waypointjobs

RootstockLabs

Application Security Engineer

Remote — Worldwide (see timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

NOTE: As part of our hiring process, we conduct background and reference checks at the to validate relevant experience, qualifications, location and professional history.

ABOUT THE ROLE

As an Application Security Engineer at RootstockLabs, you will help secure our Bitcoin-secured DeFi infrastructure by reviewing code, smart contracts, and protocol changes, and by building the security automation that keeps our development lifecycle safe. You will work closely with development teams on threat modeling and architecture reviews, manage our bug bounty program end to end, and coordinate external security audits with third-party auditors. You will also research attack techniques relevant to our ecosystem (EVM, bridges, p2p) and translate them into concrete defenses, and support incident investigations when application-layer issues arise.

KEY RESPONSIBILITIES

Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects

Participate in design and architecture reviews; threat-model new products and features with development teams

Triage and validate bug bounty reports; assess severity and coordinate remediation with engineering

Collaborate on external security audits: scope engagements and work with third-party auditors through to the resolution of findings

Build and operate security automation, including AI-assisted code review, scanning, and findings-triage pipelines

Research attack techniques relevant to the ecosystem (EVM, bridges, p2p) and turn findings into concrete defenses: monitoring alerts, CI security checks, and hardening changes

Support incident investigations when application-layer issues arise

WHAT YOU BRING

3+ years of experience in Application Security or Security Engineering

Solid grasp of common vulnerability classes (OWASP Top 10) and secure code review in Java plus at least one of TypeScript/JavaScript, Python, Go, or Rust

Hands-on experience with blockchain security: smart contract auditing (Solidity/EVM) or protocol/node-level security

Experience building and operating security automation, AI-assisted workflows (LLM-based triage, code review, or scanning), SAST/DAST, dependency and secret scanning, and CI/CD security gates

Fluent English

NICE TO HAVE

Experience in bug bounty triage or vulnerability disclosure programs

Experience mitigating network-level attacks (p2p, eclipse, DoS) or analyzing consensus-level attack scenarios

Offensive security background (pentesting, red team, CTFs, exploit development)

Public security research: CVEs, bug bounty track record, audit reports, conference talks

Knowledge of C/C++ (for node/client codebases)

Experience with fuzzing (smart contracts or native code)

ROOTIES BENEFITS

At RootstockLabs, we don’t just offer a job, we offer a community. Here’s what you can expect when you join us:

Competitive compensation package and unique benefits designed to support your growth and well-being.

100% Remote Work working within a Central European to Argentinian time-zone window (UTC-3 to UTC+2, with about an hour's flexibility either side), and with access to global coworking spaces.

Work-Life Balance: Paid vacation and sick leave days

Continuous Learning: Access to training programs, language courses, and learning sponsorship annually.

Unique Projects: Work with cutting-edge blockchain technology in a global, diverse team.

ABOUT ROOTSTOCKLABS

RootstockLabs builds Bitcoin-secured DeFi infrastructure that enables companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale.

Market: Companies, financial institutions, and their customers

Product: Bitcoin-secured DeFi financial products

Distribution: B2B2C through regulated financial institutions

We operate at the intersection of crypto infrastructure and institutional finance, enabling compliant, scalable access to decentralized financial services powered by Bitcoin.

Originally posted on Himalayas

Who can apply

The source lists worldwide eligibility. Accepted UTC offsets: UTC-11, UTC-10, UTC-9.5, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC-4, UTC-3.5, UTC-3, UTC-2, UTC-1, UTC+0, UTC+1, UTC+2, UTC+3, UTC+3.5, UTC+4, UTC+4.5, UTC+5, UTC+5.5, UTC+5.75, UTC+6, UTC+6.5, UTC+7, UTC+8, UTC+8.75, UTC+9, UTC+9.5, UTC+10, UTC+10.5, UTC+11, UTC+12, UTC+12.75, UTC+13, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job