Senior Security Engineer @Mysten Labs
All Others
Salary usd 165,000 - 2..
Remote Location
Employment Type full-time
Posted 2wks ago

[Hiring] Senior Security Engineer @Mysten Labs

2wks ago - Mysten Labs is hiring a remote Senior Security Engineer. πŸ’Έ Salary: usd 165,000 - 225,000 per year πŸ“Location: USA, Canada

Role Description

Mysten Labs is looking for a Senior Security Engineer to help protect the Sui ecosystem. You’ll uncover vulnerabilities, build monitoring tools, and assess economic risk across DeFi protocols. Working closely with external protocol teams and Mysten’s own DeFi products, including DeepBook, you’ll help address risks before they become incidents and strengthen security across the ecosystem.

  • Build and run continuous monitoring of the Sui DeFi ecosystem for security and economic risk:
    • oracle issues
    • misconfigurations/bad economic parameters
    • solvency and bad-debt exposure under price shocks
    • liquidation capacity against on-chain liquidity depth
    • accounting-versus-positions reconciliation
    • invariants
  • Extend security team tooling, both precise static analysis tooling and proprietary agent skills.
  • Measure and drive compliance with the DeFi security recommendations across supported protocols:
    • run the recurring compliance cycle
    • fill the protocol report card
    • validate security claims (audits, custody, upgrade governance, oracle dependencies) against on-chain reality
    • track remediation commitments
    • escalate when a protocol regresses or fails to disclose an incident
    • partner with the ecosystem and finance owners of the process
  • Hunt for critical vulnerabilities in the highest-TVL Sui protocols and get them fixed before they are exploited:
    • full-package audits
    • variant analysis across forks
    • pre-execution review of multisig upgrade payloads
    • forensics after incidents anywhere in the ecosystem
  • Be the security team's point of contact for external DeFi teams and for Mysten's own DeFi products such as DeepBook:
    • due diligence
    • incident coordination
    • post-mortems that feed back into the recommendations and the monitors
  • Write it down: findings, reports, and runbooks that a protocol engineer can act on and a non-technical stakeholder can understand, with every claim traceable to bytecode, chain state, or data.

Qualifications

  • Bachelor's degree in Computer Science, Computer Engineering, a relevant technical field, or equivalent practical experience.
  • 3+ years of hands-on experience in security engineering, smart contract security, or DeFi risk engineering, with a track record of building tools that ran in production and of finding real vulnerabilities (audit findings, bug bounty reports, published research, or incident work).
  • Strong understanding of DeFi mechanics and their failure modes:
    • lending markets (LTV, liquidation thresholds and bonuses, close factors, bad debt)
    • AMMs and concentrated liquidity
    • perpetuals
    • liquid staking
    • oracles (staleness, confidence, TWAP, multi-source aggregation)
    • flash loans
    • MEV
  • Proficiency in TypeScript and Python, and comfort with Rust.
  • Ability to write SQL over large datasets and to work with blockchain indexers and data warehouses.
  • Experience reading smart contract code at source or the bytecode or disassembly level, or evident ability to learn it quickly.
  • Rigor: you verify claims against bytecode and chain state, build known-clean checks into your tools, and say what you did not verify.
  • Strong written and verbal communication, including the ability to influence external teams you have no formal authority over.
  • Interest in the web3 space is required.

Preferred Qualifications

  • Sui and Move experience: the object and capability model, package upgrades and version gates, programmable transaction blocks, the Sui GraphQL and gRPC APIs.
  • Knowledge of the recent DeFi exploit history on Sui and other chains: named incidents, oracle compromises, and the defect classes behind them.
  • Experience building analysis or monitoring tools with LLM agents (Claude Code skills or comparable), and a clear sense of where models help and where deterministic tooling must do the work.
  • Static or dynamic program analysis experience: taint analysis, call graphs, symbolic execution, fuzzing, formal verification.
  • Quantitative or economic modeling experience: stress testing, liquidity modeling, risk parameters for lending markets.
  • Publications, conference talks, CVEs, or bug bounty rankings.
Before You Apply
️
remote Be aware of the location restriction for this remote position: USA, Canada
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Engineer @Mysten Labs
All Others
Salary usd 165,000 - 2..
Remote Location
Employment Type full-time
Posted 2wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: USA, Canada
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,072+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later