You will drive security outcomes by threat modeling software and infrastructure, writing exploits, and building AI-driven security tooling. Additionally, you will manage incident response, perform code reviews, and harden CI/CD pipelines and supply chains.
Outcomes You'll Drive
We find our vulnerabilities before anyone else does You hunt through code, infrastructure, and deployments with an attacker's mindset. The things you find get triaged, remediated, fixed.
Security that ships as code Your work produces pull requests, hardened configs, detection rules, and tests. Engineers see you as someone who makes their systems better, not someone who slows them down.
A hardened perimeter where it matters Key custody, secrets management, access control, CI/CD, and the software supply chain are locked down against the realistic threats to a system securing crypto-assets.
An AI-augmented security practice LLMs and coding agents multiply your reach across code review, fuzzing, triage, and log analysis. You know exactly where they help, where they lie, and how to build systems that leverage them to scale things up.
Calm, rehearsed incident response When something goes wrong there's a playbook, a clear owner, and a blameless postmortem that leaves the system stronger than before.
What You'll Do
Offense
Threat model and attack our software, infrastructure, and contracts. Write exploits against our own systems before adversaries do.
Build and run fuzzing, property-based, and adversarial test harnesses.
Run internal red-team exercises and coordinate external audits and bug bounty programs, triaging and validating what comes back.
Defense
Detection and monitoring: what does "compromised" look like, and how do we know within minutes rather than days?
Harden hosts, CI/CD, and the software supply chain. Audit dependencies and design reproducible builds and signed/attested releases.
Support incident response and post-incident reviews.
Engineering & Tooling
Review security-sensitive PRs across the codebase and pair with engineers on secure design.
Build AI-driven security tooling: agents for code review and dependency triage, LLM-assisted log analysis, automated first-pass audits of new contracts and integrations.
Write clear, actionable findings and advisories for internal teams, external signers, and partners.
What We're Looking For
Security is what you do for fun, not just for work. CTFs, bug bounties, side research, reading advisories at breakfast.
5+ years in software engineering and ****a meaningful portion of it in security. Red team, blue team, appsec, detection engineering, or security research.
Solid programming foundation. You read and write production code (Rust, Go, C, TypeScript, Python, or similar), and you understand systems, networking, and cryptography.
Hands-on offensive or defensive experience: exploit development, pentesting, incident response, detection engineering, or hardening production systems.
Pragmatism. You measure yourself in closed attack paths and shipped fixes. You know risk matrices exist, but you don't lead with them.
Fluency with AI tooling. You use LLMs and coding agents daily in security work, you've built something with them, and you have grounded opinions about their failure modes.
Strong written communication. Findings, advisories, and design reviews that people actually read and act on.
Comfort working remotely and autonomously across time zones.
Nice to Have
Expertise in Rust, our primary language.
Bitcoin protocol internals, or experience auditing smart contracts (Clarity, Solidity, or similar).
Threshold signatures, MPC, or applied cryptography.
Security of distributed systems and consensus protocols.
Cloud and infrastructure security.
Experience building AI agents for security workflows, or securing systems that integrate LLMs.
A public track record: CVEs, published research, notable CTF placings, or bug bounty history.
What We Offer
Competitive compensation including $160,000-$200,000 USD base salary.
Stacks (STX) tokens - STX is the native cryptocurrency of the Stacks network.
Comprehensive health coverage and free life and disability insurance.
Up to 16 weeks of paid parental leave to support you through one of life's biggest transitions.
Monthly stipends for your home office or co-working space of choice.
Annual learning and development stipend to keep growing your skills.
An open vacation policy, take the days you need when you need.
401(k) with a 3% match.
A high-ownership role shaping some of the most critical infrastructure in the Stacks ecosystem.
A fast-moving, focused team where strong engineering judgment is valued and where your work will ship quickly and visibly.
The chance to define engineering standards for one of the most ambitious Bitcoin L2 ecosystems, shaping how Bitcoin moves in and out of smart contracts.
A remote-first culture with flexibility, autonomy, and deep collaboration with product and engineering.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”