> Markdown version of [/jobs/ext/2104603-security-engineer-penetration-testing](https://www.wearedevelopers.com/jobs/ext/2104603-security-engineer-penetration-testing). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer (Penetration Testing) - **Company:** Certified Kernel Tech LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $100,000.0 - $180,000.0 - **Contract:** Temporary to permanent - **Skills:** Private Networks, Amazon Web Services, Data Analysis, Software System Penetration Testing, Microsoft Azure, Bash Shell, Big Data, Cloud Computing Security, Code Review, Cyber Security, Computer Programming, Digital Assets, Fat Client, Mobile Application Software, Python (Programming Language), Microsoft Office, Blockchain, TypeScript, Scripting, Google Cloud, Lightspeed, Software Security, Binance, GWAPT, Information Technology, Web3.js - **Published:** August 18, 2026 - **Apply:** https://jobs.lever.co/certik/305d508f-1b1a-4b64-ac41-903b14329764/apply?lever-origin=applied&lever-source%5B%5D=BuiltInNationwide ## About the Role * Passionate about cryptocurrency, DeFi, and blockchain, with a willingness to learn Web3 technologies such as smart contracts * Minimum of 4 years of experience in application security and penetration testing * Experienced in source code review for different languages, with a strong understanding of JavaScript and TypeScript * Experienced in mobile application penetration testing * Familiar with cloud platforms and their security risks, such as AWS, Azure, and GCP * Experience in programming with scripting languages such as Python and Bash * Solid understanding of cryptography * BS/MS/PhD in Computer Science or Information Security * Strong spoken and written communication skills Bonus Points * Experienced in pentesting Web3 applications such as crypto exchanges, wallets, Dapps, and key custodian solutions * Experienced in smart contract security audits * Familiar with browser extension architecture and security risks * Actively participate in the blockchain security community * OSCP, OSWE, OSCE, GWAPT, or comparable certification * Participated in bug bounty programs and audit contests * Published security-related blog posts and spoken at security conferences and/or local meetups ## Description The primary responsibility of this role is for CertiK's security-related services. Intersecting cybersecurity and blockchain, CertiK's security offerings include security consulting, security reviews, security auditing of smart contracts and blockchains, verification of smart contracts, penetration testing, and more. We are looking to hire someone with a passion for application security and penetration testing. This is a fun and challenging full-time position. If you are excited about hacking, threat modeling, scanning, auditing, designing, and enhancing the security of applications across the board then you will thrive in this role. While you work with clients, we will also provide you with plenty of opportunities to get involved with research and development efforts to help us raise the standards of blockchain security., * Perform security assessments on web, mobile, thick client applications, and browser extensions * Conduct external and internal network penetration tests * Perform security source code reviews * Perform cloud security reviews * Develop comprehensive pentest reports for both technical and non-technical audiences * Research and develop innovative techniques, tools, and methodologies for pentesting applications in the blockchain space * Contribute to the community by developing tools, presentations, and blog posts, CertiK will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements. https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf All CertiK employees are expected to actively support diversity on their teams, and in the Company., Handle incoming owner relations inquiries about revenue, land, division orders, JIB, A/R, and A&P. Log and follow up cases in a tracking system, build trusting client relationships, manage difficult situations calmly, provide accurate timely responses, and participate in cross-training. Top Skills: MS Office Enverus ## Related Videos - [Smart Contract fundamentals - My first DApp](https://www.wearedevelopers.com/videos/52-smart-contract-fundamentals-my-first-dapp) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)