Match score not available

Senior Application Security Engineer - MetaMask

UNLIMITED HOLIDAYS - WORK FROM ANYWHERE - FULLY FLEXIBLE
Remote: 
Full Remote
Contract: 
Salary: 
100 - 201K yearly
Experience: 
Senior (5-10 years)
Work from: 

Offer summary

Qualifications:

6+ years of experience in software security, 4+ years focused on web application security, Experience with security design reviews and testing, Knowledge of modern web and mobile app security, Solid communication skills.

Key responsabilities:

  • Conduct design reviews and threat modeling
  • Assess and remediate security vulnerabilities
  • Identify and address gaps in SSDLC
  • Document vulnerabilities for actionable insights
  • Write code to fix vulnerabilities
ConsenSys logo
ConsenSys Scaleup https://consensys.net/
501 - 1000 Employees
HQ: New York
See more ConsenSys offers

Job description

Logo Jobgether

Your missions

Consensys is the leading blockchain and web3 software company founded by Joe Lubin, CEO of Consensys and Co-Founder of Ethereum. Since 2014, Consensys has been at the forefront of innovation, pioneering technological developments within the web3 ecosystem.

Through our product suite, including the MetaMask platform, Infura, Linea, Diligence, and our NFT toolkit Phosphor, we have become the trusted collaborator for users, creators, and developers on their path to build and belong in the world they want to see.

Whether building a dapp, an NFT collection, a portfolio, or a better future, the instinct to build is universal. Consensys inspires and champions the builder instinct in everyone by making web3 universally easy to use and develop on.

Our mission is to unlock the collaborative power of communities by making the decentralized web universally easy to access, use, and build on. 

You’ll get to work on the tools, infrastructure, and apps that scale these platforms to onboard one billion participants and 5 million developers. You’ll be constantly exposed to new concepts, ideas, and frameworks from your peers, and as you work on different projects — challenging you to stay at the top of your game. You’ll join a network of builders that reaches the edge of our ecosystem. Consensys alumni have moved on to become tech entrepreneurs, CEOs, and team leads at tech companies. 

About MetaMask

We’re building for a future where the internet and world economy empowers people through interactions based on consent, privacy, and free association. Where both communities and individuals flourish. To accomplish that, we’re working hard to make web3 accessible for everyone.

MetaMask is both a crypto wallet and a gateway to the decentralized web. Our tools help people create communities, play video games, access financial services, make payments, invest in assets, protect against economic turmoil, and more. Our browser extension and mobile platforms meet the needs of millions of users and developers across the world.

Originally a humble key manager, today MetaMask serves over 30 million monthly active users as a decentralized application development platform, an aggregator of decentralized cryptocurrency exchanges, and a decentralized identity manager.

About the Role

MetaMask has experienced explosive user growth over the past year as a cryptographic key manager and web3 application development platform. As this user base continues to grow, an immense amount of trust is being placed in MetaMask as a tool that manages and wields their digital authority, controlling assets, identities and more. It is of highest importance to us that we keep our users as safe and secure as possible.

We are looking for an Application Security Engineer to join our rapidly growing security team to help embed security into all phases of the software development lifecycle. You would work closely with development teams and product managers to ensure MetaMask products are designed and implemented to the highest security standards. 

To apply for this position, you must have:

  • 6+ years of experience building and securing software, with at least 4 years focusing on web application security.
  • Experience performing security design reviews, threat modeling, or security testing.
  • Enthusiasm for writing code, and helping others do the same.
  • Experienced working with JavaScript code to identify issues.
  • Solid written and verbal communication skills.
  • Proactiveness and be self-driven to be successful working in a remote environment.
  • Relevant knowledge of modern web and mobile app security landscape, real-world attacks and mitigations.
  • A belief in our mission and values.

Nice to have:

  • Experience working as a software developer.
  • Familiarity with the Ethereum blockchain and Decentralized Applications.
  • You’re a MetaMask user!

Responsibilities

  • Support product teams as they develop new features by conducting design reviews, threat modeling, security testing, and code reviews.
  • Assess potential security vulnerabilities within our applications, and work with development teams to ensure remediation in our established SLAs.
  • Identify gaps in MetaMask’s secure software development life cycle (SSDLC), and take initiative leading efforts to address them.
  • Determine the root cause and severity of vulnerabilities reported to us through our bug bounty platform.
  • Participate and contribute to team meetings, roadmap planning, and discussions.
  • Validate that security patches address reported vulnerabilities and test for any potential bypasses
  • Document identified vulnerabilities in a way that allows for our engineering team to take quick action.
  • Proactively prevent future occurrences of a vulnerability through developing automation, security controls, and educating developers.
  • Write code to support the development of security engineering projects, or fix vulnerabilities in MetaMask client applications.
  • Pave your own path in how you want to make MetaMask more secure. 

About Consensys

Our mission is to unlock the collaborative power of communities by making Web3 universally easy to use, access, and build on.

Working with Consensys puts you at the forefront of an evolving paradigm, transforming our society for the better. We fundamentally believe blockchain is the next generation of technology that can lay the foundation for a more just and equitable society. 

Blockchain tech is just over 10 years old. Ethereum itself is still a toddler and we’re far from reaching our full potential. You’ll get to work on the tools, infrastructure, and apps that scale these platforms to billions of users. 

You’ll be constantly exposed to new concepts, ideas, and frameworks from your peers, and as you work on different projects — challenging you to stay at the top of your game. You’ll join a network of entrepreneurs and technologists that reaches the edge of our ecosystem. Consensys alumni have moved on to become tech entrepreneurs, CEOs, and team leads at tech companies.

Why join Consensys? Here are some of the perks of being part of a unique organization like Consensys:

One of the most recognized tech companies in the blockchain ecosystem globally. A work experience at Consensys is a tremendous reference for your future career. Consensys alumni have moved on to become tech entrepreneurs, CEOs, and team leads at tech companies.

The forefront of a revolution. We fundamentally believe blockchain is a next generation of technology that can lay the foundation for a more just and equitable society. You can be a part of building the digital economy of tomorrow and radically transforming our society for the better.

A dynamic startup environment with deep roots. We are one of the earliest blockchain companies and a leader in the space.  You’ll join a network of entrepreneurs and technologists that reaches the edge of our ecosystem.  

Deep technical challenges. Blockchain technology is just over 10 years old. Ethereum itself is still a toddler. There is much to be done before these platforms can scale to the order of millions or billions of users. We are building the tools, infrastructure and applications l that are pushing the technology forward.

Continuous learning and improvements. You’ll be constantly exposed to new concepts, ideas and frameworks from your peers and as you work on different projects — challenging you to stay at the top of your game.

Don't meet all the requirements? Don't sweat it. We’re passionate about building a diverse team of humans and as such, if you think you've got what it takes for our chaotic-but-fun, remote-friendly, start-up environment—apply anyway, detailing your relevant transferable skills in your cover letter. While we have a pretty good idea of what we need, we're ready for you to challenge our thinking on who needs to be in this role.

It is a requirement of employment in this position that applicants will be required to submit to background checks including but not limited to employment, education and criminal record checks. Further details will be provided to applicants that successfully meet the criteria for the position as determined by the company in its sole discretion. By submitting an application for employment, you are acknowledging and consenting to this requirement.

The salary range for US-based candidates only will be determined throughout the interview process depending on experience and skills. Candidates should anticipate a base salary (not including bonus, equity or other benefits) of $USD $100,000-$201,000

#LI-HG1

The salary range for US-based candidates only will be determined throughout the interview process depending on experience and skills.

US pay range (not including bonus, equity or other benefits)
$100,000$201,000 USD

 

In the rapidly evolving Web3 space, we believe that everyone is a builder. This expansive paradigm requires a range of backgrounds, talents, skills, and experiences to influence and shape the future. At Consensys, this diversity fuels our ability to shift control and redefine the realm of possibility. We are committed to ensuring that our technology empowers people and communities with economic and political agency through decentralized technologies. We welcome the range of perspectives and differences and celebrate them. We're excited to see how your unique skills as a builder can contribute to our vision, drive innovation, and help us shape a more inclusive Web3.

Consensys is an equal opportunity employer. All employment decisions are made without regard to race, color, national origin, ancestry, sex, gender, gender identity or expression, sexual orientation, age, genetic information, religion, disability, medical condition, pregnancy, marital status, family status, veteran status, or any other characteristic protected by law. Consensys is aware of fraudulent recruitment practices and we encourage all applicants to review our best practices to protect yourself which can be found (https://consensys.io/careers/best-practices-to-avoid-recruitment-fraud/).

Required profile

Experience

Level of experience: Senior (5-10 years)
Spoken language(s):
Check out the description to know which languages are mandatory.

Soft Skills

  • Problem Solving
  • Collaboration
  • Proactivity
  • Non-Verbal Communication

Security Engineer Related jobs