← All jobs
ML

Senior Security Engineer, DeFi

Mysten LabsUSA (Remote)
Type
Full-time
Work setup
Remote
Experience
Senior
Posted
Today
🌍 Fully remote

What security roles in crypto pay

67 salaries · our own data
median $200k$143k$268k

Most security roles in crypto pay between $143k and $268k, with a median of $200k.

As a Senior Security Engineer at Mysten Labs, you help protect the Sui ecosystem by uncovering vulnerabilities, building monitoring tools, and assessing economic risk across DeFi protocols. Working closely with external protocol teams and Mysten's own DeFi products including DeepBook, you'll help address risks before they become incidents and strengthen security across the ecosystem.

What you'll do

  • Build and run continuous monitoring of the Sui DeFi ecosystem for security and economic risk: oracle issues, misconfigurations and bad economic parameters, solvency and bad-debt exposure under price shocks, liquidation capacity against on-chain liquidity depth, accounting-versus-positions reconciliation, and invariants.
  • Extend security team tooling, including both precise static analysis tooling and proprietary agent skills.
  • Measure and drive compliance with DeFi security recommendations across supported protocols: run the recurring compliance cycle, fill the protocol report card, validate security claims such as audits, custody, upgrade governance, and oracle dependencies against on-chain reality, track remediation commitments, and escalate when a protocol regresses or fails to disclose an incident.
  • Hunt for critical vulnerabilities in the highest-TVL Sui protocols and get them fixed before they are exploited through full-package audits, variant analysis across forks, pre-execution review of multisig upgrade payloads, and forensics after incidents anywhere in the ecosystem.
  • Be the security team's point of contact for external DeFi teams and for Mysten's own DeFi products such as DeepBook, handling due diligence, incident coordination, and post-mortems that feed back into recommendations and monitors.
  • Write findings, reports, and runbooks that a protocol engineer can act on and a non-technical stakeholder can understand, with every claim traceable to bytecode, chain state, or data.

What you bring

  • A Bachelor's degree in Computer Science, Computer Engineering, a relevant technical field, or equivalent practical experience.
  • 3+ years of hands-on experience in security engineering, smart contract security, or DeFi risk engineering, with a track record of building tools that ran in production and finding real vulnerabilities such as audit findings, bug bounty reports, published research, or incident work.
  • A strong understanding of DeFi mechanics and their failure modes: lending markets (LTV, liquidation thresholds and bonuses, close factors, bad debt), AMMs and concentrated liquidity, perpetuals, liquid staking, oracles (staleness, confidence, TWAP, multi-source aggregation), flash loans, and MEV.
  • Proficiency in TypeScript and Python, and comfort with Rust. Ability to write SQL over large datasets and to work with blockchain indexers and data warehouses.
  • Experience reading smart contract code at source, bytecode, or disassembly level, or an evident ability to learn it quickly. Move experience is a plus, not a requirement; Solidity or Rust smart contract experience transfers.
  • Rigor in verifying claims against bytecode and chain state, building known-clean checks into your tools, and stating what you did not verify.
  • Strong written and verbal communication, including the ability to influence external teams you have no formal authority over.
  • Interest in the web3 space.

Nice to have

  • Sui and Move experience: the object and capability model, package upgrades and version gates, programmable transaction blocks, and the Sui GraphQL and gRPC APIs.
  • Knowledge of the recent DeFi exploit history on Sui and other chains: named incidents, oracle compromises, and the defect classes behind them.
  • Experience building analysis or monitoring tools with LLM agents such as Claude Code, and a clear sense of where models help and where deterministic tooling must do the work.
  • Static or dynamic program analysis experience: taint analysis, call graphs, symbolic execution, fuzzing, or formal verification.
  • Quantitative or economic modeling experience: stress testing, liquidity modeling, or risk parameters for lending markets.
  • Publications, conference talks, CVEs, or bug bounty rankings.

About Mysten Labs

Mysten Labs is building foundational infrastructure for decentralized protocols based on blockchain technologies. The company raised a $300M Series B round from top venture funds including Jump Crypto, Andreessen Horowitz, Binance Labs, Redpoint, Lightspeed, and others. The team is remote-first and hiring worldwide.

Senior Security Engineer, DeFi | CryptoJobsHQ