Born from groundbreaking research at Columbia University and Yale UniversityCertiK is a leading Web3 security company focused on securing blockchain protocols smart contracts and decentralized applications through cutting-edge security research formal verification and AI-powered technology. Founded in 2017 and headquartered in New York City CertiK provides end-to-end security solutions including smart contract audits penetration testing on-chain monitoring incident response and compliance services for some of the largest projects in the digital asset ecosystem.
Today CertiK supports thousands of enterprise clients and Web3 projects globally with a distributed international team spanning North America Asia and Europe. The company is backed by leading investors including Coatue Goldman Sachs Insight Partners and Sequoia Capital and has been recognized by organizations such as the World Economic Forum and CB Insights for its contributions to blockchain security innovation.
About the Role
The primary responsibility of this role is for CertiKs security-related services. Intersecting cybersecurity and blockchain CertiKs security offerings include security consulting security reviews security auditing of smart contracts and blockchains verification of smart contracts penetration testing and more. We are looking to hire someone with a passion for application security and penetration testing. This is a fun and challenging full-time position. If you are excited about hacking threat modeling scanning auditing designing and enhancing the security of applications across the board then you will thrive in this role. While you work with clients we will also provide you with plenty of opportunities to get involved with research and development efforts to help us raise the standards of blockchain security.
Responsibilities
Lead design/deployment of enterprise-grade security solutions to safeguard internal networks/applications/infrastructure ensuring confidentiality/integrity/availability of mission-critical systems & data
Define/enforce organization-wide security policies/standards; own end-to-end vulnerability management lifecycle & lead cross-functional incident response with engineering/IT/compliance teams
Oversee real-time threat detection/response operations; conduct forensic investigations & drive root cause analysis for high-impact security incidents to inform long-term defense strategies
Manage/execute comprehensive security assessments across internal/third-party systems including architecture reviews/endpoint security evaluations/infrastructure hardening initiatives
Guide secure development practices by applying advanced static/dynamic analysis to identify vulnerabilities & deliver remediation guidance to engineering teams
Conduct threat modeling/risk analysis for high-value systems to proactively identify/mitigate attack vectors & influence system/product architecture
Masters degree in Computer Science Software Engineering Security Informatics or related field.
Expertise in threat modeling/architectural risk assessment using structured methodologies (e.g. STRIDE/DREAD)
Advanced knowledge of SSDLC including static/dynamic analysis/QA practices & end-to-end vulnerability lifecycle management (tracking/remediation coordination/verification)
Strong ability to conduct comprehensive security assessments across network infrastructure/application architecture/system configurations
Familiarity with cloud environments (AWS/Azure/GCP) & CI/CD deployment workflows; Proficiency in Java/Python with applied skills in secure coding/debugging/symbolic execution & internal tooling/automation scripting
Target annual salary compensation for this role performed is $130000 to $160000. The exact compensation at which this job is filled will be determined by the skills and experience of qualified candidates.
CertiK is proud to offer medical vision and dental insurance 401(k) plan with company matching life and accidental death and dismemberment insurance HSA (with high deductible plan) FSA and other benefits to all full-time employees along with flexible paid time off and holidays. CertiK also offers a variable commission program for business development sales roles.
In compliance with federal law all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
CertiK is proud to be an equal opportunity employer. We will not discriminate against any applicant or employee on the basis of age race color creed religion sex sexual orientation gender gender identity or expression medical condition national origin ancestry citizenship marital status or civil partnership/union status physical or mental disability pregnancy childbirth genetic information military and veteran status or any other basis prohibited by applicable federal state or local law.
CertiK will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements.
We may use artificial intelligence (AI) tools to support parts of the hiring process such as reviewing applications analyzing resumes or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed please contact us.
Required Experience:
Senior IC
About the CompanyBorn from groundbreaking research at Columbia University and Yale UniversityCertiK is a leading Web3 security company focused on securing blockchain protocols smart contracts and decentralized applications through cutting-edge security research formal verification and AI-powered tec...
About the Company
Born from groundbreaking research at Columbia University and Yale UniversityCertiK is a leading Web3 security company focused on securing blockchain protocols smart contracts and decentralized applications through cutting-edge security research formal verification and AI-powered technology. Founded in 2017 and headquartered in New York City CertiK provides end-to-end security solutions including smart contract audits penetration testing on-chain monitoring incident response and compliance services for some of the largest projects in the digital asset ecosystem.
Today CertiK supports thousands of enterprise clients and Web3 projects globally with a distributed international team spanning North America Asia and Europe. The company is backed by leading investors including Coatue Goldman Sachs Insight Partners and Sequoia Capital and has been recognized by organizations such as the World Economic Forum and CB Insights for its contributions to blockchain security innovation.
About the Role
The primary responsibility of this role is for CertiKs security-related services. Intersecting cybersecurity and blockchain CertiKs security offerings include security consulting security reviews security auditing of smart contracts and blockchains verification of smart contracts penetration testing and more. We are looking to hire someone with a passion for application security and penetration testing. This is a fun and challenging full-time position. If you are excited about hacking threat modeling scanning auditing designing and enhancing the security of applications across the board then you will thrive in this role. While you work with clients we will also provide you with plenty of opportunities to get involved with research and development efforts to help us raise the standards of blockchain security.
Responsibilities
Lead design/deployment of enterprise-grade security solutions to safeguard internal networks/applications/infrastructure ensuring confidentiality/integrity/availability of mission-critical systems & data
Define/enforce organization-wide security policies/standards; own end-to-end vulnerability management lifecycle & lead cross-functional incident response with engineering/IT/compliance teams
Oversee real-time threat detection/response operations; conduct forensic investigations & drive root cause analysis for high-impact security incidents to inform long-term defense strategies
Manage/execute comprehensive security assessments across internal/third-party systems including architecture reviews/endpoint security evaluations/infrastructure hardening initiatives
Guide secure development practices by applying advanced static/dynamic analysis to identify vulnerabilities & deliver remediation guidance to engineering teams
Conduct threat modeling/risk analysis for high-value systems to proactively identify/mitigate attack vectors & influence system/product architecture
Masters degree in Computer Science Software Engineering Security Informatics or related field.
Expertise in threat modeling/architectural risk assessment using structured methodologies (e.g. STRIDE/DREAD)
Advanced knowledge of SSDLC including static/dynamic analysis/QA practices & end-to-end vulnerability lifecycle management (tracking/remediation coordination/verification)
Strong ability to conduct comprehensive security assessments across network infrastructure/application architecture/system configurations
Familiarity with cloud environments (AWS/Azure/GCP) & CI/CD deployment workflows; Proficiency in Java/Python with applied skills in secure coding/debugging/symbolic execution & internal tooling/automation scripting
Target annual salary compensation for this role performed is $130000 to $160000. The exact compensation at which this job is filled will be determined by the skills and experience of qualified candidates.
CertiK is proud to offer medical vision and dental insurance 401(k) plan with company matching life and accidental death and dismemberment insurance HSA (with high deductible plan) FSA and other benefits to all full-time employees along with flexible paid time off and holidays. CertiK also offers a variable commission program for business development sales roles.
In compliance with federal law all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
CertiK is proud to be an equal opportunity employer. We will not discriminate against any applicant or employee on the basis of age race color creed religion sex sexual orientation gender gender identity or expression medical condition national origin ancestry citizenship marital status or civil partnership/union status physical or mental disability pregnancy childbirth genetic information military and veteran status or any other basis prohibited by applicable federal state or local law.
CertiK will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements.
We may use artificial intelligence (AI) tools to support parts of the hiring process such as reviewing applications analyzing resumes or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed please contact us.