Web3 Security Engineer Job Description Template

The web3 security engineer protects a protocol and the organization around it, covering contract security, key management, operational security and incident response. The threat model is unusual: adversaries are anonymous, well funded and can act instantly, and there is no chargeback. The role reaches beyond code into how the team manages keys, deployments and privileged access.

Typical Duties and Responsibilities

  • Review smart contracts and protocol changes for security issues
  • Design and enforce key management and multisig procedures
  • Build on chain monitoring and alerting for anomalous activity
  • Run incident response for exploits, including pause and recovery procedures
  • Manage bug bounty programs and triage submissions
  • Assess third party protocol and bridge integration risk
  • Secure deployment pipelines and privileged operations
  • Conduct threat modeling for new features before implementation
  • Train engineers on secure development practice
  • Maintain the security incident runbook and rehearse it

Education

  • Bachelor’s degree in computer science, information security or a related field

Required Skills and Experience

  • 3+ years in security with meaningful blockchain experience
  • Deep knowledge of smart contract vulnerability classes and past exploits
  • Experience with key management, multisig and hardware security
  • Ability to run an incident where funds are actively at risk
  • Understanding of MEV, front running and transaction ordering risk
  • Experience with on chain monitoring and forensic analysis
  • Clear communication under pressure
  • Familiarity with audit processes from either side

Preferred Qualifications

  • Audit or bug bounty track record
  • Experience with formal verification tooling
Contact us

Recruit with Nexus IT Group