远程工作雷达

信息安全工程师,产品

Information Security Engineer, Product

开发工程限定地区(需当地身份)
公司Aptos
薪资未公开
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

Aptos 是一个以人为本的区块链,致力于以安全且可扩展的方式帮助数十亿人实现去中心化资产的普遍公平访问。

由一些最初研究、设计和构建 Diem 区块链的创建者和维护者创立,我们已为此目标投入数年时间。我们认为我们开发的开源 Diem 技术是构建一个安全且可扩展的 web3 世界的重要基础,在这个世界上,每个人都能以更低的费用和更少的中介获得更加公平的成长和获取金融资产的机会。

Aptos(Ohlone 语中“人民”的意思)体现了我们的使命和价值观。

职位描述
在 Aptos Labs,我们正在引领 web3 的未来,需要一位充满热情的产品安全工程师来帮助保护我们的核心技术。在这个职位上,你将处于保护 Aptos 核心基础设施和 Aptos Labs 产品的最前沿。你的主动态度将帮助我们识别和缓解新兴威胁,确保我们的系统保持稳健和可信。你将与我们的开发人员紧密合作,影响安全最佳实践,并领导塑造 web3 安全未来的关键项目。

职责

  • 通过设计评审、代码审计和渗透测试分析和评估新型和重复出现的安全问题。
  • 设计和构建安全工具,开发针对漏洞预防和检测的缓解方案、框架和加固策略。
  • 审查和制定安全的运维实践,并为工程师提供安全指导。
  • 处理和分类来自漏洞赏金计划的报告。

最低要求

  • 计算机科学或相关技术领域的学士或硕士学历,或同等经验。
  • 3 年以上漏洞研究和利用的经验。
  • 具有原生开发实践和常见漏洞模式的经验(例如 Rust、C 等)。
  • 具有自动化安全分析工具和框架的经验(如模糊测试、静态分析等)。

优先考虑

  • 对安全社区的贡献(公开研究、博客、相关会议演讲等)。
  • 具有虚拟机或复杂运行时环境的经验,如 MoveVM(额外加分)、EVM、WASM 或基于 LLVM 的运行时,包括其安全模型、沙箱和执行隔离。
  • 熟悉智能合约编程语言(Move 为额外加分),安全工具和框架。
查看英文原文

Aptos is a people-first blockchain on a mission to help billions of people achieve universal and fair access to decentralized assets in a safe and scalable way.

Founded by some of the original creators and maintainers that researched, designed, and built the Diem blockchain to serve this purpose, we have dedicated several years toward this mission. We believe the open-source Diem technology we have developed is an important foundation of a safe and scalable web3 world where everyone has more equitable opportunities to grow and access financial assets with lower fees and fewer intermediaries.

Aptos (Ohlone for "The People") encompasses our mission and ethos for why we build.

About the Role
At Aptos Labs we’re pioneering the future of web3 and need a passionate Product Security Engineer to help secure our core technologies. In this role, you’ll be at the forefront of safeguarding our Aptos core infrastructure and Aptos Labs products. Your proactive approach will help us identify and mitigate emerging threats, ensuring our systems remain resilient and trustworthy. You will work closely with our developers, influence security best practices, and lead initiatives that shape the future of web3 security.
Responsibilities

  • Analyze and assess novel and recurring security issues via design reviews, code audits, and penetration tests.
  • Design and build security tools, and develop mitigations, frameworks, and hardening strategies tailored for vulnerability prevention and detection.
  • Review and develop secure operational practices, and provide security guidance for engineers.
  • Respond to and triage reports from bug bounty programs.

Minimum Qualifications

  • B.S. or M.S. in Computer Science, a related technical field, or equivalent experience.
  • 3+ years of experience in vulnerability research and exploitation.
  • Experience with native development practices and common vulnerability patterns (e.g., Rust, C, etc.)
  • Experience with automated security analysis tooling and frameworks (fuzzing, static analysis, etc.)

Preferred Qualifications

  • Contributions to the security community (public research, blogging, talks in relevant conferences, etc.)
  • Experience with virtual machines or complex runtime environments, such as MoveVM (extra bonus), EVM, WASM, or LLVM-based runtimes, including their security models, sandboxing, and execution isolation.
  • Familiarity with smart contract programming languages (extra bonus for Move), security tools, and frameworks, including formal verification.

Our Benefits

  • 100% insurance premium coverage for medical, dental, and vision for you and your dependents (US Employees)
  • Equipment of your choice
  • Flexible vacation time, 11 holidays, and floating company days off
  • Competitive Salary
  • Protocol Token Grants
  • 401k matching (US Employees)
  • Fun and inclusive in-person and digital events

Aptos is committed to diversity in the workplace, and we’re proud to be an Equal Opportunity Employer. We do not hire on the basis of race, color, religion, creed, gender, national origin, citizenship, age, disability, veteran status, marital status, pregnancy, parental status, sex, gender expression or identity, sexual orientation, or any other basis protected by local, state or federal law. All employment is decided based on qualifications, merit, and business need.

We are committed to providing a safe and secure hiring process for all applicants. Unfortunately, there are individuals who may attempt to impersonate Aptos or our employees for fraudulent purposes.
To protect yourself, please be aware of the following:

  • We will never ask you for payment of any kind during the application or onboarding process, including fees for background checks, training, or equipment.
  • We will always communicate with you using our official company email domain.
  • We will never request your personal financial information, such as your social security number or bank account details, during the initial application stages or via email or a video/voice call when onboarding.

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位