Senior Security Engineer
About the Company
CertiK is a reputable Web3 security company founded in New York City in 2017. The company specializes in securing blockchain protocols, smart contracts, and decentralized applications through advanced security research, formal verification, and AI-powered technology. CertiK offers comprehensive security solutions, including smart contract audits, penetration testing, on-chain monitoring, incident response, and compliance services for prominent digital asset projects.
CertiK has a global presence, serving numerous enterprise clients and Web3 projects worldwide. The company has a diverse international team across North America, Asia, and Europe and is supported by renowned investors like Coatue, Goldman Sachs, Insight Partners, and Sequoia Capital. CertiK's contributions to blockchain security innovation have been acknowledged by prestigious organizations such as the World Economic Forum and CB Insights.
About the Role
The primary focus of this role is to oversee CertiK's security services, which involve cybersecurity and blockchain integration. Responsibilities include security consulting, audits of smart contracts and blockchains, security reviews, formal verification of smart contracts, penetration testing, and more. We seek a candidate with a strong interest in application security and penetration testing. This is a dynamic full-time position suited for individuals passionate about enhancing application security across various domains. Apart from client engagements, there will be ample opportunities to contribute to research and development initiatives aimed at elevating blockchain security standards.
Responsibilities
- Collaborate with external blockchain developers to conduct security audits and ensure the security of products like smart contracts, protocols, and applications.
- Define and enforce security policies, manage vulnerabilities, address security incidents and exploits, and generate comprehensive analysis reports.
- Monitor security breaches, shield systems against cyberattacks, and offer expert technical advice on cybersecurity.
- Perform penetration testing on web and mobile applications (Android and iOS), as well as conduct internal and external network security assessments.
- Review source code and security design, perform threat modeling, and provide guidance to software development teams.
- Contribute to the enhancement of internal security tools and devise new tools that adhere to best engineering practices to bolster security services.
- Utilize static and dynamic analyses to identify vulnerabilities in smart contracts, propose appropriate solutions, assess sandbox, VM, network, and distributed-system code for weaknesses, and develop PoC exploits.
- Engage in security research, publish findings through technical blogs, and present at various conferences and tech events to showcase technical expertise and insights.
Requirements
- Hold a Master’s degree in Security Informatics, Cybersecurity, or a related field.
- Possess in-depth knowledge of solidity, smart contract security, cryptography, and blockchain technology.
- Demonstrate technical proficiency in Web3 security, threat and vulnerability management, penetration testing, and security reviews for programs written in languages like Java, JavaScript, Python, C/C++, PHP, and Go.
- Have familiarity with cloud platforms such as AWS, Azure, and GCP, and proficiency in Python and JavaScript.
The expected annual salary range for this role is $130,000 to $163,000, depending on the qualifications and experience of candidates. CertiK offers a comprehensive benefits package to full-time employees, including medical, vision, and dental insurance, a 401(k) plan with company matching, life and accidental death and dismemberment insurance, HSA, FSA, flexible paid time off, holidays, and a variable commission program for business development roles.
CertiK is an equal opportunity employer, committed to supporting diversity in the workplace and complying with all federal laws regarding employment eligibility. Qualified applicants with criminal histories will be considered in accordance with local and federal regulations.
In the recruitment process, CertiK may utilize artificial intelligence tools to aid in application reviews, resume analysis, and evaluation of responses, though final hiring decisions are made by humans. For more information on data processing, kindly reach out to us.
