All vacancies
CertiK

Senior Security Engineer

CertiK · office · senior · full-time · $130000–$160000 USD
cryptotechweb3 CybersecurityBlockchainSmart ContractsSecurity AuditingPenetration TestingJavaPythonAWSAzureGCP
8.5
AI Score
The vacancy is well-structured and informative, making it appealing to qualified applicants.
Job description
## About the Company Born from groundbreaking research at Columbia University and Yale University, CertiK is a leading Web3 security company focused on securing blockchain protocols, smart contracts, and decentralized applications through cutting-edge security research, formal verification, and AI-powered technology. Founded in 2017 and headquartered in New York City, CertiK provides end-to-end security solutions including smart contract audits, penetration testing, on-chain monitoring, incident response, and compliance services for some of the largest projects in the digital asset ecosystem. Today, CertiK supports thousands of enterprise clients and Web3 projects globally, with a distributed international team spanning North America, Asia, and Europe. The company is backed by leading investors including Coatue, Goldman Sachs, Insight Partners, and Sequoia Capital, and has been recognized by organizations such as the World Economic Forum and CB Insights for its contributions to blockchain security innovation.
Responsibilities
## Responsibilities - Lead design/deployment of enterprise-grade security solutions to safeguard internal networks/applications/infrastructure, ensuring confidentiality/integrity/availability of mission-critical systems & data - Define/enforce organization-wide security policies/standards; own end-to-end vulnerability management lifecycle & lead cross-functional incident response with engineering/IT/compliance teams - Oversee real-time threat detection/response operations; conduct forensic investigations & drive root cause analysis for high-impact security incidents to inform long-term defense strategies - Manage/execute comprehensive security assessments across internal/third-party systems, including architecture reviews/endpoint security evaluations/infrastructure hardening initiatives - Guide secure development practices by applying advanced static/dynamic analysis to identify vulnerabilities & deliver remediation guidance to engineering teams - Conduct threat modeling/risk analysis for high-value systems to proactively identify/mitigate attack vectors & influence system/product architecture - Architect/maintain internal security tooling to expand detection coverage, streamline response workflows & enhance operational visibility
Requirements
## Requirements - Master’s degree in Computer Science, Software Engineering, Security Informatics, or related field. - Expertise in threat modeling/architectural risk assessment using structured methodologies (e.g., STRIDE/DREAD) - Advanced knowledge of SSDLC, including static/dynamic analysis/QA practices & end-to-end vulnerability lifecycle management (tracking/remediation coordination/verification) - Strong ability to conduct comprehensive security assessments across network infrastructure/application architecture/system configurations - Familiarity with cloud environments (AWS/Azure/GCP) & CI/CD deployment workflows; Proficiency in Java/Python with applied skills in secure coding/debugging/symbolic execution & internal tooling/automation scripting
Conditions
## Conditions - Target annual salary compensation for this role performed is $130,000 to $160,000. - CertiK is proud to offer medical, vision, and dental insurance, 401(k) plan with company matching, life and accidental death and dismemberment insurance, HSA (with high deductible plan), FSA, and other benefits to all full-time employees, along with flexible paid time off and holidays. - CertiK also offers a variable commission program for business development sales roles.
About CertiK
CertiK is a Web3 security company that provides smart contract audits, blockchain protocol security, formal verification, and continuous on-chain monitoring. It serves blockchain and crypto projects with tools and services for security, compliance, incident response, and fraud investigation.
Web3 Security · 200-1000 · New York, United States · Founded 2018 · https://www.certik.com/?ref=sailonchain.com
Apply to this role