All remote jobs
Open role
Remote opportunity atCertiK

Blockchain Security Expert – Security Audit Track

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
28Listing views
1Application actions
10 Oct 2026Apply before
Opportunity details

About this role.

AI Summary

CertiK is seeking a Blockchain Security Expert to deliver security consulting, audits, reviews, verification, and testing for smart contracts, blockchain infrastructure, Web3 protocols, and dApps. The role centers on manual code review, threat modeling, vulnerability discovery, property-based testing, and gas-related security analysis. Candidates need specialist cybersecurity and auditing knowledge, practical smart-contract or blockchain infrastructure development experience, and familiarity with attacks such as reentrancy, sandwich attacks, and arithmetic vulnerabilities. This is a client-facing, high-accountability role requiring clear English communication and the ability to manage multiple priorities in a startup environment. The US-remote full-time position offers target annual compensation of $120,000 to $180,000.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

4/5
GuidedFull ownership

Communication Load

4/5
IndependentCollaborative
AI insightThe position requires advanced, specialized expertise across blockchain protocols, smart-contract languages, offensive security techniques, and formal security assessment practices. Auditors must identify subtle technical and economic vulnerabilities while delivering reliable findings to clients under competing deadlines.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$150,000
US market range$120k–$190k
AI insightThe disclosed US target annual compensation is $120,000 to $180,000 USD, with a midpoint of $150,000. A competitive US market range for a blockchain security engineer/auditor with specialist smart-contract audit skills is approximately $120,000 to $190,000 annually; actual compensation will vary by audit experience, protocol expertise, and location.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you structure a security audit for a new DeFi smart-contract protocol?

I would first define the protocol's intended behavior, assets at risk, trust assumptions, and privileged roles. Next, I would map the attack surface, conduct manual code and architecture reviews, write or extend targeted tests and fuzzing properties, validate findings with reproducible exploits, and prioritize remediation based on impact and exploitability. I would finish with a clear report that explains root causes, affected components, proof of concept, and practical fixes.

How do you identify and validate reentrancy vulnerabilities?

I look for external calls that occur before internal state updates, including indirect calls through token hooks, callbacks, fallback functions, and cross-contract interactions. I verify exploitability by tracing call paths and creating a minimal malicious receiver or attacker contract. Recommended mitigations usually include checks-effects-interactions, reentrancy guards, pull-payment patterns, and minimizing unnecessary external calls.

What is an economic attack, and how would you assess one?

An economic attack exploits protocol incentives, pricing, liquidity, governance, or oracle assumptions rather than only a coding defect. I model the actor incentives and transaction sequence, then test scenarios such as flash-loan manipulation, sandwiching, oracle distortion, liquidation cascades, and share-price or rounding exploits. I assess feasibility using realistic liquidity, fees, slippage, timing, and profit calculations.

How do property-based tests improve smart-contract security?

Property-based tests validate invariants across a broad range of generated inputs and state transitions instead of checking only predefined examples. For example, I may assert that total assets remain conserved, collateralization rules are maintained, unauthorized actors cannot alter privileged state, and users cannot withdraw more than their entitled balance. Fuzzing these properties helps expose unexpected edge cases and interaction sequences.

How would you communicate a critical audit finding to a client?

I would communicate promptly and clearly, beginning with severity, affected scope, exploit preconditions, and potential impact. I would provide a concise proof of concept or transaction flow, explain the technical root cause in accessible language, and recommend a specific remediation with validation steps. I would remain available to review the patch and confirm whether the issue is fully resolved.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

About You

You’re a self-starter. You believe in tackling the most important problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand that #startuplife means that you’re going to be wearing multiple hats. And that’s what motivates you. You’re accountable and obsessed with improvement, both in yourself and in others. You’re up to the challenge of building a world-class company that aims to be the infrastructure for more secure software for all.

About the Company

CertiK leads blockchain security by securing smart contracts and blockchains with cutting-edge Formal Verification technology. Founded by Computer Science professors of Yale University and Columbia University, CertiK has audited and secured over $500B in assets, including many of the world’s top blockchain projects.

About the Role

The primary responsibility of this role is for CertiK’s security-related services. Intersecting cybersecurity and blockchain, CertiK’s security offerings include security consulting, security reviews, security auditing of smart contracts and blockchains, verification of smart contracts, penetration testing, and more.

As a Security Engineer at CertiK, you will contribute to the security offerings of the company, working with the rest of the security team to deliver the best products and services. You might engage directly with CertiK’s existing and future clients, participate in expanding security-related products and services, and follow the blockchain world on emerging security problems and trends.

Responsibilities

  • Perform end-to-end security services, including consulting, reviewing, auditing, verifying, testing, and delivering detailed security assessments for blockchain systems such as smart contracts, web3 protocols, L1/L2/L3 infrastructures, and dApps.
  • Conduct comprehensive manual code reviews to identify vulnerabilities, logical flaws, economic attacks, and non-obvious edge cases across Solidity, Golang, Rust or other blockchain languages.
  • Develop and refine threat models and attack surfaces, covering economic, technical, operational, and trust-assumption risks for blockchain protocols.
  • Design and execute security tests, including property-based testing and gas-related analysis.

Requirements

  • Bachelor’s degree in Security, Computer Science, Mathematics, Physics, and Engineering
  • The ability to efficiently triage and juggle multiple priorities and deadlines.
  • Specialist-level knowledge of cybersecurity and security auditing. Can write and deploy smart contracts/blockchain infrastructure and write tests with frameworks.
  • Familiar with classic attack vectors and vulnerabilities such as reentrancy, sandwich attacks, overflow/underflow
  • The ability to effectively communicate with the clients and internal team, both verbally in English and in writing, about security services and requirements.
  • [Preferred] Prior hands-on security auditing experience.

What We Offer

  • Opportunity to shape the national conversation on blockchain and security.
  • Collaborate with industry-leading security researchers, technologists, and global institutions.
  • Flexible work environment and mission-driven culture.

Compensation

Additional Information

Compensation: If the role is performed in the US, the target annual compensation is $120,000 – $180,000. The exact compensation at which this job is filled will be determined by the skills and experience of qualified candidates.

#blockchain

#startups

#hiring

CertiK accepts applications for this position on an ongoing basis.

CertiK is proud to offer medical, vision, and dental insurance, 401(k) plan with company matching, life and accidental death and dismemberment insurance, HSA (with high deductible plan), FSA, and other benefits to all full-time employees, along with flexible paid time off and holidays. CertiK also offers a variable commission program for business development sales roles.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

CertiK is proud to be an equal opportunity employer. We will not discriminate against any applicant or employee on the basis of age, race, color, creed, religion, sex, sexual orientation, gender, gender identity or expression, medical condition, national origin, ancestry, citizenship, marital status or civil partnership/union status, physical or mental disability, pregnancy, childbirth, genetic information, military and veteran status, or any other basis prohibited by applicable federal, state or local law.

CertiK will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements.

https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf

All CertiK employees are expected to actively support diversity on their teams, and in the Company.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu