[Hiring] Application Security Engineer @Polygon Labs
Application Security Engineer @Polygon Labs
Software Development
Salary unspecified
Remote Location
Employment Type full-time
Posted 2d ago

[Hiring] Application Security Engineer @Polygon Labs

2d ago - Polygon Labs is hiring a remote Application Security Engineer. πŸ’Έ Salary: unspecified πŸ“Location: Worldwide

Role Description

Polygon's Application Security team sits at the intersection of every product we ship. With a growing engineering org, an active bug bounty program fielding 30+ open submissions at any given time, and products going live across smart contracts, backend services, and infrastructure simultaneously, the team needs more depth, not a gatekeeper, a builder. You will report directly to the Application Security Lead and work across every engineering team at every stage of development, from sprint planning to post-ship remediation. Your job is to make security scale faster than the attack surface grows.

Responsibilities

  • Own end-to-end security reviews across smart contracts (Solidity), backend services (Go, TypeScript, Python), and frontend surfaces, producing written findings at the quality level of a top external audit firm, published and used as the internal standard.
  • Build and ship an agentic security CI/CD pipeline: agent-driven review that runs autonomously against every PR and release candidate, reasons about changes in context, and gets smarter with each deployment.
  • Design and maintain specialised AI-powered code reviewers tuned to specific vulnerability classes and surfaces, Solidity-aware, protocol-aware, and calibrated to the actual patterns Polygon's products surface.
  • Triage and manage the bug bounty program: read incoming submissions daily, reproduce valid findings, separate signal from noise, assign severity, and route confirmed issues to engineering with enough context to fix them correctly, using custom AI workflows to maintain rigor at volume.
  • Follow through on remediation: review proposed fixes, close out resolved findings, and push back where a fix addresses symptoms rather than root cause.
  • Embed across engineering teams at all stages, sprint planning, design review, feature freeze, post-launch, as a working partner, not a sign-off function.
  • Lead the team's AI security practice by example: build custom prompt chains, Claude Code workflows, and Codex integrations tailored to specific security tasks, then demo and share them so the whole team's baseline rises.

Qualifications

  • Full-stack security fluency across multiple languages: you can drop into an unfamiliar codebase and produce a meaningful review within a day, Solidity, Go, TypeScript, and Python are the surfaces that matter most here.
  • Smart contract security as a core competency: production experience auditing or building secure Solidity, deep familiarity with EVM internals, common DeFi protocol patterns, and the historical record of smart contract exploits.
  • Proven AI workflow depth, not just tool usage: you have built custom prompt chains, CI integrations, and task-specific plugins (using tools like Claude Code and Codex) for security work specifically, and you can speak clearly about where AI accelerates and where human judgment is irreplaceable.
  • Experience making security decisions under real time pressure in a Web3 environment, where speed and rigor have to coexist.
  • A public portfolio that demonstrates your security thinking: audit reports, bug bounty writeups, research posts, or open-source tooling, something that shows what good looks like when you put your name on it.

Preferred Qualifications

  • Experience running or contributing to a structured bug bounty program (triage, researcher communication, severity calibration).
  • Direct exposure to payments protocols, stablecoin infrastructure, or regulated fintech environments.
  • Prior work building security tooling that other engineers actually use, not just internal scripts, but something with adoption.

Benefits

  • Remote first global workforce.
  • Industry leading Medical, Dental and Vision health insurance.
  • Company matching 401k with 3% match.
  • $1,500 Home Office Set Up Allowance (life-time max).
  • $200 Annual AI Allowance Program.
  • $75 Monthly internet or phone reimbursement.
  • Flexible Time Off.
  • Company issued laptop.
  • Egg freezing, mental health, and employee wellness benefits.
Before You Apply
️
worldwide Be aware of the location restriction for this remote position: Worldwide
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Application Security Engineer @Polygon Labs
Software Development
Salary unspecified
Remote Location
Employment Type full-time
Posted 2d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 160,000+ Remote Jobs
️
worldwide Be aware of the location restriction for this remote position: Worldwide
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 160,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 160,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later