Aptos
Information Security Engineer, Product
Remote Global (US, EU) (Remote)midAdded 1 month ago
About this role
Aptos Labs is seeking a Product Security Engineer to protect its blockchain infrastructure and products. You'll conduct security assessments, design protective tools, and lead Web3 security initiatives while working remotely across global teams.
What you'll do
- Perform security design reviews, code audits, and penetration testing on blockchain systems
- Create security tools and develop mitigation strategies for vulnerability prevention
- Establish secure operational practices and guide engineering teams on security
- Manage and triage bug bounty program submissions
- Research and assess novel and recurring security threats
What they're looking for
- Vulnerability research and exploitation (3+ years)
- Native development languages (Rust, C, or similar)
- Automated security tools (fuzzing, static analysis)
- Smart contract security and formal verification
- Virtual machine and runtime environment security (MoveVM, EVM, WASM, LLVM)
- Security code auditing and threat modeling
- Move programming language (preferred)
Benefits
- 100% medical, dental, and vision insurance coverage for employees and dependents (US)
- Choice of equipment
- Flexible vacation, 11 holidays, and floating company days
- Competitive salary and protocol token grants
- 401k matching (US employees)
- In-person and digital team events
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Aptos
Aptos develops blockchain infrastructure and products in the Web3 space. The company is hiring product security engineers and other technical roles focused on protecting its systems and advancing security initiatives.
- Website
- aptoslabs.com
Likely interview questions
- Walk us through your experience with vulnerability research and exploitation. Can you describe a specific vulnerability you discovered and how you responsibly disclosed it?
- Tell us about your experience with native development languages like Rust or C. How have you applied security knowledge when reviewing or auditing code in these languages?