
Headquarters:
URL: https://dusklabs.xyz
Concerning the Function
We’re in search of a mid-level safety engineer to affix the Nightfall Labs engineering staff, specializing in safety analysis and constructing strong automated safety testing infrastructure throughout our portfolio of fintech and cryptography initiatives. This position combines hands-on safety evaluation with programs engineering, requiring somebody who can each establish vulnerabilities and construct the instruments to repeatedly validate safety posture.
You may work throughout a variety of programs – from transport layer protocols implementing novel post-quantum cryptography to monetary infrastructure dealing with delicate transactions – conducting in-depth safety analysis and growing complete automated testing frameworks to assist our security-first growth course of.
You may be on a high-performing staff with different expert-level builders who’re keen about studying and dealing on attention-grabbing issues.
Duties
-
Conduct safety analysis and vulnerability evaluation throughout fintech and cryptographic programs.
-
Design and construct automated safety testing infrastructure utilizing Rust and shell scripts.
-
Develop and keep complete safety take a look at suites, together with fuzzing, penetration testing automation, and cryptographic protocol testing.
-
Construct monitoring and alerting programs to detect safety anomalies and potential assault vectors.
-
Carry out menace modeling and safety assessments of system structure and code implementations throughout a number of initiatives.
-
Analysis and analyze rising assault strategies, vulnerabilities, and defensive applied sciences related to monetary programs and cryptographic protocols.
-
Create instruments and frameworks for steady safety validation in CI/CD pipelines.
-
Doc safety findings and translate analysis into actionable suggestions for the event staff.
-
Preserve and improve current safety testing instruments and infrastructure.
Required {Qualifications}
-
Sturdy software program growth fundamentals with 2–4 years of expertise.
-
Strong expertise with Rust or willingness to study rapidly.
-
Comfy with TypeScript and fashionable internet applied sciences.
-
Sturdy expertise with Linux programs and shell scripting.
-
Background in safety testing methodologies, together with static evaluation, dynamic evaluation, and penetration testing.
-
Data of cryptographic ideas and safe coding practices.
-
Expertise constructing automated testing infrastructure or CI/CD programs.
-
Familiarity with safety instruments and frameworks (SAST, DAST, fuzzing instruments, and so on.).
-
Data of community protocol evaluation and visitors inspection instruments.
-
Sturdy analytical and problem-solving abilities with consideration to element.
Most popular {Qualifications}
-
Expertise with safety analysis or vulnerability discovery.
-
Background in cryptographic protocol evaluation or implementation.
-
Expertise auditing DeFi protocols.
-
Expertise with containerization and orchestration applied sciences (Docker, Kubernetes).
-
Familiarity with reverse engineering instruments and binary evaluation.
-
Expertise with compliance frameworks and safety requirements.
-
Background in malware evaluation or incident response.
-
Expertise with cloud safety and infrastructure-as-code.
-
Open supply contributions to safety instruments or analysis initiatives.
About Nightfall Labs
We’re an engineering-driven growth company that helps early-stage firms kick-start their engineering operations, or helps mid-stage firms develop greenfield software program initiatives.
We try to keep up experience on the cutting-edge of expertise, take satisfaction in doing top quality work, and differentiate ourselves from different growth groups by our outcomes.
You may be an excellent match if you’re keen about expertise, like getting issues executed, studying new issues, and dealing on attention-grabbing issues.
You may even be an excellent match when you like freedom. We respect your autonomy and haven’t got strict guidelines on how and if you work. We solely have occasional conferences, and like asynchronous communication. After we do have conferences, we attempt to knock them out unexpectedly to maximise uninterrupted work time.
If you happen to’ve obtained a public report of your work, whether or not that is a physique of talks and publications, or particularly open supply software program initiatives, we would like to see it. You may go to the entrance of the interview line.
To use: https://weworkremotely.com/remote-jobs/dusk-labs-security-engineer-research-test


