About this role.
This PhD-level internship focuses on building and integrating LLM-powered AI agents that improve blockchain smart-contract security audits. The intern will research agent architectures, fine-tune language models, and experiment with methods for vulnerability detection and risk assessment. The role sits at the intersection of applied AI research, cybersecurity, and blockchain engineering, with an emphasis on translating research into scalable tooling. Strong Python and deep-learning experience are required, while Solidity, Ethereum, and audit-methodology exposure are valuable differentiators.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
5/5Pace & Pressure
4/5Autonomy Level
4/5Communication Load
4/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would combine a contract-aware ingestion pipeline with retrieval of trusted security patterns, audit rules, and relevant code context. The agent should use structured tool calls for static-analysis results and generate findings in a fixed schema containing the vulnerable code path, vulnerability class, confidence, evidence, and remediation guidance. I would validate it against labeled vulnerable and clean contracts, prioritizing precision, recall, and false-positive rates.
I would start with a curated dataset of audited contracts, vulnerability reports, patches, and adversarial examples, ensuring clear licensing and label quality. Depending on available compute and data volume, I would use supervised fine-tuning or parameter-efficient methods such as LoRA, then evaluate on held-out vulnerability families and unseen codebases. I would also include negative examples to reduce unsupported findings and measure performance against baseline static-analysis tools.
I would evaluate technical quality through reproducible benchmarks, expert review, calibration analysis, and regression tests across common vulnerability types. In production, the agent should be positioned as decision support rather than an autonomous authority, with traceable evidence, confidence thresholds, human review, and monitoring for drift. Clear escalation paths and feedback collection from auditors are essential to improve the system safely.
I would first trace external calls and identify whether state changes occur after an untrusted interaction. I would examine call paths, access controls, balance accounting, and whether an attacker can recursively invoke the function before state is updated. I would then recommend mitigations such as checks-effects-interactions, reentrancy guards, pull-payment patterns, and targeted tests that demonstrate exploitability.
I begin by defining measurable user and security requirements, then build a minimal reproducible pipeline with clear interfaces, logging, and evaluation tests. After validating the approach, I optimize inference cost and latency, add robust error handling and observability, and integrate human-feedback loops. I would work closely with auditors and platform engineers to ensure the final system fits real workflows and produces actionable outputs.
About the Company
Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain protocols and smart contracts. CertiK’s mission is to secure the cyber world. Starting with blockchain, CertiK applies cutting-edge innovations from academia into enterprise, enabling mission-critical applications to be built with security and correctness. CertiK is one of the fastest growing and most trusted companies in blockchain security and has become a true market leader. Our clients include leading projects such as Aave, Polygon, Binance Smart Chain, Yearn, and Chiliz. Our investors include top VCs like Tiger Global, Coatue Management, Shunwei Capital and Hillhouse Capital as well as industry leaders like Coinbase Ventures and Binance.
About the Position
The primary focus of this role is to pioneer the development of an intelligent AI agent powered by large language models (LLMs) to enhance our security audit tools in the blockchain space. As a Blockchain Security Expert intern, you will work closely with our blockchain security team to bridge cutting-edge academic research with practical applications. Your efforts will be dedicated to designing, fine-tuning, and integrating LLM-driven AI agents that automatically analyze smart contracts and identify potential vulnerabilities. In this role, you’ll be immersed in research and experimentation, exploring new methods to improve threat detection and risk assessment within our security audit platform, thereby directly contributing to more secure blockchain infrastructures.
Responsibilities
- Collaborate with our blockchain security team to design and implement a large language model (LLM)-based AI agent for security audit tools.
- Experiment with novel AI techniques to enhance threat detection and risk assessment in blockchain environments.
- Assist in transforming cutting-edge research on AI agents into practical, scalable security auditing solutions.
- Continuously research emerging trends in LLMs, AI agent architectures, and cybersecurity, and proactively propose improvements.
Requirements
- Currently pursuing or recently completed a PhD in Artificial Intelligence, Computer Science, or a related field, with a strong emphasis on machine learning, natural language processing, and/or cybersecurity.
- Deep understanding of LLM architectures (e.g., transformers) and hands-on experience in training or fine-tuning such models.
- Proficiency in Python and experience with deep learning frameworks (e.g., PyTorch or TensorFlow).
- Basic familiarity with blockchain technology and smart contract development is a plus.
- Excellent analytical skills, problem-solving capabilities, and the ability to thrive in a fast-paced, innovative startup environment.
- Strong written and verbal communication skills in English.
Bonus Points
- Prior research or project experience in developing AI agents or automated security analysis tools.
- Exposure to security audit methodologies and vulnerability assessment, particularly in blockchain or smart contract environments.
- Familiarity with blockchain programming languages (e.g., Solidity) and platforms (e.g., Ethereum).
- Publications or contributions to leading conferences/journals in AI, NLP, or cybersecurity.
- Demonstrated ability to translate research insights into effective, production-ready tools.
Compensation
Additional Information
Target monthly salary for this role performed is $6,000 – $8,000 if based in the US. The exact compensation at which this job is filled will be determined by the skills and experience of qualified candidates.
CertiK accepts applications for this position on an ongoing basis.
CertiK is proud to offer medical, vision, and dental insurance, 401(k) plan with company matching, life and accidental death and dismemberment insurance, HSA (with high deductible plan), FSA, and other benefits to all full-time employees, along with flexible paid time off and holidays. CertiK also offers a variable commission program for business development sales roles.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
CertiK is proud to be an equal opportunity employer. We will not discriminate against any applicant or employee on the basis of age, race, color, creed, religion, sex, sexual orientation, gender, gender identity or expression, medical condition, national origin, ancestry, citizenship, marital status or civil partnership/union status, physical or mental disability, pregnancy, childbirth, genetic information, military and veteran status, or any other basis prohibited by applicable federal, state or local law.
CertiK will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements.
https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf
All CertiK employees are expected to actively support diversity on their teams, and in the Company.
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.







