Remote Offensive Security Engineer – Blockchain and DeFi Specialist

Halborn

United Kingdom Full-time in I.T. & Communications
    Share:
    • Job ID 2766390

    Job Description

    Join our innovative team at Halborn Inc, where we are on a mission to deliver top-notch security solutions and services for the most advanced technology firms, starting with the blockchain sector. Since our establishment in 2019, Halborn has emerged as a premier cybersecurity firm, dedicated to tackling the unique challenges posed by the cryptocurrency and fintech industries. Our expertise spans a wide range of issues, from breaches and social engineering to the theft of private keys and economic hacks. We proudly serve an exclusive clientele of blockchain companies and rapidly growing startups.

    Life at Halborn

    As a remote-first company with over 100 team members worldwide, we are continually expanding our elite roster of white-hat hackers, sales experts, security engineers, and DevSecOps specialists. Our culture promotes autonomy and flexibility, allowing you to set your own hours and pursue your passion within the dynamic cryptocurrency landscape.

    Diversity and Inclusion

    Halborn Inc is proud to be an Equal Opportunity Employer. We embrace diversity and do not discriminate based on race, religion, color, national origin, sexual orientation, gender identity, gender expression, transgender status, age, education, veteran status, disability, or any other legally protected characteristic. We are committed to fostering a diverse and inclusive environment for everyone on our expanding team.

    Please note that we cannot sponsor employment visas at this time, and recruitment agencies or consultants are not permitted to submit resumes through our site.

    Your Role

    • Lead realistic adversary simulations from initiation to comprehensive reporting.
    • Conduct thorough testing across systems, applications, networks, and processes.
    • Explore and research advanced offensive security methodologies.
    • Design and create tools and exploits.
    • Effectively communicate potential risks and suggested remediations in written and spoken formats.
    • Collaborate independently or as part of a team on specialized projects requiring unique expertise.
    • Uphold ethical standards in alignment with company and professional guidelines.

    Your Expertise

    • A strong enthusiasm for the blockchain sector.
    • Minimum of 3 years’ experience in application development using Golang and C++ (both are essential), with a preference for blockchain or smart contract development experience.
    • At least 2 years of hands-on offensive security experience.
    • Familiarity with WASM/BPF is an advantage.
    • Solid understanding of system and network administration.
    • Proficient with popular penetration testing tools (e.g., BurpSuite, Metasploit).
    • Experience in reverse engineering and fuzzing is a plus.
    • Solid scripting language proficiency.
    • Well-versed in key server and workstation operating systems.
    • Thorough knowledge of modern web application languages and frameworks.
    • Deep understanding of blockchain technology and smart contract frameworks.
    • Comprehensive knowledge of Golang-based smart contract runtimes.
    • Critical thinking skills to identify both technical and non-technical risks.
    • Adept at writing technical reports and explaining complex concepts to non-technical audiences.
    • Background in security research, inclusive of vulnerability discovery and exploit development.

    Desirable Qualifications

    • Experience with Bitcoin and its derivatives (e.g., Bitcoin Cash).
    • Familiarity with Ethereum clients.
    • Knowledge of Cosmos SDK and a solid understanding of Tendermint.
    • Experience with Inter-Blockchain Communication (IBC).
    • Background in working with consensus protocols.
    • Basic understanding of cryptographic principles such as public/private keys, hash functions, and Merkle trees.
    • Relevant security certifications (such as OSCP, OSCE, GPEN, GWAPT, LPT, CISSP) are a plus but not mandatory.

    Other jobs you may like

    10x your chance to get hired

    Land a job without sending dozens of applications!

     

    Let employers find you

     

    Happy Remote Worker