Senior Application Security Engineer

Remote $130k–$218k senior 5 days ago full-time quality 9/10

Role in brief

Consensys is seeking a Senior Application Security Engineer for MetaMask, a prominent crypto wallet. This role focuses on improving application security, responding to vulnerability reports, and guiding engineering teams. It is suitable for experienced security professionals with a background in JavaScript applications and blockchain technology.

JavaScriptNode.jsReactReact NativeBlockchainEthereum

About the role

As a Senior Application Security Engineer, you will be crucial in safeguarding MetaMask, a crypto wallet used by over 30 million people. Your primary responsibilities will involve managing vulnerabilities reported through the bug bounty program, including determining their root cause and severity. You will also work directly with ethical hackers and product engineering teams to ensure these issues are resolved effectively.

A significant part of this role involves hands-on security engineering, which includes writing code to support security projects or directly fixing vulnerabilities within MetaMask's client applications. You will also provide security guidance to product teams by conducting design reviews, threat modeling, and security testing. This ensures that security is integrated throughout the development lifecycle.

Success in this position means actively identifying and addressing gaps in MetaMask's secure software development lifecycle. You will contribute to a more robust security posture for the platform by supporting product teams through various security assessments and code reviews, ultimately enhancing the safety and reliability of the decentralized web gateway.

The salary for this position ranges from $130,000 to $218,000 USD.

Skills that matter here

  • JavaScript: This role requires securing applications built with JavaScript, including Node.js, React, and React Native.
  • Node.js: Experience securing backend systems developed with Node.js is a key requirement.
  • React: You will be securing web applications that utilize the React framework.
  • React Native: Securing mobile applications built with React Native is part of the role's responsibilities.
  • Blockchain: Familiarity with blockchain technology, especially Ethereum, is necessary for understanding the underlying platform.
  • Ethereum: Knowledge of Ethereum is important given MetaMask's role as a gateway to the decentralized web.

Who this role suits

  • You have a strong background in securing modern software, including web and mobile applications.
  • You are adept at analyzing vulnerabilities, communicating with external security researchers, and guiding internal teams to remediation.
  • You are comfortable with hands-on coding to implement security fixes and support security engineering initiatives.
  • You possess an understanding of blockchain technology and decentralized applications.

From the employer

  • Determine the root cause and severity of vulnerabilities reported through the bug bounty platform
  • Interface with ethical hackers, triage reports, and guide product engineering teams to resolution
  • Write code to support security engineering projects, or fix vulnerabilities in MetaMask client applications
  • Support product teams by conducting design reviews, threat modeling, security testing, and code reviews
  • Identify gaps in MetaMask's secure software development life cycle (SSDLC)
  • 6+ years of experience building and securing software, including hands-on product or application security experience
  • Experience securing modern backend systems, web applications, and APIs
  • Experience securing JavaScript-based applications across web and/or mobile (Node.js, React, React Native preferred)
  • Familiarity with Blockchain technology (particularly Ethereum), Decentralized Applications and crypto wallets

Questions about this role

What is the seniority level for this position?

This is a senior-level position.

What kind of experience is required?

Candidates should have at least 6 years of experience building and securing software, with a focus on product or application security.

How do I apply for this role?

The job posting does not provide specific application instructions.

Similar jobs

Before you apply

  • Legitimate employers never ask you to pay anything to apply or get hired.
  • Never share seed phrases or private keys. No real job needs them.
  • Do not install software ("test tasks", "trading tools", "video call clients") sent during hiring.
  • Check that the application page's domain really belongs to Consensys.