
Application Security Engineer at RootstockLabs Ltd.
Empowering developers to build on Bitcoin, growing Rootstock and decentralized tech.
Secures Bitcoin-backed DeFi infrastructure; reviews source code, smart contracts, and protocol changes; threat modeling and architecture reviews with development teams; owns bug bounty triage/validation and coordinates external audits through remediation; builds security automation including AI-assisted code review, scanning, findings triage, CI security checks, monitoring alerts, and hardening; researches EVM, bridge, and p2p attack techniques and supports application-layer incident investigations; requires 3+ years in application/security engineering, secure code review in Java plus one of TypeScript/JavaScript, Python, Go, or Rust, blockchain security experience in Solidity/EVM or protocol/node security, security automation experience, and fluent English; bonus: bug bounty/disclosure programs, network or consensus attack mitigation, offensive security background, public security research, C/C++, fuzzing
Remote within UTC-3 to UTC+2 time zones; effectively Europe through Argentina-aligned LATAM time zones






