Security Engineer - Smart Contract Auditor
Location
Worldwide
Posted
1 day ago
Salary
0
Seniority
Mid Level
Job Description
Security Engineer - Smart Contract Auditor
Caiz
Role Description We are seeking an experienced Security Engineer – Smart Contract Auditor to ensure the robustness, transparency, and safety of our blockchain ecosystem. The role requires deep technical expertise in smart contracts, blockchain security, and cryptographic protocols. - Conduct comprehensive audits of smart contracts, blockchain protocols, and decentralized applications (dApps). - Identify, analyze, and remediate vulnerabilities in smart contracts, including reentrancy, overflow/underflow, logic errors, gas optimization issues, and governance risks. - Design and implement security best practices for smart contract development and deployment. - Collaborate with blockchain engineers to review architecture and propose secure design improvements. - Perform penetration testing and threat modeling specific to blockchain and DeFi environments. - Write detailed audit reports, including vulnerabilities, risk assessments, and recommendations. - Monitor deployed contracts and blockchain infrastructure for abnormal activities and potential exploits. - Stay updated on the latest blockchain security threats, vulnerabilities, and industry best practices. - Educate internal teams on security awareness, safe coding practices, and emerging risks. Qualifications - 3–5 years of experience in blockchain security, smart contract auditing, or cybersecurity roles. - Strong understanding of Ethereum, Solidity, and EVM-based chains (experience with other chains like BSC, Polygon, Polkadot, or Layer-2s is a plus). - Hands-on experience auditing DeFi protocols, staking contracts, NFTs, or DAO governance contracts. - Proven experience with blockchain security tools (e.g., MythX, Slither, Echidna, Foundry, Tenderly, Hardhat, Truffle). - Knowledge of cryptographic principles (hashing, signatures, zero-knowledge proofs) and applied security. - Experience publishing or contributing to audit reports, whitepapers, or security advisories is a strong plus. - Expert in Solidity, smart contract development, and debugging. - Strong analytical and problem-solving skills for identifying complex vulnerabilities. - Proficiency in penetration testing, fuzzing, and formal verification methods. - Ability to clearly document findings and communicate with both technical and non-technical stakeholders. - Familiarity with secure coding guidelines and blockchain threat landscapes. Requirements - Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Cryptography, or related technical field. - Fluent in English. Benefits - Competitive Financial Compensation: We offer financial benefits that reflect the value of your work and dedication. - Work Flexibility: Enjoy the flexibility to work from home, the office, or even abroad. - Annual Holidays: Generous paid time off to help you maintain a healthy work-life balance. - Relocation Assistance: We provide relocation support for employees moving to new locations. - Professional Development: Opportunities for training, certifications, and career growth. - Employee Recognition: Programs to celebrate and reward your achievements and contributions. - Inclusive & Collaborative Culture: A supportive and diverse work environment where your voice matters. - Diversity, Equality, and Inclusion: We are committed to fostering a workplace that values diversity and promotes equality and inclusion for all employees.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Principal Software Security Engineer
ServiceNowAs the AI platform for business transformation, we're putting AI to work across organizations — freeing people for work that matters. Making old tech work with new tech. Reaching across departments, from the front office to the back office and every office in between. Our ambition? To become the AI defining enterprise software company of the 21st century (or "AI DESCO21C," as we like to call it). With more than 8,400+ customers, we serve approximately 90% of the Fortune 500®, and we're proud to be a Fortune 100 Best Companies to Work For® and World's Most Admired Companies™. Explore your future career with us, visit www.careers.servicenow.com From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.
Company Description It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today - ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone. Job Description The ServiceNow Security Organisation (SSO): The ServiceNow Security Organisation (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact The Security Research / Offensive Security team delivers red-team-like engagements and produces investigative reports that drive a reduction in operational security risk. Paired with a toolkit of code/program and dynamic environmental analysis skills, the team provides guidance on primary security controls, best practices, and product enhancement. Exploration techniques focus on problems broadly, measuring industry trends and product insecurity across ServiceNow's cloud environment. As a Principal Software Security Engineer, you'll be responsible for delivering offensive security engagements against ServiceNow's public-facing and internal products. You'll also be responsible for security auditing of the ServiceNow product stack and researching nuances of securing SaaS platforms. This will require an in-depth knowledge of various approaches to application auditing, including secure code review, debugging, dynamic web application testing, analysis and threat modeling. You'll work closely with product engineering teams to provide investigative reports to improve platform resiliency and ensure best-in-class security solutions. What you get to do in this role: - Work with diverse business and technology owners - Participate in offensive security engagements including external adversarial emulation. - Perform security audits to discover, communicate, and recommend remediation activities for vulnerabilities - Work with engineering teams on remediation - Create and maintain strategic relationships Qualifications To be Successful in this role you have: - Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI's potential impact on the function or industry. - A passion for security and problem solving - Background in software security auditing, computer security and the statistical methods - 15+ years of experience performing software security auditing including code review, reverse engineering, thick app analysis, and black-box web application testing or related experience and education - Familiarity with NIST 800-53 and similar controls framework - Developer-level proficiency in Python, Java, and JavaScript, including modern client-side JavaScript frameworks - Experience writing static code analysis rules a plus - Experience with Python data science and machine learning frameworks a plus - Network and system security engineering skills a plus - Degree in computer science / engineering, informatics, mathematics/statistics, or equivalent work experience - Offensive Security OSWE and/or OSCP certification(s) a plus Additional Information Work Personas We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here . To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service. Equal Opportunity Employer ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. Accommodations We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance. Export Control Regulations For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. From Fortune. ©2025 Fortune Media IP Limited. All rights reserved. Used under license.
Role Description Assists in spearheading the development and enforcement of robust cybersecurity strategies, ensuring the highest level of security across all technological platforms. Leads threat prevention, detection, and remediation efforts for the organization. - Design and build robust security infrastructure that includes firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), and secure network architectures. - Ensure these measures are scalable and integrated seamlessly with existing systems. - Perform regular threat assessments to identify vulnerabilities within the network and application layers. - Develop and implement strategies to mitigate identified risks, including the deployment of patches, updates, and security enhancements. - Lead the incident response team. - Respond to security breaches and incidents with urgency, conduct thorough investigations to determine the root cause, and implement corrective actions to prevent future occurrences. - Administer security tools and technologies, ensuring they are optimized to detect and prevent malicious activities. - Evaluate and recommend new security solutions to enhance defense capabilities. - Continuously monitor network traffic for unusual or suspicious activity. - Use advanced network security tools to detect and block threats before they can infiltrate or damage the system. - Work closely with the IT department and other relevant teams to ensure security measures are aligned with organizational needs. - Report on security posture, incidents, and ongoing risk assessments to senior management. Qualifications - 7+ years of progressive information security experience, with 4+ years in a SOC, threat detection, or incident response role. - Deep expertise in Microsoft Security stack: Defender XDR, Defender for Endpoint (P2/E5), Defender for Identity, Microsoft Sentinel, and Log Analytics. - Strong KQL proficiency for custom analytics, threat hunting, and workbook development. - Hands-on experience with Entra ID / Azure AD, hybrid AD environments, and M365 security administration. - Demonstrated experience leading incident response engagements from detection through post-incident reporting. - Working knowledge of MITRE ATT&CK and its practical application to detection engineering. - Familiarity with HIPAA Security Rule requirements and healthcare security operations context. - Strong written communication skills; ability to produce clear incident reports and executive summaries. Requirements - Experience in a multi-org, multi-domain M365 tenant environment. - Hands-on experience with Logic Apps / Azure Automation for SOAR playbooks. - Familiarity with SentinelOne, Mimecast, Netwrix Auditor, or similar tooling in the NOR stack. - Experience working alongside DFIR retainer providers (e.g., Kroll, Mandiant) during major incidents. - Relevant certifications: MS-500, SC-200, SC-300, GCIH, GCFA, GDAT, CISSP, or equivalent. - Healthcare vertical experience (hospitals, health systems, or covered entities under HIPAA). - Experience with BloodHound CE, Impacket, or similar AD security audit tooling. Benefits - Pay Rate: Min - $145,000 l Max - $145,000
• Manage the ongoing serialization maintenance, tracking, and data integrity for active ecosystem devices within contracted programs • Oversee a regular cadence of equipment replacement throughout the product lifecycle to mitigate operational risks • Consult and support the Avigilon sales and partner communities on the administration and execution of the SUA program • Build, configure, and execute precise financial and cost-basis models for complex, multi-brand opportunities • Own bespoke contract structures and technical responses for partner issues and contract requests • Execute lifecycle and support services validation in strict accordance with the designated service scope • Audit and update installed base records, accurately differentiate customer-specific contracts, and analyze hardware refresh cycles • Coordinate technical details horizontally with Product Management, Quote-to-Cash (QTC), and Finance to prevent deployment delays
Lead IAM Provisioning Engineer
NTT DATA ServicesNTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers, and application services. Our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.
Role Description This SailPoint-Focused L3 Senior User Provisioning Engineer is a technical leader for identity lifecycle, entitlement engineering, and privileged access across enterprise IGA/PAM and cloud identity platforms. This role owns complex SailPoint and CyberArk integrations, designs Entra ID identity flows, manages PKI and certificate automation, and drives reliability, auditability, and automation across provisioning processes. The L3 engineer resolves escalated incidents, leads root-cause remediation, and mentors L2/L1 staff. - Technical ownership of user lifecycle and entitlement engineering across Active Directory, Entra ID, SaaS apps, and custom systems. - SailPoint IGA leadership: design, implement, and tune connectors, provisioning policies, role engineering, reconciliation, and certification campaigns. - CyberArk PAM stewardship: onboard targets, manage vault policies, implement credential rotation, and support privileged session controls. - PKI and certificate lifecycle: architect and operate certificate issuance, renewal, revocation, and automation for service identities and TLS endpoints. - Cloud identity engineering: design Entra ID conditional access, cross-tenant syncs, and entitlement models; coordinate with AWS/GCP IAM as needed. - Automation and infrastructure as code: develop and maintain SCIM/SAML/OIDC connectors, PowerShell/Python scripts, and Terraform/IaC for repeatable provisioning patterns. - Incident response and RCA: lead Tier-3 troubleshooting for provisioning failures, perform root-cause analysis, implement permanent fixes, and reduce recurrence. - Governance and audit readiness: lead access reviews, entitlement remediation, evidence collection, and support external/internal audits. - Mentorship and documentation: create runbooks, operational playbooks, and train L1/L2 engineers to improve throughput and reduce manual errors. Qualifications - 5+ years of hands-on IAM experience with progressive responsibility in provisioning and identity engineering. - Proven, practical experience with SailPoint (IGA) and CyberArk (PAM) implementations. - Deep operational knowledge of Entra ID / Azure AD and identity synchronization patterns. - Strong understanding of PKI concepts and hands-on certificate management. - Proficient with identity protocols: SCIM, SAML, OAuth/OIDC, MFA. - Advanced scripting and automation skills: PowerShell, Python, Bash; experience with Terraform or CloudFormation. - Experience with ITSM/ticketing tools (ServiceNow, Jira) and SLA management. - Demonstrated ability to perform complex troubleshooting and deliver durable engineering fixes. Preferred Qualifications - Experience integrating HR systems (Workday, SuccessFactors) with IGA. - Familiarity with Kubernetes RBAC, secrets management (Vault, Key Vault), and DevSecOps CI/CD integration. - Certifications: SailPoint, CyberArk, Microsoft Identity/Entra, CISSP, or equivalent. Soft Skills and Logistics - Analytical and detail oriented with strong problem-solving and RCA discipline. - Effective communicator able to influence engineering, security, and business stakeholders. - Proven mentor and team player who improves operational maturity. - Employment type: Full-time or contract. - Location: Remote / Hybrid / On-site. - Reports to: IAM Operations or Security Architecture Lead. Benefits - Medical, dental, and vision insurance with an employer contribution. - Flexible spending or health savings account. - Life and AD&D insurance. - Short and long term disability coverage. - Paid time off. - Employee assistance. - Participation in a 401k program with company match. - Additional voluntary or legally-required benefits.

