Posted on: 23/05/2026
Job Description :
- Perform penetration testing of applications/products based on Web, Mobile, Web3 assets like Smart Contract, Bitcoin Script, etc.
- Plan and perform red team exercises in a variety of environments.
- Manage applications/products bug bounty program with validation and response mechanism for vulnerabilities submitted by external researchers.
- Continuous research on new attack vectors/techniques and their mitigations.
- Manage attack surface based on risk assessment for the business.
- Develop scripts, tools and methodologies to enhance security posture of the whole company and its applications/products.
- Manage continuous passive and active monitoring and alert systems such as Prometheus, Grafana, Wazuh, etc.
- Apply knowledge of AWS services to support the maintenance of secure cloud infrastructure.
- Deployment and management of security tools (open source and commercial)
- Clear communication for vulnerability reports and their remediation required.
- Work with cross-functional teams to align and priorities remediation efforts.
- Work collaboratively/independently on unique or special assignments which may require specialized knowledge and/or experience.
- Comply with company, division and professional ethical standards.
Ideal Candidate :
Strong Security Engineer- Web3 & Web2 | Penetration Testing, Cloud Security & Blockchain
- Must have 4+year of experience in a security engineering role or related position covering both Web3 and Web2 security paradigms across application, infrastructure, and cloud security contexts.
- Must have hands-on experience performing penetration testing on Web, Mobile, and Web3 assets including Smart Contracts and Bitcoin Scripts and must have planned or executed red team exercises across varied environments.
- Must have strong working knowledge of OWASP Top 10, SANS Top 25, NIST, MITRE ATT&CK, and shift-left security methodologies with the ability to apply these in vulnerability identification and risk prioritisation.
- Must have a strong understanding of application, infrastructure, and networking architecture with the ability to assess attack surfaces holistically and manage risk across business assets.
- Must be proficient in deploying and managing continuous monitoring and alerting systems with direct exposure to tools such as Prometheus, Grafana, Wazuh, or comparable security tooling.
- Must have working familiarity with AWS services and basic cloud security concepts with practical ability to support and maintain secure cloud infrastructure.
- Must be able to develop scripts, tools, and methodologies to enhance security posture with working knowledge of at least one of Go, Rust, TypeScript, or Python.
- Must have a foundational understanding of blockchain technologies and associated security considerations covering smart contract security, Bitcoin script analysis, or related Web3 attack vectors
- Must hold a Bachelor's degree in Computer Science, Information Technology, or a related field.
- Candidate must have prior experience working at a blockchain or Web3-native product company.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1638392