Security Engineer (Penetration Testing)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+14 more
Job description
The primary responsibility of this role is for CertiK’s security-related services. Intersecting cybersecurity and blockchain, CertiK’s security offerings include security consulting, security reviews, security auditing of smart contracts and blockchains, verification of smart contracts, penetration testing, and more. We are looking to hire someone with a passion for application security and penetration testing. This is a fun and challenging full-time position. If you are excited about hacking, threat modeling, scanning, auditing, designing, and enhancing the security of applications across the board then you will thrive in this role. While you work with clients, we will also provide you with plenty of opportunities to get involved with research and development efforts to help us raise the standards of blockchain security., * Perform security assessments on web, mobile, thick client applications, and browser extensions
- Conduct external and internal network penetration tests
- Perform security source code reviews
- Perform cloud security reviews
- Develop comprehensive pentest reports for both technical and non-technical audiences
- Research and develop innovative techniques, tools, and methodologies for pentesting applications in the blockchain space
- Contribute to the community by developing tools, presentations, and blog posts, CertiK will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements. https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf All CertiK employees are expected to actively support diversity on their teams, and in the Company., Handle incoming owner relations inquiries about revenue, land, division orders, JIB, A/R, and A&P. Log and follow up cases in a tracking system, build trusting client relationships, manage difficult situations calmly, provide accurate timely responses, and participate in cross-training. Top Skills: MS Office Enverus
Requirements
- Passionate about cryptocurrency, DeFi, and blockchain, with a willingness to learn Web3 technologies such as smart contracts
- Minimum of 4 years of experience in application security and penetration testing
- Experienced in source code review for different languages, with a strong understanding of JavaScript and TypeScript
- Experienced in mobile application penetration testing
- Familiar with cloud platforms and their security risks, such as AWS, Azure, and GCP
- Experience in programming with scripting languages such as Python and Bash
- Solid understanding of cryptography
- BS/MS/PhD in Computer Science or Information Security
- Strong spoken and written communication skills
Bonus Points
- Experienced in pentesting Web3 applications such as crypto exchanges, wallets, Dapps, and key custodian solutions
- Experienced in smart contract security audits
- Familiar with browser extension architecture and security risks
- Actively participate in the blockchain security community
- OSCP, OSWE, OSCE, GWAPT, or comparable certification
- Participated in bug bounty programs and audit contests
- Published security-related blog posts and spoken at security conferences and/or local meetups
Benefits & conditions
Target annual base salary for this role performed in the US is $100,000 - $180,000. The exact compensation at which this job is filled will be determined by the skills and experience of qualified candidates. #LI-Remote #blockchain #startups #hiring CertiK is proud to offer medical, vision, and dental insurance, 401(k) plan with company matching, life and accidental death and dismemberment insurance, HSA (with high deductible plan), FSA, and other benefits to all full-time employees, along with flexible paid time off and holidays. CertiK also offers a variable commission program for business development sales roles. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire., In-Office or Remote 2 Locations 43K-58K Annually Mid level 43K-58K Annually Mid level, In-Office or Remote 2 Locations 120K-135K Annually Senior level 120K-135K Annually Senior level Big Data * Information Technology * Software * Analytics * Energy Serve as a strategic advisor driving adoption and value of Enverus Power & Renewables products. Lead onboarding, training, client engagements, and account strategy; present analytics, gather product feedback, support renewals, and expand user adoption while collaborating with sales and product teams. Top Skills: APIsMosaicPanoramaPrismPythonSalesforce Mochi Health, Healthtech * Telehealth Handle inbound patient calls to answer questions about prescriptions, refills, appointments, and account status. Document interactions, follow up via secure portal when needed, escalate clinical issues per protocol, and maintain HIPAA and patient safety standards. Part-time, phone-first role with potential conversion to permanent. Top Skills: Headset With MicrophoneReliable Internet (25 Mbps)Secure Patient Portal
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute
About the company
CertiK is a pioneer in blockchain security, leveraging best-in-class AI technology to protect and monitor blockchain protocols and smart contracts. Founded in 2018 by professors from Yale University and Columbia University, CertiK’s mission is to secure the web3 world. CertiK applies cutting-edge innovations from academia to enterprise, enabling mission-critical applications to scale with safety and correctness., One of the fastest-growing and most trusted companies in blockchain security, CertiK is a true market leader. To date, CertiK has worked with over 3,200 Enterprise clients, secured over $310 billion worth of digital assets, and has detected over 60,000 vulnerabilities in blockchain code. Our clients include leading projects such as Aave, Polygon, Binance Smart Chain, Terra, Yearn, and Chiliz. Investors = Insight Partners, Sequoia, Tiger Global, Coatue Management, Lightspeed, Advent International, SoftBank, Hillhouse Capital, Goldman Sachs, Coinbase Ventures, Binance, Shunwei Capital, IDG Capital, Wing, Legend Star, Danhua Capital and other investors.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Dev Digest 138 - Are you secure about this?
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.