or apply directly on RootstockLabs Ltd.'s site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 6 days RootstockLabs Ltd.'s roles stay open a median of 45 days
- Reposted
- No
- Salary listed
- No 0% of RootstockLabs Ltd.'s roles list one
- Ghost-job risk at RootstockLabs Ltd.
- high 2 stale, 0 reposted of 3 open
- Hiring momentum
- 3 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-17
Measured from postings appearing on and disappearing from RootstockLabs Ltd.'s own greenhouse board since 2026-08-03. Full hiring picture for RootstockLabs Ltd..
About this role
As an Application Security Engineer at RootstockLabs, you will focus on securing Bitcoin-backed DeFi infrastructure by conducting security reviews of code and smart contracts, managing a bug bounty program, and coordinating external security audits. You will also engage in threat modeling, build security automation, and support incident investigations related to application-layer issues.
- benefits
- 3/5
- freshness
- 5/5
- career value
- 5/5
- role clarity
- 5/5
- pay transparency
- 0/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of RootstockLabs Ltd. as an employer.
What you need
- 3+ years of experience in Application Security or Security Engineering
- Solid grasp of common vulnerability classes (OWASP Top 10) and secure code review in Java plus at least one of TypeScript/JavaScript, Python, Go, or Rust
- Hands-on experience with blockchain security: smart contract auditing (Solidity/EVM) or protocol/node-level security
- Experience building and operating security automation, AI-assisted workflows (LLM-based triage, code review, or scanning), SAST/DAST, dependency and secret scanning, and CI/CD security gates
- Fluent English
Nice to have
- Experience in bug bounty triage or vulnerability disclosure programs
- Experience mitigating network-level attacks (p2p, eclipse, DoS) or analyzing consensus-level attack scenarios
- Offensive security background (pentesting, red team, CTFs, exploit development)
- Public security research: CVEs, bug bounty track record, audit reports, conference talks
- Knowledge of C/C++ (for node/client codebases)
What you get
- Competitive compensation package and unique benefits designed to support your growth and well-being
- 100% Remote Work within a Central European to Argentinian time-zone window (UTC-3 to UTC+2)
- Paid vacation and sick leave days
- Access to training programs, language courses, and learning sponsorship annually
- Work with cutting-edge blockchain technology in a global, diverse team
Worth weighing
- No salary listed
- Focus on blockchain security may limit exposure to other security domains
- Remote work is limited to specific time zones (UTC-3 to UTC+2)
Summarised from RootstockLabs Ltd.'s posting. Read the full original.
Listed by RootstockLabs Ltd. on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.