Logo for IOV Labs

Application Security Engineer

Role overview

Qualifications

  • 3+ years of experience in Application Security or Security Engineering
  • Solid grasp of common vulnerability classes (OWASP Top 10) and secure code review in Java plus at least one of TypeScript/JavaScript, Python, Go, or Rust
  • Hands-on experience with blockchain security: smart contract auditing (Solidity/EVM) or protocol/node-level security
  • Experience building and operating security automation, AI-assisted workflows (LLM-based triage, code review, or scanning), SAST/DAST, dependency and secret scanning, and CI/CD security gates

Responsibilities

  • Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects
  • Participate in design and architecture reviews; threat-model new products and features with development teams
  • Triage and validate bug bounty reports; assess severity and coordinate remediation with engineering
  • Collaborate on external security audits: scope engagements and work with third-party auditors through to the resolution of findings

Key facts

Hard skills

Other skills

  • Incident Reporting
  • Collaboration
  • Problem Solving
  • Communication

About the company

IOV Labs logo

IOV Labs

Blockchain, Crypto & Web3

The internet has democratized knowledge and strengthened human connections, but millions of people still dream of financial equality. At IOV Labs, we are developing low-cost, high-quality, easy-to-use platforms for all people, of all backgrounds, all around the world. Harnessing the benefits of Bitcoin, the web’s most secure and reliable financial network, we are building the foundations for a new economy, one that gives everyone the tools to create and grow value. We achieve this with platforms like RSK, the first open-source smart contract platform and RIF OS, which puts our technology in the hands of organizations and service providers. In 2019, we also acquired Taringa!, the top Spanish-speaking social network in the world with 30 million users and over 1,000 active online communities. With tools to create and verify personal identity, establish and execute agreements, and engage in commercial transactions, now everyone has the chance to participate in a new economy. Welcome to the internet of value.

Company details

Company typeScaleup
IndustryBlockchain, Crypto & Web3
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

NOTE: As part of our hiring process, we conduct background and reference checks at the to validate relevant experience, qualifications, location and professional history.

ABOUT THE ROLE

As an Application Security Engineer at RootstockLabs, you will help secure our Bitcoin-secured DeFi infrastructure by reviewing code, smart contracts, and protocol changes, and by building the security automation that keeps our development lifecycle safe. You will work closely with development teams on threat modeling and architecture reviews, manage our bug bounty program end to end, and coordinate external security audits with third-party auditors. You will also research attack techniques relevant to our ecosystem (EVM, bridges, p2p) and translate them into concrete defenses, and support incident investigations when application-layer issues arise.

KEY RESPONSIBILITIES

  • Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects
  • Participate in design and architecture reviews; threat-model new products and features with development teams
  • Triage and validate bug bounty reports; assess severity and coordinate remediation with engineering
  • Collaborate on external security audits: scope engagements and work with third-party auditors through to the resolution of findings
  • Build and operate security automation, including AI-assisted code review, scanning, and findings-triage pipelines
  • Research attack techniques relevant to the ecosystem (EVM, bridges, p2p) and turn findings into concrete defenses: monitoring alerts, CI security checks, and hardening changes
  • Support incident investigations when application-layer issues arise

WHAT YOU BRING

  • 3+ years of experience in Application Security or Security Engineering
  • Solid grasp of common vulnerability classes (OWASP Top 10) and secure code review in Java plus at least one of TypeScript/JavaScript, Python, Go, or Rust
  • Hands-on experience with blockchain security: smart contract auditing (Solidity/EVM) or protocol/node-level security
  • Experience building and operating security automation, AI-assisted workflows (LLM-based triage, code review, or scanning), SAST/DAST, dependency and secret scanning, and CI/CD security gates
  • Fluent English

NICE TO HAVE

  • Experience in bug bounty triage or vulnerability disclosure programs
  • Experience mitigating network-level attacks (p2p, eclipse, DoS) or analyzing consensus-level attack scenarios
  • Offensive security background (pentesting, red team, CTFs, exploit development)
  • Public security research: CVEs, bug bounty track record, audit reports, conference talks
  • Knowledge of C/C++ (for node/client codebases)
  • Experience with fuzzing (smart contracts or native code)

ROOTIES BENEFITS

At RootstockLabs, we don’t just offer a job, we offer a community. Here’s what you can expect when you join us:

  • Competitive compensation package and unique benefits designed to support your growth and well-being.
  • 100% Remote Work working within a Central European to Argentinian time-zone window (UTC-3 to UTC+2, with about an hour's flexibility either side), and with access to global coworking spaces.
  • Work-Life Balance: Paid vacation and sick leave days
  • Continuous Learning: Access to training programs, language courses, and learning sponsorship annually.
  • Unique Projects: Work with cutting-edge blockchain technology in a global, diverse team. 

ABOUT ROOTSTOCKLABS  

RootstockLabs builds Bitcoin-secured DeFi infrastructure that enables companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale.

  • Market: Companies, financial institutions, and their customers
  • Product: Bitcoin-secured DeFi financial products
  • Distribution: B2B2C through regulated financial institutions

We operate at the intersection of crypto infrastructure and institutional finance, enabling compliant, scalable access to decentralized financial services powered by Bitcoin.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Application Security Engineer Related jobs

Other jobs at IOV Labs

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.