IT 与编程
Senior Application Security Engineer(远程职位)
Consensys
Senior Application Security Engineer:「IT 与编程」类别,完全远程
这条招聘信息来自 Consensys,岗位是 Senior Application Security Engineer:这是高级职位,公司期待由你自己拿主意。职位属于「IT 与编程」类别,完全远程。公司招的是居住在欧洲的候选人。
公司没有公布具体数字,这一项会在面试时谈定。对工作时间,招聘信息没有提出任何条件。
这个职位通过了自动核查:凡是要求外国工作许可、签证担保、特定国籍,或者必须居住在指定国家的招聘信息,都不会进入列表。
要点
- 公司
- Consensys
- 类别
- IT 与编程
- 谁可以申请
- 来自欧洲任何国家
- 工作方式
- 完全远程
- 级别
- 高级
- 用工形式
- 全职
- 发布时间
- 2026年8月16日 (9 天前)
- 有效期
- 截至 2026年9月25日
- 来源
- Jobicy
新职位邮件提醒:IT 与编程
职位板每天更新数次。只有出现新的、已核查的职位时才会写信。不发垃圾邮件,也不需要注册账号。
已经订阅过了? 管理订阅设置
公司发布的职位描述
Consensys is the leading blockchain and web3 software company. Founded by Joe Lubin, CEO of Consensys and Co-Founder of Ethereum in 2014, Consensys has been at the forefront of innovation, pioneering technological developments within the web3 ecosystem. The financial system is being rebuilt on open, programmable infrastructure, and Consensys is helping power that transition. From MetaMask, the platform trusted by tens of millions of users worldwide, to Linea, the only 100% proven zkEVM rollup and an emerging home for institutional ETH capital, Consensys builds products and infrastructure that enable users, developers, and institutions to participate in the next generation of the internet. Our mission is to unlock the collaborative power of communities by making the decentralized web universally easy to access, use, and build on. Joining Consensys means working with a fully remote, globally distributed team of technologists, designers, cryptographers, product thinkers, and researchers who are building the next layer of the internet. You'll be exposed to new ideas, emerging technologies, and complex challenges that push you to stay at the top of your game while helping scale products and infrastructure used by tens of millions of users and thousands of developers across the web3 ecosystem. You'll join a network of builders that reaches the edge of our ecosystem. Consensys alumni have moved on to become tech entrepreneurs, CEOs, and team leads at tech companies. About MetaMask We’re building for a future where the internet and world economy empowers people through interactions based on consent, privacy, and free association. Where both communities and individuals flourish. To accomplish that, we’re working hard to make web3 accessible for everyone around the world. MetaMask is both a crypto wallet and a gateway to the decentralized web. Our tools help people create communities, play video games, access financial services, make payments, invest in assets, protect against economic turmoil, and more. Our browser extension and mobile platforms meet the needs of millions of users and developers across the world. Originally a humble key manager, today MetaMask serves over 30 million monthly active users as a decentralized application development platform , an aggregator of decentralized cryptocurrency exchanges , and a decentralized identity manager. About the Role MetaMask has experienced explosive user growth over the past year as a cryptographic key manager and web3 application development platform. As this user base continues to grow, an immense amount of trust is being placed in MetaMask as a tool that manages and wields their digital authority, controlling assets, identities and more. It is of highest importance to us that we keep our users as safe and secure as possible. We are looking for a Senior Application Security Engineer to join our rapidly growing security team to help embed security into all phases of the software development lifecycle. You would work closely with development teams and product managers to ensure MetaMask products are designed and implemented to the highest security standards. Consenys’s application security team primarily supports MetaMask with opportunities to expand to additional products in the Consensys family. To apply for this position, you must have:
* 6+ years of experience building and securing software, including hands-on product or application security experience.
* Experience securing modern backend systems, web applications, and APIs.
* Experience performing threat modelling, security design reviews, and vulnerability assessment.
* Experience securing JavaScript-based applications across web and/or mobile (Node.js, React, React Native preferred).
* Strong coding skills, with the ability to work directly with engineers to identify and fix vulnerabilities or build secure solutions.
* Familiarity with Blockchain technology (particularly Ethereum), Decentralized Applications and crypto wallets
* Solid understanding of the modern web and mobile security landscape, including common attack vectors and mitigations.
* Strong communication skills, with the ability to influence engineering decisions and collaborate effectively in a remote environment.
* Self-driven and proactive, comfortable operating in a high-autonomy, distributed team.
* Alignment with our mission and values. Timezone: Most timezones will work. Regardless of where you are, some overlap with EU and US-Pacific time zones will be necessary. Nice to have:
* Experience working as a software developer.
* Deep knowledge of Ethereum (and other blockchains), Decentralized Applications and crypto wallets.
* Knowledge of smart contract implementation and security.
* You’re a MetaMask user! Responsibilities
* Determine the root cause and severity of vulnerabilities reported to us through our bug bounty platform.
* Interface with ethical hackers, triage reports, and guide product engineering teams to resolution.
* Document identified vulnerabilities in a way that allows for our engineering team to take quick action.
* Write code to support the development of security engineering projects, or fix vulnerabilities in MetaMask client applications. This includes the development of AI tooling for vulnerability determination and resolution in order to keep pace with the changing AI-powered vulnerability detection landscape.
* Assess potential security vulnerabilities within our applications, and work with development teams to ensure remediation in our established SLAs.
* Support product teams as they develop new features by conducting design reviews, threat modeling, security testing, and code reviews.
* Identify gaps in MetaMask’s secure software development life cycle (SSDLC), and take initiative leading efforts to address them.
* Participate and contribute to team meetings, roadmap planning, and discussions.
* Validate that security patches address reported vulnerabilities and test for any potential bypasses
* Proactively prevent future occurrences of a vulnerability through developing automation, security controls, and educating developers.
* Pave your own path in how you want to make MetaMask more secure. Don't meet all the requirements? Don't sweat it. We’re passionate about building a diverse team of humans and as such, if you think you've got what it takes for our chaotic-but-fun, remote-friendly, start-up environment-apply anyway, detailing your relevant transferable skills in your cover letter. While we have a pretty good idea of what we need, we're ready for you to challenge our thinking on who needs to be in this role. It is a requirement of employment in this position that applicants will be required to submit to background checks including but not limited to employment, education and criminal record checks. Further details will be provided to applicants that successfully meet the criteria for the position as determined by the company in its sole discretion. By submitting an application for employment, you are acknowledging and consenting to this requirement.
The salary range listed for this role applies to US-based candidates only. Compensation for candidates based outside the US (including Canada, EMEA, and LATAM) will be determined based on location, experience, and skills during the interview process, and may differ from the listed US range. US pay range (not including bonus, equity or other benefits) $130,000-$218,000 USD In the rapidly evolving Web3 space, we believe that everyone is a builder. This expansive paradigm requires a range of backgrounds, talents, skills, and experiences to influence and shape the future. At Consensys, this diversity fuels our ability to shift control and redefine the realm of possibility…
职位正文保留公司发布时的原文,因为投递的时候用的也是同一种语言。
关于这个职位的常见问题
我可以在自己居住的地方申请「Senior Application Security Engineer」这个职位吗?
可以。对于这个职位,Consensys 接受来自欧洲任何国家的候选人,所以你不需要其他国家的工作许可。这条招聘信息通过了自动核查:如果雇主要求工作许可、签证担保,或者必须居住在某个特定国家,它就不会出现在本站。
标明的报酬是多少?
对于这个职位,Consensys 没有公布报酬。多数远程招聘信息不给出具体数字,这件事会在面试时谈定。
怎么申请?
你通过发布在 Jobicy 上的原始招聘信息,直接向雇主提交申请。Donator 不代收申请,不收取佣金,也不保存简历。
这是什么类型的职位?
这是「IT 与编程」类别中的一个完全远程职位。混合办公的招聘信息,以及任何需要到办公室的职位,本站都不会发布。
适合这个职位的免费证书
这个领域里分量最重的几张免费证书。每一张都在发证方自己的页面上核实过。
Applied Skills (scenario-based credentials)
exam is free tooMicrosoft · ~1 h
Microsoft's only free verifiable credential: a lab task in 30-45 minutes, with no proctor, no ID check and no card. Retakes are allowed.
It has to be finished in one session; there is no save and resume.
strong brandOCI Foundations Associate
exam is free tooOracle · ~12 h
A rare case where the certification exam itself is free and needs no Pearson VUE: you sit it inside MyLearn. Take the 2026 track, not the 2025 one.
Oracle's pages load via JS; confirm the $0 on the final step of registration.
strong brandValid: 18-24 monthsCS50x: Introduction to Computer Science
certificateHarvard CS50 · ~100 h
Harvard's own branded certificate is free once you pass every problem set and the final project. The edX verified certificate is a separate paid product and is not needed.
strong brandCS50P: Programming with Python
certificateHarvard CS50 · ~60 h
Same mechanism as CS50x: at least 70% on every assignment plus a final project. The certificate does not expire.
strong brand
