S

Senior Security Engineer

stacks labs • United State
Remote
Apply Now
AI Summary

Fully remote Security Engineer role at Stacks Labs focused on building secure systems for the sBTC signer network, Stacks node, and smart contracts. Responsibilities include threat modeling, offensive security testing, hardening infrastructure, and developing AI-augmented security tooling. Requires 5+ years of software engineering experience with a significant portion in security, strong programming skills, and fluency with AI tooling.

Key Highlights
Work directly with the CTO to secure critical crypto-asset infrastructure including the sBTC signer network and Stacks node.
Develop and deploy AI-augmented security practices using LLMs and coding agents for code review, fuzzing, and log analysis.
Operate autonomously in a fully remote, globally distributed environment with a high-ownership mindset.
Key Responsibilities
Threat model and attack software, infrastructure, and contracts to identify vulnerabilities before adversaries do.
Build and run fuzzing, property-based, and adversarial test harnesses.
Run internal red-team exercises and coordinate external audits and bug bounty programs.
Implement detection and monitoring systems to identify compromises within minutes.
Harden hosts, CI/CD pipelines, and the software supply chain, including auditing dependencies and designing reproducible builds.
Support incident response and post-incident reviews.
Review security-sensitive pull requests and pair with engineers on secure design.
Build AI-driven security tooling for code review, dependency triage, and log analysis.
Write clear, actionable findings and advisories for internal teams and external partners.
Technical Skills Required
Security Engineering Programming AI Tooling
Benefits & Perks
Competitive compensation including $160,000-$200,000 USD base salary
Stacks (STX) tokens
Comprehensive health coverage and free life and disability insurance
Up to 16 weeks of paid parental leave
Monthly stipends for home office or co-working space
Annual learning and development stipend
Open vacation policy
401(k) with a 3% match
Nice to Have
Expertise in Rust
Bitcoin protocol internals or experience auditing smart contracts (Clarity, Solidity)
Threshold signatures, MPC, or applied cryptography
Security of distributed systems and consensus protocols
Cloud and infrastructure security
Experience building AI agents for security workflows
Public track record such as CVEs, published research, or notable CTF placings

Job Description


As a Security Engineer at Stacks Labs, you'll work with the CTO to help building secure systems, including the sBTC signer network, the Stacks node, our smart contracts, and the infrastructure and release pipeline that ship them.


You'll operate autonomously in a fully remote role, embedded with a globally distributed engineering team. This is a hands-on role for someone who would rather find and fix the bug instead of writing a slide about it.


Outcomes You'll Drive
  • We find our vulnerabilities before anyone else does
  • You hunt through code, infrastructure, and deployments with an attacker's mindset. The things you find get triaged, remediated, fixed.
  • Security that ships as code
  • Your work produces pull requests, hardened configs, detection rules, and tests. Engineers see you as someone who makes their systems better, not someone who slows them down.
  • A hardened perimeter where it matters
  • Key custody, secrets management, access control, CI/CD, and the software supply chain are locked down against the realistic threats to a system securing crypto-assets.
  • An AI-augmented security practice
  • LLMs and coding agents multiply your reach across code review, fuzzing, triage, and log analysis. You know exactly where they help, where they lie, and how to build systems that leverage them to scale things up.
  • Calm, rehearsed incident response
  • When something goes wrong there's a playbook, a clear owner, and a blameless postmortem that leaves the system stronger than before.


What You'll DoOffense
  • Threat model and attack our software, infrastructure, and contracts. Write exploits against our own systems before adversaries do.
  • Build and run fuzzing, property-based, and adversarial test harnesses.
  • Run internal red-team exercises and coordinate external audits and bug bounty programs, triaging and validating what comes back.
Defense
  • Detection and monitoring: what does "compromised" look like, and how do we know within minutes rather than days?
  • Harden hosts, CI/CD, and the software supply chain. Audit dependencies and design reproducible builds and signed/attested releases.
  • Support incident response and post-incident reviews.
Engineering & Tooling
  • Review security-sensitive PRs across the codebase and pair with engineers on secure design.
  • Build AI-driven security tooling: agents for code review and dependency triage, LLM-assisted log analysis, automated first-pass audits of new contracts and integrations.
  • Write clear, actionable findings and advisories for internal teams, external signers, and partners.


What We're Looking For
  • Security is what you do for fun, not just for work. CTFs, bug bounties, side research, reading advisories at breakfast.
  • 5+ years in software engineering and ****a meaningful portion of it in security. Red team, blue team, appsec, detection engineering, or security research.
  • Solid programming foundation. You read and write production code (Rust, Go, C, TypeScript, Python, or similar), and you understand systems, networking, and cryptography.
  • Hands-on offensive or defensive experience: exploit development, pentesting, incident response, detection engineering, or hardening production systems.
  • Pragmatism. You measure yourself in closed attack paths and shipped fixes. You know risk matrices exist, but you don't lead with them.
  • Fluency with AI tooling. You use LLMs and coding agents daily in security work, you've built something with them, and you have grounded opinions about their failure modes.
  • Strong written communication. Findings, advisories, and design reviews that people actually read and act on.
  • Comfort working remotely and autonomously across time zones.


Nice to Have
  • Expertise in Rust, our primary language.
  • Bitcoin protocol internals, or experience auditing smart contracts (Clarity, Solidity, or similar).
  • Threshold signatures, MPC, or applied cryptography.
  • Security of distributed systems and consensus protocols.
  • Cloud and infrastructure security.
  • Experience building AI agents for security workflows, or securing systems that integrate LLMs.
  • A public track record: CVEs, published research, notable CTF placings, or bug bounty history.


What We Offer
  • Competitive compensation including $160,000-$200,000 USD base salary.
  • Stacks (STX) tokens - STX is the native cryptocurrency of the Stacks network.
  • Comprehensive health coverage and free life and disability insurance.
  • Up to 16 weeks of paid parental leave to support you through one of life's biggest transitions.
  • Monthly stipends for your home office or co-working space of choice.
  • Annual learning and development stipend to keep growing your skills.
  • An open vacation policy, take the days you need when you need.
  • 401(k) with a 3% match.
  • A high-ownership role shaping some of the most critical infrastructure in the Stacks ecosystem.
  • A fast-moving, focused team where strong engineering judgment is valued and where your work will ship quickly and visibly.
  • The chance to define engineering standards for one of the most ambitious Bitcoin L2 ecosystems, shaping how Bitcoin moves in and out of smart contracts.
  • A remote-first culture with flexibility, autonomy, and deep collaboration with product and engineering.


To Apply

Think you're a good fit? Follow the link below to our Rippling ATS to upload your credentials and officially apply.

👉 Apply for this position


Stacks Labs is proud to be an equal opportunity employer and deeply cares about building a diverse team. Stacks Labs is committed to building an inclusive environment for people of all backgrounds. We do not discriminate on the basis of race, color, gender, sexual orientation, gender identity or expression, religion, disability, national origin, protected veteran status, age, or any other status protected by law.


Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

Jobgether

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

WorkOS

United State

Software Security Engineer

Cyber Security
•
2d ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

Mindlance

United State

Subscribe our newsletter

New Things Will Always Update Regularly