Mysten Labs

Security Engineer

6.0/10

Mysten Labs

Not specified
Remote
mid
13 days ago
cryptosecurityweb3RustTypeScriptPythonMove

AI Summary

The vacancy is well-defined in responsibilities and requirements but lacks compensation details.

Check Match โ€” Just drop your CV

See your fit for Security Engineer in seconds.

Description

What you'll do

  • โ€ขMaintain and improve the custody systems that hold validator keys, operational keys, and important objects for Mysten-run smart contracts and general on-chain operations, including key generation, storage, access controls, signing workflows, aggregation, rotation, and recovery procedures.
  • โ€ขHarden the signing path end-to-end: review and improve the code, infrastructure, and operational practices around how transactions are authorized, reviewed, and submitted on-chain.
  • โ€ขBuild and improve anti-scam and anti-abuse tooling for the Sui ecosystem, detecting phishing sites, malicious dApps, drainer contracts, and other threats that target Sui users, and partnering with wallet ecosystem teams on mitigations.
  • โ€ขConduct code and design reviews of components that interact with sensitive keys or handle on-chain assets, with a focus on cryptographic correctness, access control, and operational safety.
  • โ€ขParticipate in investigation and response for security issues and incidents that touch custody or ecosystem abuse, and drive concrete fixes that prevent the same class of issue from recurring.

Conditions

  • โ€ขEmployment is contingent upon the successful completion of a background check, which may include verification of employment history, education credentials, criminal history, and other relevant information.
  • โ€ขOur team is remote first and we are hiring across the world. Here at Mysten Labs, youโ€™ll be joining a world-class team with tremendous growth potential as we bring the next billion users to web3.

Requirements

  • โ€ข3+ years of hands-on experience in security engineering, application security, or product security.
  • โ€ขKnowledge relevant to key management in production, for example HSMs, cloud KMS, MPC or threshold-signature systems, hardware wallets, or comparable custody infrastructure.
  • โ€ขProficiency in one or more of: Rust, TypeScript, Python, or Move, and experience reviewing and writing security-sensitive code.
  • โ€ขSolid understanding of applied cryptography fundamentals and the common ways cryptographic systems are misused in practice.
  • โ€ขA builder mentality: comfortable operating with ambiguity, diving into unfamiliar codebases, and shipping the fix yourself rather than handing it off.
  • โ€ขStrong written and verbal communication: you can explain a finding or an issue clearly to the engineer who needs to fix it and to a non-technical stakeholder who needs to understand the risk.
  • โ€ขInterest in the web3 space is required; prior experience shipping in crypto, fintech, or other regulated/high-stakes environments is a plus.
Loading similar jobs...