Protocol Security Researcher
Salva questo lavoro e mantieni la tua ricerca organizzata
Crea un account gratuito per salvare lavori, creare avvisi e tornare a questa inserzione dalla tua dashboard.
Continuando accetti i nostri Termini & Informativa sulla privacy.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Protocol Security Researcher based in Italy.
This is an opportunity to help build and strengthen an internal protocol security function within a globally distributed engineering environment.
È essenziale assicurarsi di soddisfare i requisiti per questo ruolo; la preghiamo di leggere attentamente quanto segue.
You will work at the intersection of smart contract security, protocol design, adversarial research, and AI-assisted security review.
Your work will help assess major protocol changes before deployment and identify risks across complex decentralized financial systems.
The role goes beyond traditional auditing, with a focus on continuously improving how protocol risks are understood, tested, monitored, and reduced.
You will collaborate closely with engineers, security specialists, monitoring teams, incident responders, and external auditors.
You will also contribute to reusable security knowledge, tooling, invariants, and testing strategies that can improve review quality and efficiency.
The position offers significant scope to influence security decisions early and help shape the evolution of a high-impact protocol security function.
Review significant protocol and smart contract changes before external audits or production deployment.
Conduct attacker-driven security research across smart contracts, protocol mechanisms, integrations, and related infrastructure.
Participate in architecture and design discussions early enough to influence security-critical decisions.
Investigate risks across adjacent systems, including assets, bridges, oracles, adapters, and other critical dependencies.
Analyze potential protocol-level failure modes and translate technical concerns into concrete exploitation scenarios, impact assessments, and mitigation strategies.
Develop and contribute to AI-assisted security tooling, while evaluating its effectiveness in real-world security review workflows.
Convert security findings into reusable knowledge, invariants, assumptions, tests, monitoring strategies, and other durable security practices.
Collaborate with monitoring and incident response teams when identified risks require operational detection or response mechanisms.
Work alongside external auditors to help define audit scope, communicate known risks, and highlight areas requiring particular attention.
5+ years of relevant security experience, with a strong background in smart contract and protocol security.
Demonstrated ability to independently review complex codebases and reason deeply about protocol-level failure modes.
Strong adversarial mindset, with the ability to move from identifying suspicious behavior to explaining how a vulnerability could realistically be exploited.
Strong understanding of decentralized finance mechanisms, including lending, liquidations, accounting, oracles, collateral, governance, and protocol integrations.
Demonstrated use of AI to improve security research, review quality, analysis depth, or review throughput.
Strong written and verbal communication skills, with the ability to explain risks, impact, uncertainty, and trade-offs to both technical and non-technical stakeholders.
Sound judgment when assessing severity, exploitability, practical impact, and the relevance of individual findings.
Experience with formal methods, fuzzing, invariant testing, or custom security tooling is a plus.
Experience developing internal tools for security reviews, code understanding, security research, or knowledge management is valued.
Experience collaborating with external audit firms or leading security audit engagements is advantageous.
Familiarity with governance payloads, upgrade mechanisms, permissioning systems, and incident response is beneficial.
Open-source security research, published vulnerability findings, CTF participation, bug bounty experience, or prior public security research is a plus.
Candidates who do not meet every listed requirement but bring relevant and demonstrable security expertise are encouraged to apply.
Remote-first working environment with flexibility across Europe, Asia, and the United States.
Opportunity to work on complex smart contract, DeFi, and protocol security challenges with meaningful real-world impact.
Broad scope to influence security architecture, research practices, tooling, and internal security processes.
Collaboration with experienced engineers, security rese