Application Security Engineer
RootstockLabs
ABOUT THE ROLEAs an Application Security Engineer at RootstockLabs, you will help secure our Bitcoin-secured DeFi infrastructure by reviewing code, smart contracts, and protocol changes, and by building the security automation that keeps our development lifecycle safe. You will work closely with development teams on threat modeling and architecture reviews, manage our bug bounty program end to end, and coordinate external security audits with third-party auditors. You will also research attack techniques relevant to our ecosystem (EVM, bridges, p2p) and translate them into concrete defenses, and support incident investigations when application-layer issues arise. KEY RESPONSIBILITIESPerform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projectsParticipate in design and architecture reviews; threat-model new products and features with development teamsTriage and validate bug bounty reports; assess severity and coordinate remediation with engineeringCollaborate on external security audits: scope engagements and work with third-party auditors through to the resolution of findingsBuild and operate security automation, including AI-assisted code review, scanning, and findings-triage pipelinesResearch attack techniques relevant to the ecosystem (EVM, bridges, p2p) and turn findings into concrete defenses: monitoring alerts, CI security checks, and hardening changesSupport incident investigations when application-layer issues arise WHAT YOU BRING3+ years of experience in Application Security or Security EngineeringSolid grasp of common vulnerability classes (OWASP Top 10) and secure code review in Java plus at least one of TypeScript/JavaScript, Python, Go, or RustHands-on experience with blockchain security: smart contract auditing (Solidity/EVM) or protocol/node-level securityExperience building and operating security automation, AI-assisted workflows (LLM-based triage, code review, or scanning), SAST/DAST, dependency and secret scanning, and CI/CD security gatesFluent English NICE TO HAVEExperience in bug bounty triage or vulnerability disclosure programsExperience mitigating network-level attacks (p2p, eclipse, DoS) or analyzing consensus-level attack scenariosOffensive security background (pentesting, red team, CTFs, exploit development)Public security research: CVEs, bug bounty track record, audit reports, conference talksKnowledge of C/C++ (for node/client codebases)Experience with fuzzing (smart contracts or native code)
ROOTIES BENEFITSAt RootstockLabs, we don’t just offer a job, we offer a community. Here’s what you can expect when you join us:Competitive compensation package and unique benefits designed to support your growth and well-being.100% Remote Work working within a Central European to Argentinian time-zone window (UTC-3 to UTC+2, with about an hour's flexibility either side), and with access to global coworking spaces.Work-Life Balance: Paid vacation and sick leave daysContinuous Learning: Access to training programs, language courses, and learning sponsorship annually.Unique Projects: Work with cutting-edge blockchain technology in a global, diverse team.
ABOUT ROOTSTOCKLABS RootstockLabs builds Bitcoin-secured DeFi infrastructure that enables companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale.Market: Companies, financial institutions, and their customersProduct: Bitcoin-secured DeFi financial productsDistribution: B2B2C through regulated financial institutionsWe operate at the intersection of crypto infrastructure and institutional finance, enabling compliant, scalable access to decentralized financial services powered by Bitcoin.
