远程工作雷达

高级渗透测试员(AWS)

Senior Penetration Tester (AWS)

其他全球可投
公司Offchainlabs
薪资未公开
工作地点Remote
地域资格全球可投
时区要求无特别要求
用工类型Full-time
发布时间未知
数据来源Lever
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

在Offchain,我们不仅仅是打造产品:我们引领着一场运动。

作为区块链扩展性和安全性的先驱,我们正处于改变世界与去中心化应用互动方式的最前沿。我们正在奠定将定义下一代数字商业、治理和人类互动的基础。这包括解决区块链技术扩展过程中出现的实际问题,同时不牺牲其核心原则:去中心化、安全性和透明性。

这个愿景的核心是我们的团队。我们的团队由善于思考和勇于行动的人组成,他们拥抱新的挑战,并寻求突破现有边界的解决方案。如果你热衷于解决前所未有的问题,并相信去中心化系统将在创造更公平的数字未来中发挥重要作用,那么我们希望听到你的声音。

为什么选择Offchain?

Offchain正在为整个以太坊生态系统设定节奏。我们构建了Arbitrum堆栈,该堆栈为Arbitrum One提供支持,这是目前最广泛采用的以太坊扩展解决方案。

如今,Arbitrum One上已有数百个项目和dApps。超过100个不同的团队使用Offchain技术构建了自己的Arbitrum链。该领域的主要参与者,如Robinhood、BlackRock、Ethena Labs、Securitize、Aave和Apechain,都在使用Arbitrum堆栈。

如果没有我们先进的技术堆栈,Arbitrum蓬勃发展的生态系统就不会存在。Arbitrum、Prysm、ZeroDev。这些不仅仅是产品名称,而是正在积极重塑以太坊可能性并推动其核心基础设施的工具。

最重要的是,我们获得了1.24亿美元的融资。我们已经展示了持续执行的能力,保障了数十亿美元的价值,支持了数千个项目,并且基础设施能够无缝处理数百万笔交易。

致Offchain求职者:

此职位无法在加利福尼亚州或科罗拉多州进行。

请注意,近期在Web3领域出现了越来越多的欺诈招聘活动。如果你想确认某人是否是Offchain员工或你收到的录用通知是否合法,请发送邮件至jobs@offchainlabs.com。

在Offchain,我们致力于为所有员工打造一个欢迎和支持的工作环境,无论他们的背景或身份如何。我们努力创造一个让每个人都感到被重视的环境。

查看英文原文

At Offchain, we aren’t just building products: we’re leading a movement.

As pioneers in blockchain scalability and security, we're at the forefront of transforming how the world interacts with decentralized applications. We're laying the foundation that will define the next generation of digital commerce, governance, and human interaction. This involves tackling real-world challenges that come with scaling blockchain technology, without compromising on its core principles: decentralization, security and transparency.

At the center of this vision is our people. Our team is made up of thinkers and doers that embrace new challenges and seek solutions that push existing boundaries. If you’re energized by solving unprecedented problems, and believe in the role that decentralized systems will play in creating a more equitable digital future, then we want to hear from you.

Why Offchain?

Offchain is setting the pace for the entire Ethereum ecosystem. We built the Arbitrum stack that powers Arbitrum One, the most widely adopted Ethereum scaling solution that exists today.

Arbitrum’s ecosystem is undergoing tremendous growth with hundreds of projects and dApps on Arbitrum One today. Over 100 different teams have used Offchain technology to build their own Arbitrum chains. Major players in the space, Robinhood, BlackRock, Ethena Labs, Securitize, Aave, and Apechain are all using the Arbitrum stack.

Arbitrum’s thriving ecosystem wouldn’t exist without our advanced technology stack. Arbitrum, Prysm, ZeroDev. These aren’t just product names. These are tools that are actively reshaping what's possible on Ethereum and advancing its core infrastructure.

To top it all off? We’re backed by $124 million in funding. We’ve demonstrated consistent execution with billions in secured value, thousands of supported projects, and infrastructure processing millions of transactions seamlessly.
Attention Offchain Job Seekers:

This role cannot be performed in California, or Colorado.

Please be advised that there has been a rise in fraudulent recruiter activities, particularly within the Web3 space. If you would like to confirm whether someone is an Offchain employee or the legitimacy of an offer you received, please email jobs@offchainlabs.com

At Offchain, we are committed to building a welcoming and supportive workplace for all employees, regardless of their background or identity. We strive to create an environment where everyone feels valued and has an equal opportunity to succeed and thrive. We encourage candidates from all walks of life to apply and join our team.

The Role

  • As a Senior Security Engineer at Offchain, you will emulate the real-world tactics, techniques, and procedures of sophisticated adversaries to surface vulnerabilities across our infrastructure and ecosystem tools.
  • You’ll run hands-on penetration tests, lead red team exercises, and work side-by-side with blue team partners to test, refine, and strengthen detection and response capabilities.
  • Your efforts will directly shape how Offchain designs, launches, protects, and achieves compliance for the infrastructure that powers millions of users and applications - including key standards such as SOC 2.

What you'll do:

  • Conduct comprehensive code audits across a variety of internal applications and infrastructure.
  • Conduct comprehensive penetration tests across cloud environments (AWS), infrastructure, and backend applications.
  • Collaborate with detection engineering, threat intelligence, and incident response groups to review security controls, uncover coverage gaps, and enhance overall detection quality.
  • Build, maintain, and evolve custom offensive tools, scripts, and automation frameworks to increase assessment speed.
  • Offer offensive security expertise during incident investigations, including log analysis and root cause reviews.
  • Keep up with evolving threats, vulnerabilities, and attack methods; share research internally and engage with the wider security community.
  • Own offensive security projects from start to finish, mentor junior team members, and cultivate a culture of ongoing learning and knowledge exchange.

What you'll need:

  • 5+ years of experience in offensive security, penetration testing, red teaming, or a closely related field.
  • Extensive experience with conducting code audits to identify and remediate security issues.
  • Experience with binary exploitation.
  • Mastery of AWS & specific attack techniques and configuration weaknesses.
  • Strong understanding of adversary tactics and frameworks like MITRE ATT&CK.
  • In-depth knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability categories.
  • Proficiency using offensive security tools such as Burp Suite, nuclei and similar frameworks.
  • Strong programming skills in Python, Go, or similar languages, with proven experience developing tools or automation.
  • Excellent written and verbal communication skills, with the ability to present complex technical details as clear, risk-focused recommendations.
  • A natural ability to think like an attacker - creative, determined, and skilled at assessing risk across complex systems.

Nice-to-haves

  • Web3 / blockchain security exposure: smart contract auditing, bug bounty hunting (e.g., Immunefi, Code4rena), or DeFi protocol review.
  • Familiarity with Ethereum L1 / L2 node architecture and security risks.
  • Experience in blockchain infrastructure penetration testing.

Perks:

  • Remote-first global workforce + NY office
  • Professional reimbursement program (facilitates industry conference attendance, certifications, and more)
  • Medical, dental & vision coverage (US + some other countries)
  • 401k retirement plan + company match (US only)
  • Wellness stipend
  • Home office set up / ergonomic equipment program
本页面信息整理自 Lever,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位