As a Security Engineer at Stacks Labs, you'll work with the CTO to help building secure systems, including the sBTC signer network, the Stacks node, our smart contracts, and the infrastructure and release pipeline that ship them.
You'll operate autonomously in a fully remote role, embedded with a globally distributed engineering team. This is a hands-on role for someone who would rather find and fix the bug instead of writing a slide about it.
Outcomes You'll Drive
- We find our vulnerabilities before anyone else does
You hunt through code, infrastructure, and deployments with an attacker's mindset. The things you find get triaged, remediated, fixed.
- Security that ships as code
Your work produces pull requests, hardened configs, detection rules, and tests. Engineers see you as someone who makes their systems better, not someone who slows them down.
- A hardened perimeter where it matters
Key custody, secrets management, access control, CI/CD, and the software supply chain are locked down against the realistic threats to a system securing crypto-assets.
- An AI-augmented security practice
LLMs and coding agents multiply your reach across code review, fuzzing, triage, and log analysis. You know exactly where they help, where they lie, and how to build systems that leverage them to scale things up.
- Calm, rehearsed incident response
When something goes wrong there's a playbook, a clear owner, and a blameless postmortem that leaves the system stronger than before.
What You'll Do
Offense
- Threat model and attack our software, infrastructure, and contracts. Write exploits against our own systems before adversaries do.
- Build and run fuzzing, property-based, and adversarial test harnesses.
- Run internal red-team exercises and coordinate external audits and bug bounty programs, triaging and validating what comes back.
Defense
- Detection and monitoring: what does "compromised" look like, and how do we know within minutes rather than days?
- Harden hosts, CI/CD, and the software supply chain. Audit dependencies and design reproducible builds and signed/attested releases.
- Support incident response and post-incident reviews.
Engineering & Tooling
- Review security-sensitive PRs across the codebase and pair with engineers on secure design.