Hashgraph
Hashgraph, formerly Swirlds Labs, is a software company home to some of the brightest minds in web3.
Product Security Engineer
Security EngineerSecurity EngineerFull TimeRemoteTeam 51-200Since 2022H1B No SponsorCompany SiteLinkedIn
Location
United States
Posted
50 days ago
Salary
Not specified
Bachelor Degree8 yrs expEnglishIPFSJavaRustWeb3
Job Description
• Conduct comprehensive product security assessments of blockchain-based systems, with a strong focus on Web3 security, smart contracts, and protocol-level risks
• Design and write malicious smart contracts and adversarial test cases to exploit and identify vulnerabilities in Hedera Blockchain and EVM-compatible systems
• Develop, implement, and continuously improve security strategies, architectures, and best practices for Hedera blockchain protocols, smart contracts, bridges, and associated services
• Partner closely with engineering teams to embed security into design, development, and deployment workflows
• Design and execute penetration testing, threat modeling, and vulnerability assessments across blockchain networks, nodes, APIs, and supporting infrastructure
• Identify, track, and stay ahead of emerging blockchain and Web3 threats, exploits, and attack patterns; provide actionable mitigation guidance
• Build and contribute to security tooling, frameworks, and automation tailored for blockchain environments, including CI/CD integrations
• Leverage AI/LLMs and automation to enhance product security reviews, vulnerability discovery, threat modeling, and security testing workflows
• Assist in incident response and post-incident analysis related to blockchain security events, including root cause analysis and remediation guidance
• Educate engineers and internal stakeholders on blockchain security principles, secure coding practices, and real-world attack scenarios
• Participate in and contribute to security awareness and secure development training programs across the organization
Job Requirements
- Bachelor’s or Master’s degree in Computer Science, Information Security, Cryptography, Blockchain, or a related field (or equivalent practical experience)
- 8+ years of experience in product security, application security, or penetration testing, including 2+ years focused on blockchain security, smart contract auditing, or Web3 security
- Solid understanding of EVM internals, smart contract execution, and common Web3 architectures; knowledge of Hedera Blockchain is a strong plus
- Deep knowledge of Web3 technologies and protocols, such as Ethereum, gossip-based networks, IPFS, and related decentralized systems
- Proven experience with blockchain-specific security assessment tools, methodologies, and manual testing techniques
- Strong understanding of blockchain attack vectors and vulnerability classes, including gas fees, authorization control flaws, fungible and non-fungible tokens issues, and bridge exploits
- Working knowledge of cryptographic principles and protocols relevant to blockchain systems (hashing, signatures, key management, consensus assumptions)
- Hands-on experience with static analysis, dynamic analysis, fuzzing, and custom security testing tools
- Strong understanding of secure coding practices, particularly in Java and Rust
- Excellent analytical, problem-solving, and communication skills, with the ability to collaborate effectively across engineering and product teams.
Benefits
- Health insurance
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Engineer50 days ago
Full TimeRemoteTeam 51-200Since 2012H1B No Sponsor
Senior Account Manager driving sales for advanced safety solutions at 908 Devices
United States
Senior Sales Recruiter – National Security
TRM LabsBlockchain intelligence solutions to detect, monitor and investigate fraud and financial crime in digital assets.
Security Engineer50 days ago
Full TimeRemoteTeam 51-200H1B Sponsor
Senior Sales Recruiter for TRM Labs in National Security sector
United States
SAP Basis & Security Consultant
Global Channel Management, Inc.Leveraging technology. Building relationships.
Security Engineer50 days ago
Full TimeRemoteTeam 11-50H1B No Sponsor
Remote SAP Basis & SECURITY Consultant with expertise in SAP security roles and authorizations
Azure
Director Analyst – Infrastructure Security and Networking
GartnerWe deliver actionable, objective insight that drives smarter decisions and stronger performance.
Security Engineer51 days ago
Full TimeRemoteTeam 10,001+Since 1979H1B Sponsor
Director Analyst focused on Infrastructure Security and Networking at Gartner