MLabs logo
MLabs

We are a Haskell, Rust, Blockchain and AI consultancy.

Product Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200H1B No SponsorCompany SiteLinkedIn

Location

Germany

Posted

9 days ago

Salary

$75K - $85K / year

Seniority

Senior

Job Description

Product Security Engineer

MLabs

• Conduct end-to-end security assessments of blockchain-based systems, spanning cryptographic primitive design, protocol architecture, smart contract implementation, and deployed infrastructure. • Own threat modeling and security architecture reviews across all product phases. • Identify real-world vulnerabilities through rigorous hands-on code reviews, adversarial testing, and the development of proof-of-concept exploits for native services, EVM-compatible contracts, cross-chain bridges, and consensus-layer components. • Partner directly with core engineering teams to translate complex cryptographic and protocol-level risks into prioritized, actionable remediation workflows. • Define and enforce security gates prior to production deployment. • Build, scale, and improve security tooling, fuzzing infrastructure, and CI/CD security automation to maximize security coverage efficiently. • Track emerging blockchain and Web3 attack patterns, map them to the internal codebase, and drive proactive mitigation strategies.

Job Requirements

  • Proven track record of hands-on vulnerability discovery and security testing across blockchain protocols, smart contracts, nodes, and APIs, with a demonstrated ability to identify deep architectural bugs beyond automated scanning.
  • Strong threat modeling and security architecture review experience applied directly to distributed cryptographic systems.
  • Direct experience assessing cross-chain protocols, threshold signature schemes, or other cryptographic systems with complex trust assumptions, including the auditing or breaking of cross-chain bridges.
  • Deep working knowledge of applied cryptography (e.g., BLS signatures, pairing-based schemes, polynomial commitments, and Fiat-Shamir constructions) and the ability to reason about cryptographic failure modes in production environments.
  • Ability to analyze trust model tradeoffs, including state proof, multisig, and oracle attestation models, and evaluate their impact on the broader attack surface.
  • Mastery of blockchain security and secure coding practices across both EVM-compatible and non-EVM chains.
  • Proficiency with security testing tooling, including static analysis, dynamic analysis, and fuzzing, alongside experience developing custom fuzzing harnesses or security test infrastructure.
  • Strong ability to read, review, and audit cryptographic code written in Rust and/or Java.
  • Clear understanding of memory safety, constant-time correctness, secret handling, and the unique security risks at JNI boundaries.
  • Experience designing and operating grammar-aware fuzzing campaigns against gRPC, JSON-RPC, or protocol-level endpoints.
  • Experience building classifier pipelines to isolate security signals from noise, or building custom security automation tooling.
  • Prior security work focused on Ethereum consensus clients or production threshold signature systems.
  • Experience integrating AI-assisted workflows into security review and triage processes.

Benefits

  • Competitive salary and compensation package.
  • Opportunity to work at the forefront of enterprise Web3 infrastructure and cryptographic innovation.
  • Collaborative, high-caliber engineering environment focused on solving complex, large-scale distributed systems challenges.
  • Flexible working arrangements and comprehensive professional growth opportunities.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 10,001+H1B Sponsor

• Extensive experience in pre-sales designing and proposing secure platform solutions • Hands on experience in architectural administration, proving designs in simulated and production environments. • Building technical security solutions, proving their viability and providing technological justifications • Ability to design complete network, cloud and security solutions providing strong technical Roadmaps • Knowledge in the following architectural technologies: Secure Networking, Secure Wireless, Private/Public Cloud, SD WAN, SASE, Zero trust, AI, Automation, Sec Ops, Operational Technology, Forensics & IR response • Strong presentation and white boarding skills • Strong communication and written skills, including responding to technical RFPs. • Proactively identify technical opportunities within the field to increase pipeline growth and team prosperity • Leading proof of concept valuations, technical workshops and events • Become a passionate industry leader that can articulate a compelling vision • Model a high standard of performance, professionalism, and integrity in all interactions • Facilitate effective communication and teamwork across departments or teams

Canada
Full TimeRemoteTeam 10,001+H1B Sponsor

• Collaborate with assigned Sales Representative to develop secure platform solutions • Be the main technical resource on sales calls and educate the customer • Strategizing about future services or capabilities customers may require within your account base • Support your customer through issue resolution by collaborating with TAC and other technical resources • Build technical business relationships with key customers and partners • Presenting at events, seminars, customer and partner meetings

Canada
Asymmetric logo

Enterprise Security Engineer – Incident Response

Asymmetric

Early stage capital for disruptive technology companies.

ContractRemoteTeam 1-10H1B No Sponsor

• Serve as Incident Commander for SIRN-related security cases, owning coordination from detection through resolution and post-incident review. • Lead incident triage efforts, rapidly assessing scope, severity, and impact to drive prioritization and response decisions. • Coordinate with internal AR teams and external Solana ecosystem stakeholders throughout active incident lifecycles. • Develop, tune, and triage telemetry signals relevant to SIRN use cases, including on-chain event monitoring and infrastructure-level detection. • Identify gaps in current detection coverage and propose improvements to signal fidelity and alert quality. • Author, maintain, and continuously improve incident runbooks tailored to SIRN scenarios. • Provide operational and logistical support to the SIRN project team, including tracking deliverables, coordinating stakeholder communications, and ensuring project milestones are met. • Maintain clear documentation across all assigned workstreams.

United States
Primer logo

Security Engineer

Primer

Powerful no-code automation for payments and commerce.

Full TimeRemoteTeam 51-200H1B Sponsor

• Running security reviews and threat modelling on features and systems across Primer's product, and turning findings into clear, actionable guidance for the teams shipping them • Independently planning and delivering your own security projects, from initial design through to rollout • Building tooling and automation that makes future reviews faster and cheaper to run • Coordinating penetration testing and tracking remediation through to closure • Supporting the recurring compliance work (SOC2, PCI), including evidence collection and remediation tracking against fixed audit windows • Contributing to AppSec roadmap initiatives across areas like application threats, AI security, supply chain security, and ASPM • Picking up proactive security work, threat research and hands-on investigation, that a one-person function has never had the capacity for • Working alongside Cloud, Infra, and GRC on the security aspects of their projects

Poland