Skip to content
ITA Jobs
All vacancies
RootstockLabs logo

Application Security Engineer

RootstockLabs

Remote · worldwide, UTC+4 acceptedSalary not disclosedfull-timeVerified 4 days agoHimalayas

As an Application Security Engineer at RootstockLabs, you will help secure our Bitcoin-secured DeFi infrastructure by reviewing code, smart contracts, and protocol changes, and by building the security automation that keeps our development lifecycle safe. You will work closely with development teams on threat modeling and architecture reviews, manage our bug bounty program end to end, and coordinate external security audits with third-party auditors.

Responsibilities

  • Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects
  • Participate in design and architecture reviews; threat-model new products and features with development teams
  • Triage and validate bug bounty reports; assess severity and coordinate remediation with engineering
  • Collaborate on external security audits: scope engagements and work with third-party auditors through to the resolution of findings
  • Build and operate security automation, including AI-assisted code review, scanning, and findings-triage pipelines
  • Research attack techniques relevant to the ecosystem (EVM, bridges, p2p) and turn findings into concrete defenses: monitoring alerts, CI security checks, and hardening changes
  • Support incident investigations when application-layer issues arise
  • WHAT YOU BRING
  • 3+ years of experience in Application Security or Security Engineering
  • Solid grasp of common vulnerability classes (OWASP Top 10) and secure code review in Java plus at least one of TypeScript/JavaScript, Python, Go, or Rust

Languages

    Work format
    Remote
    Seniority
    Mid
    Posted
    13 Sept 2026 (4 days ago)
    Last verified
    13 Sept 2026
    Apply by
    12 Nov 2026

    Keep looking