RootstockLabs is seeking an Application Security Engineer to help secure our Bitcoin-secured DeFi infrastructure. You will play a critical role in reviewing code, smart contracts, and protocol changes while building security automation to maintain a safe development lifecycle.
Key responsibilities
- Perform security reviews of source code, smart contracts, and protocol changes across various projects.
- Participate in design and architecture reviews and conduct threat modeling for new products and features.
- Triage and validate bug bounty reports, assessing severity and coordinating remediation with engineering teams.
- Collaborate on external security audits by scoping engagements and working with third-party auditors.
- Build and operate security automation, including AI-assisted code review, scanning, and findings-triage pipelines.
- Research attack techniques relevant to the ecosystem and translate findings into concrete defenses.
Requirements
- 3+ years of experience in Application Security or Security Engineering.
- Solid grasp of common vulnerability classes and secure code review in Java plus at least one of TypeScript, Python, Go, or Rust.
- Hands-on experience with blockchain security, specifically smart contract auditing or protocol-level security.
- Experience building and operating security automation, SAST/DAST, and CI/CD security gates.
- Fluent English communication skills.
What we offer
- Competitive compensation package and unique benefits designed to support your growth.
- Fully remote work environment with access to global coworking spaces.
- Paid vacation and sick leave to ensure a healthy work-life balance.
- Access to continuous learning opportunities, including training programs and language courses.
- The chance to work with cutting-edge blockchain technology in a diverse, global team.