Application Security Engineer
RootstockLabs Ltd. · Remote · Remote
Posted Sep 10, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
NOTE: As part of our hiring process, we conduct background and reference checks at the to validate relevant experience, qualifications, location and professional history.
ABOUT THE ROLE
As an Application Security Engineer at RootstockLabs, you will help secure our Bitcoin-secured DeFi infrastructure by reviewing code, smart contracts, and protocol changes, and by building the security automation that keeps our development lifecycle safe. You will work closely with development teams on threat modeling and architecture reviews, manage our bug bounty program end to end, and coordinate external security audits with third-party auditors. You will also research attack techniques relevant to our ecosystem (EVM, bridges, p2p) and translate them into concrete defenses, and support incident investigations when application-layer issues arise.
KEY RESPONSIBILITIES
Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects
Participate in design and architecture reviews; threat-model new products and features with development teams
Triage and validate bug bounty reports; assess severity and coordinate remediation with engineering
Collaborate on external security audits: scope engagements and work with third-party auditors through to the resolution of findings
Build and operate security automation, including AI-assisted code review, scanning, and findings-triage pipelines
Research attack techniques relevant to the ecosystem (EVM, bridges, p2p) and turn findings into concrete defenses: monitoring alerts, CI security checks, and hardening changes
Support incident investigations when application-layer issues arise
WHAT YOU BRING
3+ years of experience in Application Security or Security Engineering
Solid grasp of common vulnerability classes (OWASP Top 10) and secure code review in Java plus at least one of TypeScript/JavaScript, Python, Go, or Rust
Hands-on experience with blockchain security: smart contract auditing (Solidity/EVM) or protocol/node-level security
Experience building and operating security automation, AI-assisted workflows (LLM-based triage, code review, or scanning), SAST/DAST, dependency and secret scanning, and CI/CD security gates
Fluent English
NICE TO HAVE
Experience in bug bounty triage or vulnerability disclosure programs
Experience mitigating network-level attacks (p2p, eclipse, DoS) or analyzing consensus-level attack scenarios
Offensive security background (pentesting, red team, CTFs, exploit development)
Public security research: CVEs, bug bounty track record, audit reports, conference talks
Knowledge of C/C++ (for node/client codebases)
Experience with fuzzing (smart contracts or native code)
ROOTIES BENEFITS
At RootstockLabs, we don’t just offer a job, we offer a community. Here’s what you can expect when you join us:
Competitive compensation package and unique benefits designed to support your growth and well-being.
100%…