5 days ago

Product Security Engineer

Aptos Labs

Hybrid
Full Time
$180,000
Hybrid

Job Overview

Job TitleProduct Security Engineer
Job TypeFull Time
CategoryCommerce
Experience5 Years
DegreeMaster
Offered Salary$180,000
LocationHybrid

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Aptos Labs

Aptos is a people-first blockchain on a mission to help billions of people achieve universal and fair access to decentralized assets in a safe and scalable way.

Founded by some of the original creators and maintainers that researched, designed, and built the Diem blockchain to serve this purpose, we have dedicated several years toward this mission. We believe the open-source Diem technology we have developed is an important foundation of a safe and scalable web3 world where everyone has more equitable opportunities to grow and access financial assets with lower fees and fewer intermediaries.

Aptos (Ohlone for "The People") encompasses our mission and ethos for why we build.

About The Role

At Aptos Labs we’re pioneering the future of web3 and need a passionate Product Security Engineer to help secure our core technologies. In this role, you’ll be at the forefront of safeguarding our Aptos core infrastructure and Aptos Labs products. Your proactive approach will help us identify and mitigate emerging threats, ensuring our systems remain resilient and trustworthy. You will work closely with our developers, influence security best practices, and lead initiatives that shape the future of web3 security.

Responsibilities

  • Analyze and assess novel and recurring security issues via design reviews, code audits, and penetration tests.
  • Design and build security tools, and develop mitigations, frameworks, and hardening strategies tailored for vulnerability prevention and detection.
  • Review and develop secure operational practices, and provide security guidance for engineers.
  • Respond to and triage reports from bug bounty programs.

Minimum Qualifications

  • B.S. or M.S. in Computer Science, a related technical field, or equivalent experience.
  • 3+ years of experience in vulnerability research and exploitation.
  • Experience with native development practices and common vulnerability patterns (e.g., Rust, C, etc.)
  • Experience with automated security analysis tooling and frameworks (fuzzing, static analysis, etc.)

Preferred Qualifications

  • Contributions to the security community (public research, blogging, talks in relevant conferences, etc.)
  • Experience with virtual machines or complex runtime environments, such as MoveVM (extra bonus), EVM, WASM, or LLVM-based runtimes, including their security models, sandboxing, and execution isolation.
  • Familiarity with smart contract programming languages (extra bonus for Move), security tools, and frameworks, including formal verification.

Our Benefits

  • 100% insurance premium coverage for medical, dental, and vision for you and your dependents (US Employees)
  • Equipment of your choice
  • Flexible vacation time, 11 holidays, and floating company days off
  • Competitive Salary
  • Protocol Token Grants
  • 401k matching (US Employees)
  • Fun and inclusive in-person and digital events

Aptos is committed to diversity in the workplace, and we’re proud to be an Equal Opportunity Employer. We do not hire on the basis of race, color, religion, creed, gender, national origin, citizenship, age, disability, veteran status, marital status, pregnancy, parental status, sex, gender expression or identity, sexual orientation, or any other basis protected by local, state or federal law. All employment is decided based on qualifications, merit, and business need.

We are committed to providing a safe and secure hiring process for all applicants. Unfortunately, there are individuals who may attempt to impersonate Aptos or our employees for fraudulent purposes.

To Protect Yourself, Please Be Aware Of The Following

  • We will never ask you for payment of any kind during the application or onboarding process, including fees for background checks, training, or equipment.
  • We will always communicate with you using our official company email domain.
  • We will never request your personal financial information, such as your social security number or bank account details, during the initial application stages or via email or a video/voice call when onboarding.

Key skills/competency

  • Vulnerability Research
  • Exploitation
  • Native Development Security
  • Rust/C Programming
  • Automated Security Analysis
  • Fuzzing
  • Static Analysis
  • Web3 Security
  • Blockchain Security
  • Smart Contract Security

Tags:

Product Security Engineer
Security Engineering
Vulnerability Research
Code Audits
Penetration Testing
Threat Modeling
Secure Design
Security Tools
Bug Bounty
Web3 Security
Blockchain Security
Rust
C
MoveVM
EVM
WASM
LLVM
Fuzzing
Static Analysis
Smart Contracts
Cryptography

Share Job:

How to Get Hired at Aptos Labs

  • Research Aptos Labs' culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor. Focus on their "people-first" blockchain approach and open-source contributions.
  • Tailor your resume: Customize your resume to highlight experience in vulnerability research, exploitation, native development security (Rust, C), and automated security analysis tools. Emphasize Web3 security and blockchain experience if applicable.
  • Showcase security expertise: Prepare to discuss specific contributions to the security community, experience with virtual machines (MoveVM, EVM, WASM), and familiarity with smart contract security tools.
  • Master the technical interview: Be ready for in-depth questions on secure coding practices, threat modeling, penetration testing methodologies, and designing secure systems within complex runtime environments.
  • Demonstrate passion for Web3: Express genuine interest in Aptos Labs' mission to enable universal access to decentralized assets and secure blockchain technologies.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background