Consensys
Senior Application Security Engineer
NEWUnited States, EMEAFull-timeGlobal
š° USD 130,000 - 218,000/yr
š Midš Remote
ActivePosted within the last 30 days
Job Description
[AI-summarized by JobStash]
You will embed security into the software development lifecycle for MetaMask products. You will review designs, perform threat modeling, conduct security testing and code reviews, and triage vulnerabilities reported through the bug bounty program. You will write code to fix vulnerabilities and build security automation and tooling, validate patches, and drive remediation within SLAs. You will liaise with engineers and ethical hackers, document findings clearly, and help prevent future issues through controls and developer education.
Requirements
- ā6+ years building and securing software, with at least 4 years in product or application security
- āExperience securing server-side applications and environments
- āExperience performing security design reviews, threat modeling, and security testing
- āExperience working with or securing JavaScript and Node.js applications in modern web environments
- āStrong coding skills in modern application stacks, ideally JavaScript and Node.js
- āExperience securing web applications and APIs
- āSolid written and verbal communication skills
- āProactive and self-driven with ability to work effectively in a remote environment
- āRelevant knowledge of modern web and mobile application security landscape, real-world attacks and mitigations
Responsibilities
- āDetermine root cause and severity of reported vulnerabilities
- āTriage bug bounty reports and interface with ethical hackers
- āGuide product engineering teams to remediation
- āDocument identified vulnerabilities to enable rapid engineering action
- āWrite code to support security engineering projects and fix client vulnerabilities
- āDevelop AI tooling for vulnerability determination and resolution
- āAssess application security and ensure remediation within SLAs
- āConduct design reviews, threat modeling, security testing, and code reviews
- āIdentify gaps in the SSDLC and lead remediation efforts
- āValidate security patches and test for potential bypasses
- āDevelop automation, security controls, and educational materials to prevent recurrence
Benefits & Perks
- āComprehensive competitive benefits package
- āEquity
- āAccess to Consensys Advance Program and Coursera learning modules
- āUnlimited vacation/holidays
- āFlexible working arrangements
- āRemote-first work
Tech Stack
Node.jsthreat modelingweb applicationSSDLCApplication securityvulnerability managementvulnerability triageAI toolingserver-side developmentcode reviewproject:Mask Network