Senior Backend Engineer, ZeroDev Wallet
At Offchain, we aren’t just building products: we’re leading a movement.
As pioneers in blockchain scalability and security, we're at the forefront of transforming how the world interacts with decentralized applications. We're laying the foundation that will define the next generation of digital commerce, governance, and human interaction. This involves tackling real-world challenges that come with scaling blockchain technology, without compromising on its core principles: decentralization, security and transparency.
At the center of this vision is our people. Our team is made up of thinkers and doers that embrace new challenges and seek solutions that push existing boundaries. If you’re energized by solving unprecedented problems, and believe in the role that decentralized systems will play in creating a more equitable digital future, then we want to hear from you.
Why Offchain?
Offchain is setting the pace for the entire Ethereum ecosystem. We built the Arbitrum stack that powers Arbitrum One, the most widely adopted Ethereum scaling solution that exists today.
Arbitrum’s ecosystem is undergoing tremendous growth with hundreds of projects and dApps on Arbitrum One today. Over 100 different teams have used Offchain technology to build their own Arbitrum chains. Major players in the space, Robinhood, BlackRock, Ethena Labs, Securitize, Aave, and Apechain are all using the Arbitrum stack.
Arbitrum’s thriving ecosystem wouldn’t exist without our advanced technology stack. Arbitrum, Prysm, ZeroDev. These aren’t just product names. These are tools that are actively reshaping what's possible on Ethereum and advancing its core infrastructure.
To top it all off? We’re backed by $124 million in funding. We’ve demonstrated consistent execution with billions in secured value, thousands of supported projects, and infrastructure processing millions of transactions seamlessly.
Attention Offchain Job Seekers:
This role cannot be performed in California, or Colorado.
Please be advised that there has been a rise in fraudulent recruiter activities, particularly within the Web3 space. If you would like to confirm whether someone is an Offchain employee or the legitimacy of an offer you received, please email jobs@offchainlabs.com
At Offchain, we are committed to building a welcoming and supportive workplace for all employees, regardless of their background or identity. We strive to create an environment where everyone feels valued and has an equal opportunity to succeed and thrive. We encourage candidates from all walks of life to apply and join our team.
The Role:
The Developer Platform team builds KMS, the key-management and signing service behind ZeroDev's embedded, non-custodial wallets. These are smart-account / account-abstraction wallets that developers integrate directly into their applications. End users retain control of their keys, while KMS security orchestrates wallet creation, authentication and signing on top of a third-party signing provider.
You'll own production Go services and the cryptographic recovery and trust-model systems around them, working in a small, high-ownership team. This is security-critical infrastructure with a high review bar and external security audits. You should already be comfortable with applied-cryptography fundamentals such as public-key cryptography, signatures and key management. You don’t need to be a cryptographer or have prior experience with areas like MPC or TEEs, but you should be able to reason about cryptographic systems and their security implications.
As the platform evolves, you'll also help expand it beyond interactive consumer wallets toward programmatic and automated signing, and programmable transaction policies.
What you'll work on:
- Backend services: build and operate Go services that power wallet creation, authentication, and signing at scale
- Key recovery and the committee trust model: distributed key generation and secret sharing that keep the service non-custodial, with recovery authority split across independent committees so no single party holds a user's key
- Trusted Execution Environments: reconstructing and operating on key material under hardware isolation and remote attestation
- Authentication and signing-provider integration: the user-facing auth methods that gate signing (passkeys / WebAuthn, OAuth, OTP, sessions, 2FA), and integrating with a third-party signing provider (authorization and policy flows, scoped credentials, quorum / consensus approvals)
- Security review and hardening: writing design docs and decision records, working directly with external security auditors, and turning a high review bar into shipped code
- Production operations on Kubernetes: observability and alerting, secrets and certificate management, on-call, and the compliance controls the domain requires (sanctions screening, PII-safe handling)
Who you are:
- Strong backend engineer who has shipped and operated production services in Go (or an adjacent systems language and is eager to go deep in Go)
- Security-first by default: You naturally think about threat models, blast radius and key custody, and write code that holds up to security-critical review
- Comfortable with applied-cryptography: You understand fundamentals such as public-key cryptography, signatures and key management, and can reason about how they apply to production systems. You don't need to be a cryptographer!
- Solid on distributed systems and API design: You’re comfortable reasoning about idempotency, failure modes and clean service boundaries
- Operationally experienced: You’ve worked with production infrastructure and are comfortable with Kubernetes, observability and incident response
- Clear written communicator: You can explain technical decisions through design docs and decision records, and work effectively in a collaborative, review-heavy environment.
Nice-to-have
You don't need to have worked with all of these. Experience in one or more would be valuable.
- Trusted Execution Environments (TEE) such as AWS Nitro Enclaves, Intel SGX / TDX or similar
- Threshold cryptography / MPC, including DKG, FROST or other threshold signatures, verifiable secret sharing or resharing
- Account abstraction, including ERC-4337, EIP-7702, smart accounts or embedded / non-custodial wallets
- Custody or signing infrastructure such as Turnkey or Fireblocks, either as an integrator or builder
- HSMs, YubiKey / PIV or secure-element integrations
- Third-party security audits and driving remediation through to completion
- Authentication technologies such as WebAuthn / passkeys and OAuth / OIDC, or experience with the Go crypto ecosystem
Perks:
- Remote-first global workforce + NY office
- Professional reimbursement program (facilitates industry conference attendance, certifications, and more)
- Medical, dental & vision coverage (US + some other countries)
- 401k retirement plan + company match (US only)
- Wellness stipend
- Home office set up / ergonomic equipment program