About this role.
CertiK is hiring a Blockchain Security Expert to perform smart-contract and blockchain security audits, identify vulnerabilities, and help define attack models. The role also involves analyzing exploited code patterns and developing or maintaining tools for feature code analysis. Candidates need at least three years of experience, foundational information-security knowledge, and proficiency in Solidity, Go, Rust, C++, Python, or Node.js. Strong English communication skills and interest in emerging blockchain security technologies are essential, while static analysis, production pipelines, and Ethereum-related platform experience are preferred.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
5/5Pace & Pressure
4/5Autonomy Level
4/5Communication Load
4/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would first define the protocol's intended behavior, assets, trust boundaries, and threat model. I would then review the architecture and code manually, use static-analysis and testing tools, assess known vulnerability classes such as reentrancy and access-control flaws, and create proof-of-concept tests for validated findings. Finally, I would prioritize findings by impact and likelihood and provide clear remediation guidance.
Reentrancy occurs when an external call transfers control to another contract before the original function has completed its state updates, allowing repeated execution against inconsistent state. Common mitigations include following checks-effects-interactions, using reentrancy guards, minimizing external calls, and using pull-payment patterns where appropriate.
I would use static analysis to systematically identify risky patterns, data-flow issues, dangerous external calls, authorization gaps, and tainted inputs across a codebase. Tool output should be triaged rather than accepted blindly, with manual validation and targeted tests used to distinguish exploitable issues from false positives.
I would collect transaction traces, contract source or bytecode, event logs, and relevant protocol state before and after the incident. I would reconstruct the attack path, identify the violated invariant or vulnerable code path, reproduce the exploit in a controlled environment, and recommend immediate containment plus durable code and monitoring improvements.
I review audit reports, incident postmortems, security research, protocol documentation, and updates from security tooling communities. I also reproduce notable vulnerabilities in test environments and convert recurring exploit patterns into review checklists, detection rules, or analysis-tool improvements.
About the Company
Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain protocols and smart contracts. CertiK’s mission is to secure the cyber world. Starting with blockchain, CertiK applies cutting-edge innovations from academia into enterprise, enabling mission-critical applications to be built with security and correctness. CertiK is one of the fastest growing and most trusted companies in blockchain security and has become a true market leader. Our clients include leading projects such as Aave, Polygon, Binance Smart Chain, Yearn, and Chiliz. Our investors include top VCs like Tiger Global, Coatue Management, Shunwei Capital and Hillhouse Capital as well as industry leaders like Coinbase Ventures and Binance.
About the Position
The primary responsibility of this role is contributing to CertiK’s security-related services at the intersection of cybersecurity and blockchain. CertiK’s offerings include security consulting, security reviews, and security auditing of smart contracts and blockchains, alongside penetration testing and various verification processes.
As a Security Engineer at CertiK, , You’ll discover and analyze security vulnerabilities in blockchain smart contracts, summarize attacked vulnerabilities, and design feature code analysis tools. You’ll also stay up-to-date with analysis tools and new technology trends to further strengthen CertiK’s security offerings and expand our services.
Responsibilities
- Participate in blockchain smart contract audits, identifying, analyzing, and addressing security vulnerabilities.
- Help evaluate and define attack models for blockchain security.
- Summarize and extract key characteristics from exploited code to build and maintain tools for feature code analysis.
- Research and work with different analysis tools, continually learning and adapting to emerging technologies in the space.
Requirements
- A bachelor’s degree (or higher) in full-time education, preferably in a science or engineering field, plus 3+ years of work experience.
- Familiarity with fundamental information security concepts.
- Proficiency in at least one of the following languages: Solidity, Go, Rust, C++, Python, or Node.js, along with a solid grasp of common algorithms.
- A demonstrated ability to function in an English working environment with strong English reading and writing skills.
- A passion for blockchain technology and a drive to learn and adapt to new technologies.
Bonus Points
- Experience working with production pipelines—maintaining or developing them.
- Familiarity with static code analysis (e.g., Syntax Analysis, Semantic Analysis, Taint analysis).
- Exposure to popular blockchain-related platforms and technologies (e.g., Ethereum, Hyperledger, Cosmos).
- Prior knowledge of blockchain smart contracts, security audits, and associated best practices.
- Hands-on blockchain experience such as evaluating risks for blockchain projects or analyzing on-chain security events.
Compensation
Additional Information
Target annual salary for this role performed is $90,000 – $150,000 if based in the US. The exact compensation at which this job is filled will be determined by the skills and experience of qualified candidates.
CertiK accepts applications for this position on an ongoing basis.
CertiK is proud to offer medical, vision, and dental insurance, 401(k) plan with company matching, life and accidental death and dismemberment insurance, HSA (with high deductible plan), FSA, and other benefits to all full-time employees, along with flexible paid time off and holidays. CertiK also offers a variable commission program for business development sales roles.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
CertiK is proud to be an equal opportunity employer. We will not discriminate against any applicant or employee on the basis of age, race, color, creed, religion, sex, sexual orientation, gender, gender identity or expression, medical condition, national origin, ancestry, citizenship, marital status or civil partnership/union status, physical or mental disability, pregnancy, childbirth, genetic information, military and veteran status, or any other basis prohibited by applicable federal, state or local law.
CertiK will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements.
https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf
All CertiK employees are expected to actively support diversity on their teams, and in the Company.
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.







