← All jobs
CR

Senior or Principal Security Assessment Research Consultant (Remote full-time)

CryptoHackSecurity, CO
Type
Full-time
Work setup
Remote
Experience
Senior
Posted
21 days ago
🌍 Fully remote

What security roles in crypto pay

64 salaries · our own data
median $202k$145k$268k

Most security roles in crypto pay between $145k and $268k, with a median of $202k.

As a Senior or Principal Security Assessment Research Consultant at CryptoHack, you conduct application security assessments for hundreds of clients yearly, ranging from Fortune 500 companies to cutting-edge startups. You work in a remote, low-overhead environment where you focus on finding vulnerabilities across web applications, mobile apps, APIs, client/server systems, embedded devices, and more. Your expertise in application hacking and security research drives the firm's mission to deliver expert assessments without bureaucracy or unnecessary process overhead.

What you'll do

  • Lead security assessments and penetration tests on web applications, mobile apps, APIs, client/server applications, and embedded systems
  • Conduct code reviews and vulnerability research across multiple programming languages including Java, Scala, C, C++, JavaScript, Python, PHP, Ruby, and others
  • Perform reverse engineering and cryptographic analysis when required for engagements
  • Document and report findings, working directly with clients on security recommendations
  • Collaborate with the team to share techniques, findings, and best practices
  • Conduct independent security research during allocated non-billable time

What you bring

  • Proven expertise in application security assessment, with a strong track record in web application penetration testing and code review
  • Several years of professional experience in security consulting, enterprise assessments, or demonstrated excellence in bug bounties or CTF competitions
  • Deep knowledge of application hacking across multiple platforms and languages
  • Ability to work independently and self-direct your assessments while collaborating effectively with team members
  • Comfortable working in a remote environment across timezones from -8 GMT through +1 GMT

Nice to have

  • Published security advisories or recognized bug bounty contributions
  • Experience with mobile application security, reverse engineering, kernel security, or cryptographic vulnerabilities
  • Background assessing microservices architectures or large-scale distributed systems

What we offer

  • Competitive salary aligned with top-tier consulting firms, with compensation based on your experience level
  • 100% coverage of top-tier health and dental plans
  • Four weeks of paid time off annually, plus national holidays and the final week of each calendar year
  • Four to eight weeks of paid, non-billable research time yearly to pursue security research of your choice
  • Fully remote work with the option to travel if desired (currently less than 1% of engagements)
  • Paid conference attendance and professional development opportunities
  • No micromanagement, no unnecessary reporting layers, and a focus on getting out of your way so you can find vulnerabilities

About CryptoHack

CryptoHack is a boutique security consulting firm founded in 2010, serving hundreds of clients including major software companies, hardware vendors, and startups. The firm prioritizes expert consultants and client success over process, offering a relaxed remote environment where senior security professionals conduct assessments on cutting-edge technologies and large-scale systems.

Senior or Principal Security Assessment Research Consultant | CryptoJobsHQ