Morpho Labs
Protocol Security Engineer
Paris or remote (from -5h GMT up to +2h GMT to ensure sufficient overlap with the rest of the team).Full-timeGlobal
š Midš Hybrid
RemoteRemote work position availableActivePosted within the last 30 days
Job Description
[AI-summarized by JobStash]
You will implement formal verification rules using Certora on smart contracts, conduct comprehensive security reviews of protocol contracts, and manage the bug bounty program including triage and researcher communication. You will build periphery smart contracts that integrate securely with the core protocol, research emerging attack vectors and vulnerability classes, and represent the security approach at conferences and through published research.
Requirements
- āMaster's degree in Computer Science Cybersecurity Software Engineering or a related field
- ā3+ years of experience in smart contracts auditing
- āProven track record of identifying critical vulnerabilities in smart contracts
- āExtensive knowledge of Ethereum Virtual Machine Solidity and the blockchain ecosystem
- āExcellent written and verbal communication skills
- āInterest in DeFi and lending protocols
- āLow ego and collaborative mindset
- āExperience with bug bounty programs and platforms including triage validation and researcher communication
- āExperience writing smart contracts securing significant TVL
- āPublication record in applied cryptography security or related domains
Responsibilities
- āImplement formal verification rules using Certora on smart contracts
- āConduct comprehensive security reviews of protocol smart contracts
- āOwn and triage the bug bounty program and communicate with security researchers
- āBuild periphery smart contracts that integrate with the core protocol
- āResearch emerging attack vectors and new vulnerability classes
- āRepresent Morpho's security approach at conferences, meetups, and through published research
Benefits & Perks
- āReal flexibility
- āTime together in Paris
- āGreat health coverage
- āSupport to keep learning
Tech Stack
Certorabug bountyauditingsecurity reviewDeFismart contractEVMSolidityFormal verification