
Senior Application Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Identify the root cause and severity of vulnerabilities identified via the bug bounty platform.
• Collaborate with ethical hackers, evaluate reports, and assist product engineering teams in finding solutions.
• Document vulnerabilities to enable engineering teams to respond promptly.
• Write code for security engineering initiatives and address vulnerabilities within MetaMask client applications.
• Create AI tools for identifying and resolving vulnerabilities.
• Evaluate application vulnerabilities and ensure remediation is completed within set SLAs.
• Conduct design reviews, threat modeling, security assessments, and code evaluations.
• Spot gaps in MetaMask’s secure software development lifecycle and spearhead initiatives to mitigate them.
• Engage in team meetings, roadmap planning, and collaborative discussions.
• Validate security patches and test for possible bypass methods.
• Develop automation and security measures to avert recurring vulnerabilities.
• Train developers on security practices.
• Assist in enhancing the security of MetaMask.
• Over 6 years of experience in building and securing software, including practical product or application security experience.
• Expertise in securing modern backend systems, web applications, and APIs.
• Proficient in conducting threat modeling, security design reviews, and vulnerability assessments.
• Experience in securing JavaScript-based applications across web and/or mobile platforms.
• Strong coding abilities and adeptness in identifying and rectifying vulnerabilities or creating secure solutions.
• Knowledge of blockchain technology, particularly Ethereum, decentralized applications, and cryptocurrency wallets.
• Comprehensive understanding of modern web and mobile security, common attack vectors, and their mitigations.
• Excellent communication skills with the capability to influence engineering decisions and collaborate in a remote setting.
• Self-motivated and proactive; comfortable working in a high-autonomy, distributed team environment.
• Alignment with Consensys’s mission and values.
• Availability for some overlap with EU and US-Pacific time zones is required.
• Employment background checks, including verification of employment, education, and criminal records, are mandatory.
• Nice to have: experience in software development.
• Nice to have: in-depth knowledge of Ethereum and other blockchains, decentralized applications, and cryptocurrency wallets.
• Nice to have: knowledge of smart contract implementation and security.
• Nice to have: familiarity as a MetaMask user.
• Fully remote work arrangement.
• Globally distributed team environment.
• Opportunities to engage with emerging technologies and tackle complex challenges.
• Exposure to innovative ideas and technologies.
• Equal opportunity employer.
• US salary range excludes bonuses, equity, and other benefits; compensation for locations outside the US is based on location, experience, and skillset.
Lightology
Fusion Practices
Bonterra
Get handpicked remote jobs straight to your inbox weekly.