Demo

Senior Security Engineer, Offensive Security and Blockchain

DFINITY
San Francisco, CA Full Time
POSTED ON 12/11/2024
AVAILABLE BEFORE 2/11/2025

We're seeking an experienced Offensive Security Engineer to join our growing security team with a focus on offensive security, threat research, and exploit development. You will identify vulnerabilities, understand how they function behind the scenes, and develop patterns and tools to mitigate risks. If you have a strong technical background, are passionate about offensive security, and enjoy working in decentralized environments, we want to hear from you.

Key Responsibilities:

Red Team Strategy & Execution

  • Lead and design sophisticated Red Team operations targeting Internet Computer Protocol, governance, subnets, nodes, and system dApps
  • Develop adversary emulation plans to test both platform and infrastructure defenses, identifying weaknesses before they can be exploited

Exploit Development & Vulnerability Research

  • Research, develop, and test advanced exploits against the Internet Computer Protocol and infrastructure
  • Maintain an internal repository of exploits, scripts, and tools for advanced offensive security operations

Infrastructure Security

  • Strengthen the security of Internet Computer Operating Systems (ICOS) running on virtual machines by implementing advanced hardening measures 
  • Perform vulnerability assessments and penetration tests on the ICOS environment and the overall Internet Computer infrastructure to identify and mitigate risks
  • Harden and assess security for internal Kubernetes clusters and associated services, ensuring robust defense mechanisms against container-based attacks
  • Perform security testing across cloud-native infrastructures, CI/CD pipelines, and microservices environments, identifying lateral movement paths and privilege escalation risks

Tool Development & Automation

  • Build and maintain custom offensive security tools for exploit delivery, post-exploitation automation, and Red Team simulations
  • Develop secure operational tools to streamline complex engagements and support security monitoring, threat detection, and incident handling

Collaboration & Incident Handling

  • Partner with cross-functional teams, including blockchain developers, DevOps, and infrastructure engineers, to embed security best practices throughout the development lifecycle
  • Lead incident response efforts involving blockchain or internal systems, conducting thorough post-mortems and implementing mitigation strategies
  • Publish security advisories and report CVEs

Requirements:

  • Extensive experience planning and executing Red Team engagements in complex, distributed environments, simulating advanced persistent threats (APTs) across blockchain and traditional infrastructure
  • Skilled in adversary emulation, lateral movement techniques, privilege escalation, and exfiltration tactics
  • Proven experience in identifying and exploiting vulnerabilities specific to blockchain ecosystems, including distributed consensus mechanisms, smart contract execution, and inter-node communication
  • Strong understanding of kernel-level vulnerabilities, hypervisor security, and virtualized environments
  • Strong understanding of SELinux
  • Expertise in securing Kubernetes clusters and traditional infrastructure, with a focus on container security.
  • Proficiency in working with QEMU virtualization technologies and AMD SEV-SNP secure enclaves is a plus
  • This is a hybrid-onsite position, based out of our soon-to-be-opened office in the heart of San Francisco.

Base Salary Range:  $175,000 - $240,000/yr

This position can be considered across multiple levels. Total compensation at DFINITY consists of base salary generous bonus and is determined based on multiple factors including job leveling, areas of expertise, educational background, geographic location and overall experience.  

In addition to the cash components of our offers, we have generous benefits including top tier medical, dental, and vision insurance; disability insurance; life insurance; 401(k); flexible PTO policy in addition to paid holidays.

Salary : $175,000 - $240,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Senior Security Engineer, Offensive Security and Blockchain?

Sign up to receive alerts about other jobs on the Senior Security Engineer, Offensive Security and Blockchain career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at DFINITY

DFINITY
Hired Organization Address San Francisco, CA Full Time
The DFINITY Foundation is seeking an experienced IT Support Lead to oversee IT operations at our San Francisco office an...
DFINITY
Hired Organization Address San Francisco, CA Full Time
In this role you will lead ICP’s efforts in Customer Relationship Management, in collaboration with the rest of the Glob...
DFINITY
Hired Organization Address San Francisco, CA Full Time
In this role you will support ICP’s continuous growth across all digital channels, in collaboration with the rest of the...
DFINITY
Hired Organization Address California, MO Full Time
We are seeking an experienced AI Integrations Engineer to join our team and contribute to the integration of various sof...

Not the job you're looking for? Here are some other Senior Security Engineer, Offensive Security and Blockchain jobs in the San Francisco, CA area that may be a better fit.

Senior Security Engineer, Offensive Security

DFINITY Foundation, San Francisco, CA

Remote Application Security Engineer - Zetachain

Blockchain Works, San Francisco, CA

AI Assistant is available now!

Feel free to start your new journey!