Head of Blockchain Security
What security roles in crypto pay
64 salaries · our own dataThis role pays $260k-$275k, above the $202k median for security roles in crypto on this board.
As Head of Blockchain Security at BULLISH, you own and elevate the end-to-end security posture of the company's blockchain infrastructure, custody systems, and smart contract protocols. You operate as both a high-impact technical authority and a strategic partner to internal teams, protocol founders, and external security partners, designing scalable security frameworks, leading complex audits across multi-chain environments, and engineering rapid-response mechanisms to protect assets in high-stakes environments. This role is based in New York and requires a minimum of 4 days per week onsite at the office.
What you'll do
- Lead deep-dive architectural reviews and security audits of smart contracts written in Solidity, Rust, and Move, focusing on protocol-level vulnerabilities, and oversee external third-party audits for high-complexity releases
- Produce clear, prioritized technical risk reports and serve as the primary security advisor to protocol founders, engineering leads, and executive leadership, translating complex risks into actionable decisions
- Build, deploy, and maintain robust blockchain monitoring, alerting, and automated detection systems across major ecosystems
- Design and operate automated emergency exit workflows to protect protocol assets under adverse market or security conditions, and facilitate cross-industry incident response tabletop exercises
- Conduct rigorous technical assessments of external institutional custody systems, internal treasury controls, and third-party vendor infrastructure
- Build repeatable security frameworks and processes that enable the security program to scale alongside aggressive organizational growth
What you bring
- 7+ years in cyber security, with 5+ years dedicated specifically to blockchain and smart contract security
- Hands-on experience assessing smart contracts written in Solidity, Rust, and/or Move
- Strong background in C/C++, Linux, and cloud native architectures (AWS, Azure, GCP)
- Proven background in senior-level penetration testing, application security, offensive security methodologies, design reviews, and threat modeling (OWASP Top 10, SANS CWE 25)
- Deep expertise in applied cryptography (PKI, algorithms, encryption at rest and in transit) and network/protocol fundamentals (IP, DNS, HTTP, SSL/TLS)
- Strong working knowledge of institutional custody infrastructure and major DeFi protocols across Ethereum, Solana, Stacks, and Sui
- Ability to articulate critical risks concisely to technical teams and non-technical stakeholders, with outstanding self-management and operational autonomy across global time zones
Nice to have
- Offensive security certifications such as OSCP, OSWE, or OSCE
- Track record of public security research, published vulnerability papers, or presentations at major industry conferences
What we offer
- Base salary of $260,000-$275,000 plus discretionary annual target bonus and performance incentives/benefits
- Minimum 4 days per week onsite at the New York office
About BULLISH
BULLISH is an institutionally focused global digital asset platform. It operates the Bullish Exchange, a regulated spot and derivatives exchange with deep liquidity across Germany, Hong Kong, and Gibraltar; CoinDesk Indices, a suite of proprietary benchmarks and indices for global institutions; CoinDesk Data, providing real-time market data and analytics; and CoinDesk Insights, a media and events platform covering digital assets, markets, policy, and blockchain technology.
