Cryptocurrency, DeFi, and Blockchain technologies.
Preferred Qualifications
- Solid academic or practical background in Mathematics, Cryptography, or Cybersecurity.
- Demonstrated experience conducting audits and collaborating with leading Web3 protocols.
- Recognized achievements such as published CVEs, or strong placements in Attackathons, Bug Bounties, or Audit Contests.
Compensation
Additional Information
About the Company
CertiK is the largest blockchain security auditor and provides a comprehensive suite of tools to secure the industry at scale. To date, CertiK has worked with over 4,900 Enterprise clients, secured over $557 billion worth of digital assets, and has detected over 18,000 vulnerabilities in blockchain code. Our clients include leading projects such as OKX, Tether, Ripple, and Pancakeswap. Our investors include top VCs like Tiger Global, Coatue Management, Shunwei Capital and Hillhouse Capital as well as industry leaders like Coinbase Ventures and Binance.
Investors = Insight Partners, Sequoia, Tiger Global, Coatue Management, Lightspeed, Advent International, SoftBank, Hillhouse Capital, Goldman Sachs, Shunwei Capital, IDG Capital, Wing, Legend Star, Danhua Capital and other investors.
About You
You’re a self-starter. You believe in tackling the most important problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand that startup life means that you’re going to be wearing multiple hats. And that’s what motivates you. You’re accountable and obsessed with improvement, both in yourself and in others. You’re up to the challenge of building a world-class company that aims to be the infrastructure for more secure software for all.
Compensation
Target annual salary for this role performed in the US is $102,000 – $180,000.
The exact compensation at which this job is filled will be determined by the skills and experience of qualified candidates.
CertiK is proud to offer medical, vision, and dental insurance, 401(k) plan with company matching, life and accidental death and dismemberment insurance, HSA (with high deductible plan), FSA, and other benefits to all full-time employees, along with flexible paid time off and holidays. CertiK also offers a variable commission program for business development sales roles.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
CertiK is proud to be an equal opportunity employer. We will not discriminate against any applicant or employee on the basis of age, race, color, creed, religion, sex, sexual orientation, gender, gender identity or expression, medical condition, national origin, ancestry, citizenship, marital status or civil partnership/union status, physical or mental disability, pregnancy, childbirth, genetic information, military and veteran status, or any other basis prohibited by applicable federal, state or local law.
CertiK will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements.
https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf
All CertiK employees are expected to actively support diversity on their teams, and in the Company.
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.






