Posted today · be early
Application Security Engineer
RootstockLabs
WorldwideremotePosted today
Skill Required
Application-Security-EngineeringBlockchain-SecuritySmart-Contract-AuditingSecurity-EngineeringCybersecurityApplication-Security-EngineerAppSec-EngineerApplication-Security-SpecialistSoftware-Security-EngineerSecurity EngineerApplication DevelopersecuritySolidityEngineeringJavaScriptTypeScriptBlockchainautomationObservabilitybuildingPythondesignC++CI/CDOWASPDesign PatternsJavaDeFiNode.jsandGenerative AIEthereumGoCICDAIFulltime
Key highlights
- Remote work with Central European to Argentinian time-zone window (UTC-3 to UTC+2)
- 3+ years required experience in Application Security or Security Engineering
- Access to global coworking spaces
- Continuous learning: training programs, language courses, and learning sponsorship annually
- No salary figure stated
Role overview
As an Application Security Engineer at RootstockLabs, you will help secure Bitcoin-secured DeFi infrastructure by reviewing code, smart contracts, and protocol changes, and by building security automation that keeps the development lifecycle safe. You will work closely with development teams on threat modeling and architecture reviews, manage the bug bounty program end-to-end, coordinate external security audits with third-party auditors, research attack techniques relevant to the ecosystem (EVM, bridges, p2p), and support incident investigations when application-layer issues arise.
Responsibilities
- Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects
- Participate in design and architecture reviews; threat-model new products and features with development teams
- Triage and validate bug bounty reports; assess severity and coordinate remediation with engineering
- Collaborate on external security audits: scope engagements and work with third-party auditors through to the resolution of findings
- Build and operate security automation, including AI-assisted code review, scanning, and findings-triage pipelines
- Research attack techniques relevant to the ecosystem (EVM, bridges, p2p) and turn findings into concrete defenses: monitoring alerts, CI security checks, and hardening changes
- Support incident investigations when application-layer issues arise
Requirements
- 3+ years of experience in Application Security or Security Engineering
- Solid grasp of common vulnerability classes (OWASP Top 10) and secure code review in Java plus at least one of TypeScript/JavaScript, Python, Go, or Rust
- Hands-on experience with blockchain security: smart contract auditing (Solidity/EVM) or protocol/node-level security
- Experience building and operating security automation, AI-assisted workflows (LLM-based triage, code review, or scanning), SAST/DAST, dependency and secret scanning, and CI/CD security gates
- Fluent English
Nice to have
- Experience in bug bounty triage or vulnerability disclosure programs
- Experience mitigating network-level attacks (p2p, eclipse, DoS) or analyzing consensus-level attack scenarios
- Offensive security background (pentesting, red team, CTFs, exploit development)
- Public security research: CVEs, bug bounty track record, audit reports, conference talks
- Knowledge of C/C++ (for node/client codebases)
- Experience with fuzzing (smart contracts or native code)
Benefits
- Competitive compensation package and unique benefits designed to support your growth and well-being
- 100% Remote Work working within a Central European to Argentinian time-zone window (UTC-3 to UTC+2, with about an hour's flexibility either side), and with access to global coworking spaces
- Work-Life Balance: Paid vacation and sick leave days
- Continuous Learning: Access to training programs, language courses, and learning sponsorship annually
- Unique Projects: Work with cutting-edge blockchain technology in a global, diverse team
Additional details
- As part of our hiring process, we conduct background and reference checks at the to validate relevant experience, qualifications, location and professional history
- RootstockLabs builds Bitcoin-secured DeFi infrastructure that enables companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale
- Market: Companies, financial institutions, and their customers
- Product: Bitcoin-secured DeFi financial products
- Distribution: B2B2C through regulated financial institutions
- We operate at the intersection of crypto infrastructure and institutional finance, enabling compliant, scalable access to decentralized financial services powered by Bitcoin