logo inner

Application Security Engineer

NethermindWorldwideRemote

What are we all about?


We are a team of builders and researchers on a mission to empower enterprises and developers worldwide to access and build on decentralized systems.Our expertise covers several domains: Ethereum and Starknet protocol engineering, layer-2, cryptography research, protocol research, decentralized finance (DeFi), security auditing, formal verification, real-time monitoring, smart contract development, and dapps and enterprise engineering.Working to solve some of the most challenging problems in the blockchain space, we frequently collaborate with, such as Ethereum Foundation, Starknet Foundation, Gnosis Chain, Flashbots, Forta Protocol, Lido, EigenLayer, Open Zeppelin, RISCZero, Aleph Zero, and many more.Today, we are a 350+ strong team working remotely across 66+ countries.View all our open positions here: https://www.nethermind.io/open-roles

About the role:


We are seeking an experienced Application Security Engineer to enhance the security of our applications. You will be instrumental in integrating security practices into the software development lifecycle (SDLC) and protecting against potential vulnerabilities.

Responsibilities:


  • Conduct thorough vulnerability assessments for web applications, identifying, reproducing, and resolving security vulnerabilities.
  • Address false positives / negatives to filter and fine tune found vulnerabilities.
  • Develop, implement, and maintain secure coding practices.
  • Integrate security measures within the software development lifecycle in collaboration with remote development teams.
  • Perform security-focused code reviews and support threat modeling activities.
  • Lead the implementation and maintenance of automated security testing tools for applications.
  • Lead red-team exercises to evaluate and improve security postures.
  • Stay updated with the latest security threats, trends, and technologies.
  • Mentor and provide guidance to junior security team members when necessary.
  • Participate in the design and planning phases to ensure security considerations are addressed early.

Must Haves:


  • Minimum of 5 years of application security experience.
  • Strong knowledge of web application security, including OWASP Top 10 vulnerabilities.
  • Experience with security tools and best practices in cloud environments (particularly AWS and GCP).
  • Familiarity with SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), Software Composition Analysis (SCA) practices.
  • Understanding of container security technologies such as Docker or Kubernetes.
  • Knowledge of network and web-related protocols (TCP/IP, UDP, HTTP, HTTPS).
  • Familiarity with security standards and compliance frameworks like SOC2, ISO 27001, or NIST.
  • Excellent written and verbal communication skills.
  • Strong analytical and problem-solving skills.
  • Ability to work independently and manage tasks effectively.
  • Proficiency in English for clear and concise communication.
  • Ability to work independently and manage tasks effectively in a distributed team.
  • Self-motivated with excellent time management skills suited for asynchronous work.
  • Strong organizational skills and a proactive approach to addressing challenges.

Nice to Haves:


  • General understanding of the blockchain ecosystem and the Ethereum network as well as smart contract auditing.
  • Development or scripting experience, preferably in languages such as JavaScript, TypeScript, Python, Go.
  • Experience with secure implementation of authentication and authorization systems (OAuth, JWT, SSO).
  • Experience in penetration testing using various techniques, including Living Off The Land (LOTL).
  • Experience with threat modeling frameworks, such as STRIDE and PASTA.

This position offers the opportunity to contribute to cutting-edge projects and work with a dynamic team dedicated to maintaining the highest security standards. Join us to play a pivotal role in safeguarding our applications and supporting the broader blockchain community.

Disclaimer: I hereby consent to my personal information being stored and processed by Demerzel Solutions Limited (t/a Nethermind) (the “Company”) for recruitment purposes in relation to both the selected job role and any other role the Company considers me a qualified candidate for. All data storing and processing by the Company takes place in accordance with the UK GDPR. Kindly refer to our privacy policy for more details. 


Your consent to share personal information is entirely voluntary, and you may withdraw your consent at any time. Should you have any questions about this process, or wish to withdraw your consent please contact: legalnotices@nethermind.io Keep up to date on what we are working on by following us on

our social channels


Click here to view our Privacy Policy.


Life at Nethermind

Nethermind has a world class team of builders and researchers with expertise in Ethereum, protocol engineering, layer 2 scaling, decentralized finance, smart contracts development and enterprise blockchain. We provide technology, R&D and consulting services for blockchain and DeFi businesses. The Nethermind team actively contributes to Ethereum core development and supports many Ethereum projects to help further develop the ecosystem. Working with amazing partners such as StarkWare, POA, EWF, Baseline, Provide and many more, Nethermind is building the future of blockchain and DeFi. Build with Nethermind. Github: https://github.com/NethermindEth Contact us on: hello@nethermind.io For technical assistance, join us on our Discord: https://discord.gg/PaCMRFdvWT
Thrive Here & What We Value* Collaborative Environment* Professional Growth Opportunities* Flexible Working Arrangements* Equity Opportunities* Continuous Learning & Development* Problem Solving & Analytical Skills* Mission-driven Company Culture* Open Positions Available for Viewers to Apply* Privacy Policy
Your tracker settings

We use cookies and similar methods to recognize visitors and remember their preferences. We also use them to measure ad campaign effectiveness, target ads and analyze site traffic. To learn more about these methods, including how to disable them, view our Cookie Policy or Privacy Policy.

By tapping `Accept`, you consent to the use of these methods by us and third parties. You can always change your tracker preferences by visiting our Cookie Policy.

logo innerThatStartupJob
Discover the best startup and their job positions, all in one place.
Copyright © 2024