Why Us?
CertiK is a pioneer in blockchain security, leveraging best-in-class AI technology to protect and monitor blockchain protocols and smart contracts. Founded in 2018 by professors from Yale University and Columbia University, CertiK’s mission is to secure the web3 world. CertiK applies cutting-edge innovations from academia to enterprise, enabling mission-critical applications to scale with safety and correctness.
About the Role
The primary responsibility of this role is for CertiK’s security-related services. Intersecting cybersecurity and blockchain, CertiK’s security offerings include security consulting, security reviews, security auditing of smart contracts and blockchains, verification of smart contracts, penetration testing, and more. We are looking to hire someone with a passion for application security and penetration testing. This is a fun and challenging full-time position. If you are excited about hacking, threat modeling, scanning, auditing, designing, and enhancing the security of applications across the board then you will thrive in this role. While you work with clients, we will also provide you with plenty of opportunities to get involved with research and development efforts to help us raise the standards of blockchain security.
Responsibilities
Perform security assessments on web, mobile, thick client applications, and browser extensionsConduct external and internal network penetration testsPerform security source code reviewsPerform cloud security reviewsDevelop comprehensive pentest reports for both technical and non-technical audiencesResearch and develop innovative techniques, tools, and methodologies for pentesting applications in the blockchain space Contribute to the community by developing tools, presentations, and blog posts
Requirements
Passionate about cryptocurrency, DeFi, and blockchain, with a willingness to learn Web3 technologies such as smart contractsMinimum of 4 years of experience in application security and penetration testingExperienced in source code review for different languages, with a strong understanding of JavaScript and TypeScriptExperienced in mobile application penetration testingFamiliar with cloud platforms and their security risks, such as AWS, Azure, and GCPExperience in programming with scripting languages such as Python and BashSolid understanding of cryptographyBS/MS/PhD in Computer Science or Information Security Strong spoken and written communication skills
Bonus Points
Experienced in pentesting Web3 applications such as crypto exchanges, wallets, Dapps, and key custodian solutions Experienced in smart contract security auditsFamiliar with browser extension architecture and security risksActively participate in the blockchain security communityOSCP, OSWE, OSCE, GWAPT, or comparable certificationParticipated in bug bounty programs and audit contestsPublished security-related blog posts and spoken at security conferences and/or local meetups