Hacken
Smart Contract Auditor (EVM, Rust, Solana, Move)
RemoteContractorGlobal
š Midš Remote
RemoteRemote work position availableActivePosted within the last 30 days
Job Description
[AI-summarized by JobStash]
You will perform manual security reviews and static and dynamic analysis of smart contracts. You will identify vulnerabilities such as reentrancy, access control flaws, logic errors and economic exploits, and produce clear audit reports with severity ratings and remediation guidance. You will work with protocol teams to understand business logic, architecture and threat models, contribute to internal tooling and audit methodology, and keep up to date with new exploits and attack vectors.
Requirements
- ā2+ years of hands-on experience in smart contract security auditing or development
- āExpertise in at least one ecosystem: EVM (Solidity, Vyper, EVM internals), Rust-based (Solana Anchor, CosmWasm, Near, Radix Scrypto) or Move (Aptos, Sui)
- āStrong understanding of common vulnerability classes such as reentrancy, access control issues, flash loan attacks and oracle manipulation
- āKnowledge of DeFi primitives including AMM, lending protocols, staking and bridges
- āFamiliarity with token standards and patterns (ERC-20, ERC-721, ERC-1155, ERC-4626) and account abstraction concepts
- āUnderstanding of EVM and blockchain fundamentals including storage layout, call context, gas mechanics and signature schemes (ECDSA, EIP-712)
- āAbility to read and reason about complex on-chain systems
- āClear written communication for technical reports
- āNice to have: public audit portfolio, bug bounty findings, CTF achievements or security research
- āNice to have: experience with security tooling such as Slither, Foundry, Echidna, Mythril, Certora, Trident and Anchor testing framework
- āNice to have: experience with fuzzing, formal verification and symbolic execution
- āNice to have: familiarity with MEV, cross-chain bridges, L2 architectures or account abstraction research
Responsibilities
- āPerform manual security reviews and static and dynamic analysis of smart contracts
- āIdentify vulnerabilities including reentrancy, access control flaws, logic errors, economic exploits and protocol specific attack vectors
- āDeliver clear, actionable audit reports with severity ratings and remediation guidance
- āCollaborate with protocol teams to understand business logic, architecture and threat models
- āContribute to internal tooling, audit methodologies and knowledge base
- āStay current with latest exploits, attack vectors and ecosystem developments
Tech Stack
NEARFormal verificationsmart contractERC-20VyperSlitherFuzzingsymbolic executionERC-1155ERC-721