CertiK

Senior Security Engineer

CertiK$130K — $160K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Master's degree in Computer Science, Software Engineering, Security Informatics, or related field.
  • Expertise in structured methodologies for threat modeling and architectural risk assessment (e.g., STRIDE/DREAD).
  • Advanced knowledge of Secure Software Development Lifecycle (SSDLC) and vulnerability management.
  • Strong proficiency in conducting security assessments across various system architectures and configurations.
  • Familiarity with cloud platforms (AWS, Azure, GCP) and CI/CD processes; proficient in Java and Python.

Responsibilities

  • Lead the development of enterprise-grade security solutions for internal networks and applications.
  • Define and implement organization-wide security policies and oversee vulnerability management processes.
  • Manage real-time threat detection operations and conduct forensic investigations for security incidents.
  • Execute thorough security assessments for internal and third-party systems, focusing on infrastructure and application hardening.
  • Promote secure development practices through advanced static and dynamic vulnerability analysis.
  • Perform threat modeling and risk analysis for critical systems to identify potential attack vectors.
  • Design and maintain internal security tools to enhance detection and response capabilities.

Benefits

  • Medical, vision, and dental insurance.
  • 401(k) plan with company matching.
  • Life and accidental death and dismemberment insurance.
  • Health Savings Account (HSA) options.
  • Flexible paid time off and holidays.
Full Job Description
About the Role
The primary responsibility of this role is for CertiK's security-related services. Intersecting cybersecurity and blockchain, CertiK's security offerings include security consulting, security reviews, security auditing of smart contracts and blockchains, verification of smart contracts, penetration testing, and more. We are looking to hire someone with a passion for application security and penetration testing. This is a fun and challenging full-time position. If you are excited about hacking, threat modeling, scanning, auditing, designing, and enhancing the security of applications across the board then you will thrive in this role. While you work with clients, we will also provide you with plenty of opportunities to get involved with research and development efforts to help us raise the standards of blockchain security.

Responsibilities

  • Lead design/deployment of enterprise-grade security solutions to safeguard internal networks/applications/infrastructure, ensuring confidentiality/integrity/availability of mission-critical systems & data
  • Define/enforce organization-wide security policies/standards; own end-to-end vulnerability management lifecycle & lead cross-functional incident response with engineering/IT/compliance teams
  • Oversee real-time threat detection/response operations; conduct forensic investigations & drive root cause analysis for high-impact security incidents to inform long-term defense strategies
  • Manage/execute comprehensive security assessments across internal/third-party systems, including architecture reviews/endpoint security evaluations/infrastructure hardening initiatives
  • Guide secure development practices by applying advanced static/dynamic analysis to identify vulnerabilities & deliver remediation guidance to engineering teams
  • Conduct threat modeling/risk analysis for high-value systems to proactively identify/mitigate attack vectors & influence system/product architecture
  • Architect/maintain internal security tooling to expand detection coverage, streamline response workflows & enhance operational visibility


Requirements

  • Master's degree in Computer Science, Software Engineering, Security Informatics, or related field.
  • Expertise in threat modeling/architectural risk assessment using structured methodologies (e.g., STRIDE/DREAD)
  • Advanced knowledge of SSDLC, including static/dynamic analysis/QA practices & end-to-end vulnerability lifecycle management (tracking/remediation coordination/verification)
  • Strong ability to conduct comprehensive security assessments across network infrastructure/application architecture/system configurations
  • Familiarity with cloud environments (AWS/Azure/GCP) & CI/CD deployment workflows; Proficiency in Java/Python with applied skills in secure coding/debugging/symbolic execution & internal tooling/automation scripting


Target annual salary compensation for this role performed is $130,000 to $160,000. The exact compensation at which this job is filled will be determined by the skills and experience of qualified candidates.

CertiK is proud to offer medical, vision, and dental insurance, 401(k) plan with company matching, life and accidental death and dismemberment insurance, HSA (with high deductible plan), FSA, and other benefits to all full-time employees, along with flexible paid time off and holidays. CertiK also offers a variable commission program for business development sales roles.

About CertiK

CertiK is a blockchain security company that provides auditing and verification services for smart contracts and blockchain protocols. The company's platform uses formal verification methods to ensure the correctness and security of blockchain applications. CertiK was founded in 2018 by computer science professors from Yale University and Columbia University and is headquartered in New York City.
Learn more about CertiK
Size
50 employees
Industry
Founded
2018

Similar Jobs

More Jobs at CertiK

  • CertiK
    Senior Data Analyst
    $110K — $125K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Senior Security Engineer jobs: