Security Engineering Lead
Lead security and auditing efforts for Espresso's codebase, identify vulnerabilities in complex distributed systems, coordinate engineering and external audit teams, guide hardening efforts, and improve testing and maintainability.
Responsibilities
- Lead security audits of the codebase
- Organize and structure security and audit efforts
- Analyze and review complex distributed system code
- Coordinate with engineering teams to communicate findings and guide system hardening
- Manage and review external security audits
- Propose improvements to testing and engineering practices for security and maintainability
Requirements
- Solid grasp of low-level and high-level software engineering principles
- At least 1 year of Rust experience, particularly async Rust, if focused on Rust
- Multiple years of smart-contract development experience and smart-contract security audit or formal-verification experience if focused on Solidity
- Experience as an engineer or software architect in a security-critical industry
- Ability to describe security stakes, challenges, and mitigation steps
- Experience as an auditor, pentester, or QA tester
- A thoughtful approach to testing software and designing it to be testable and auditable
- Ability to think adversarially and identify reliability or security vulnerabilities
- Experience designing or testing distributed systems
- Comfort diving into unknowns and asking questions
- Knowledge of testing and static-analysis tools such as Foundry and Slither is a plus
- Blockchain knowledge or experience is preferred but not required
- Experience working on security-critical systems is preferred
Benefits
- Fully remote with flexible hours
- Work alongside leading contributors in the crypto space
- Competitive salary and equity package
- Regular international team off-sites
- Unlimited vacation policy
- Top-tier health, dental, and vision coverage for US employees