Senior Application Security Engineer
Job Description
- WebAPI Web3 Smart ContractDApp
- SDL / DevSecOps SDL/SAST/DAST CI/CD
- /
- 2 OWASP Top 10 Web/API
- Web3 / Web3 DApp Solidity DApp/
- Burp SuiteSlitherMythrilCheckmarx Python/Go
Key Responsibilities:
- Code Audit & Penetration Testing: Conduct security code reviews and penetration testing for Web applications, APIs, and Web3 infrastructure (Smart Contracts, DApps, Wallets).
- SDL & DevSecOps: Drive the Security Development Lifecycle (SDL) by integrating SAST/DAST automation tools into CI/CD pipelines.
- Incident Response: Handle application-level security incidents, conduct root-cause analysis, and track vulnerability remediation.
- Security Architecture Review: Participate in product design reviews to identify architectural/logical flaws and provide security hardening solutions.
Requirements:
- Core AppSec Skills: 2+ years of experience in AppSec or PenTesting; solid knowledge of OWASP Top 10 and web/API vulnerability exploitation.
- Web3 / Blockchain Experience: Familiar with Web3 threat vectors (e.g., Reentrancy, Flash Loans, Signature Forgery, DApp attacks). Hands-on experience in Solidity auditing or DApp/Wallet testing is a strong plus.
- Tooling & Automation: Proficient with security tools (e.g., Burp Suite, Slither, Mythril, Checkmarx) and capable of scripting in Python or Go for automation.
- Communication: Excellent cross-functional communication skills to effectively drive remediation with development teams.
More Info
Key Skills
Web API vulnerability exploitation
Mythril
Solidity auditing
Slither
DApp Wallet testing

