yandex
consensys
Зарплата
130 000 $ – 218 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
SeniorУдалённоПолная занятость

Senior Application Security Engineer

Оценка ИИ

Отличная вакансия в компании-лидере индустрии с прозрачным диапазоном зарплаты для США и возможностью удаленной работы. Роль предлагает работу над критически важным продуктом (MetaMask) и использование передовых технологий, включая AI.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Высокая сложность обусловлена спецификой Web3 и необходимостью глубоких знаний как в классической безопасности приложений, так и в блокчейн-технологиях. Требуется опыт работы с bug bounty и умение писать код для автоматизации безопасности.

Анализ зарплаты

Медиана175 000 $
Рынок140 000 $ – 225 000 $
Оценка ИИ

Предложенная вилка $130k–$218k полностью соответствует рыночным стандартам для Senior AppSec ролей в США, особенно в секторе FinTech и Web3. Верхняя граница диапазона является весьма конкурентной даже для Tier-1 компаний.

Сопроводительное письмо

I am writing to express my strong interest in the Senior Application Security Engineer position at Consensys. With over six years of experience in software security and a deep-seated passion for the Ethereum ecosystem, I have closely followed MetaMask's evolution as a cornerstone of Web3 infrastructure. My background in performing complex threat models and managing bug bounty programs aligns perfectly with your mission to provide a secure environment for millions of users.

In my previous roles, I have successfully integrated security into the SSDLC by working hand-in-hand with developers, rather than just acting as a gatekeeper. I am particularly excited about the opportunity to develop AI-driven tooling for vulnerability detection, as mentioned in the job description. I am a proactive builder who thrives in remote environments and is eager to contribute to the security resilience of MetaMask and the broader Consensys product suite.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в consensys уже сейчас

Присоединяйтесь к лидерам Web3 и защитите будущее децентрализованных финансов вместе с MetaMask!

Описание вакансии

Consensys is the leading blockchain and web3 software company founded by Joe Lubin, CEO of Consensys and Co-Founder of Ethereum. Since 2014, Consensys has been at the forefront of innovation, pioneering technological developments within the web3 ecosystem.

Through our product suite, including the MetaMask platform, Infura, Linea, Diligence, and our NFT toolkit Phosphor, we have become the trusted collaborator for users, creators, and developers on their path to build and belong in the world they want to see.

Whether building a dapp, an NFT collection, a portfolio, or a better future, the instinct to build is universal. Consensys inspires and champions the builder instinct in everyone by making web3 universally easy to use and develop on.

Our mission is to unlock the collaborative power of communities by making the decentralized web universally easy to access, use, and build on.

You’ll get to work on the tools, infrastructure, and apps that scale these platforms to onboard one billion participants and 5 million developers. You’ll be constantly exposed to new concepts, ideas, and frameworks from your peers, and as you work on different projects — challenging you to stay at the top of your game. You’ll join a network of builders that reaches the edge of our ecosystem. Consensys alumni have moved on to become tech entrepreneurs, CEOs, and team leads at tech companies.

About Metamask

MetaMask aims to create a thriving engineering organization that supports the well-being of our engineers while empowering them to do work they are proud of and enjoy. We strive for an environment that gives our people high trust and autonomy, while also facilitating collaboration, communication and camaraderie among teams and teammates. We aspire to build a diverse engineering team, inclusive to people from all backgrounds and demographics. It is also of great importance to us that working at MetaMask is an experience that catalyzes career growth and learning.

About the Role

MetaMask has experienced explosive user growth over the past year as a cryptographic key manager and web3 application development platform. As this user base continues to grow, an immense amount of trust is being placed in MetaMask as a tool that manages and wields their digital authority, controlling assets, identities and more. It is of highest importance to us that we keep our users as safe and secure as possible.

We are looking for a Senior Application Security Engineer to join our rapidly growing security team to help embed security into all phases of the software development lifecycle. You would work closely with development teams and product managers to ensure MetaMask products are designed and implemented to the highest security standards. Consenys’s application security team primarily supports MetaMask with opportunities to expand to additional products in the Consensys family.

To apply for this position, you must have:

  • 6+ years of experience building and securing software, with at least 4 years in a product security, or application security position.
  • Experience securing server-side applications and environments.
  • Experience performing security design reviews, threat modeling, or security testing.
  • Enthusiasm for writing code, and helping others do the same.
  • Experience securing web applications & APIs
  • Solid written and verbal communication skills.
  • Proactiveness and be self-driven to be successful working in a remote environment.
  • Relevant knowledge of modern web and mobile app security landscape, real-world attacks and mitigations.
  • A belief in our mission and values.

Timezone: Most timezones will work. Regardless of where you are, some overlap with EU and US-Pacific time zones will be necessary.

Nice to have:

  • Experience working as a software developer.
  • Familiarity with the Ethereum blockchain and Decentralized Applications.
  • You’re a MetaMask user!

Responsibilities

  • Determine the root cause and severity of vulnerabilities reported to us through our bug bounty platform.
  • Interface with ethical hackers, triage reports, and guide product engineering teams to resolution.
  • Document identified vulnerabilities in a way that allows for our engineering team to take quick action.
  • Write code to support the development of security engineering projects, or fix vulnerabilities in MetaMask client applications. This includes the development of AI tooling for vulnerability determination and resolution in order to keep pace with the changing AI-powered vulnerability detection landscape.
  • Assess potential security vulnerabilities within our applications, and work with development teams to ensure remediation in our established SLAs.
  • Support product teams as they develop new features by conducting design reviews, threat modeling, security testing, and code reviews.
  • Identify gaps in MetaMask’s secure software development life cycle (SSDLC), and take initiative leading efforts to address them.
  • Participate and contribute to team meetings, roadmap planning, and discussions.
  • Validate that security patches address reported vulnerabilities and test for any potential bypasses
  • Proactively prevent future occurrences of a vulnerability through developing automation, security controls, and educating developers.
  • Pave your own path in how you want to make MetaMask more secure.

Don't meet all the requirements? Don't sweat it. We’re passionate about building a diverse team of humans and as such, if you think you've got what it takes for our chaotic-but-fun, remote-friendly, start-up environment—apply anyway, detailing your relevant transferable skills in your cover letter. While we have a pretty good idea of what we need, we're ready for you to challenge our thinking on who needs to be in this role.

It is a requirement of employment in this position that applicants will be required to submit to background checks including but not limited to employment, education and criminal record checks. Further details will be provided to applicants that successfully meet the criteria for the position as determined by the company in its sole discretion. By submitting an application for employment, you are acknowledging and consenting to this requirement.

The salary range for US-based candidates only will be determined throughout the interview process depending on experience and skills.

US pay range (not including bonus, equity or other benefits)

$130,000—$218,000 USD

In the rapidly evolving Web3 space, we believe that everyone is a builder. This expansive paradigm requires a range of backgrounds, talents, skills, and experiences to influence and shape the future. At Consensys, this diversity fuels our ability to shift control and redefine the realm of possibility. We are committed to ensuring that our technology empowers people and communities with economic and political agency through decentralized technologies. We welcome the range of perspectives and differences and celebrate them. We're excited to see how your unique skills as a builder can contribute to our vision, drive innovation, and help us shape a more inclusive Web3.

Consensys is an equal opportunity employer. All employment decisions are made without regard to race, color, national origin, ancestry, sex, gender, gender identity or expression, sexual orientation, age, genetic information, religion, disability, medical condition, pregnancy, marital status, family status, veteran status, or any other characteristic protected by law. Consensys is aware of fraudulent recruitment practices and we encourage all applicants to review our best practices to protect yourself which can be found (https://consensys.io/careers/best-practices-to-avoid-recruitment-fraud/)).

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Threat Modeling
  • AI
  • Application Security
  • API Security
  • Blockchain
  • Web3
  • SSDLC
  • Security Testing
  • Bug Bounty
  • Ethereum

Возможные вопросы на собеседовании

Проверка понимания специфических рисков кошельков как расширений браузера.

Какие специфические векторы атак на браузерные расширения, такие как MetaMask, вы считаете наиболее критичными сегодня?

Оценка опыта взаимодействия с внешними исследователями.

Расскажите о вашем опыте управления отчетами в bug bounty программах. Как вы разрешаете споры о критичности уязвимости с исследователями?

Проверка навыков интеграции безопасности в процесс разработки.

Как бы вы внедрили процесс Threat Modeling в быстрорастущей команде разработки, чтобы это не замедляло выпуск фич?

Оценка технических навыков и стремления к автоматизации.

В описании вакансии упоминается использование AI для поиска уязвимостей. Какие инструменты или подходы вы бы предложили для автоматизации триажа багов?

Проверка знаний безопасности смарт-контрактов.

Несмотря на фокус на AppSec, MetaMask взаимодействует с dApps. Какие риски на стороне фронтенда могут привести к компрометации активов пользователя в блокчейне?

Похожие вакансии

Atom group
4 000 $ – 5 000 $

Senior Information Security (ИБ)

SeniorУдалённоБеларусь
Information Security · DevSecOps · SDLC · Risk Management · Security Policy · DevOps
+6 навыков
SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
Innostaff
Не указана

Сеньор AppSecOps-инженер

SeniorУдалённоБеларусь
AppSecOps · DevSecOps · SAST · DAST · SCA · CI/CD · Cybersecurity · Kubernetes · Docker
+9 навыков
MTS Web Services
250 000 ₽ – 300 000 ₽

Старший эксперт SIEM

SeniorВ офисеРоссия
SIEM · SoC · Linux · Windows · macOS · CCNA · LPIC-1 · Cybersecurity · Incident Response · Network Security
+10 навыков
Инфосистемы Джет
Не указана

Старший инженер внедрения SIEM

SeniorВ офисеРоссия
SIEM · SOAR · SGRC · ArcSight · MaxPatrol SIEM · FortiSIEM · QRadar · Splunk · Linux · Windows Server · Information Security
+11 навыков
Крипта
Не указана

Senior Security Auditor

SeniorУдалённо
Solidity · DeFi · EVM · Slither · Echidna · Foundry · Hardhat · Rust · Python · Go · Vyper · C++
+12 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

consensys
Зарплата
130 000 $ – 218 000 $