SlipstreamJobsFresh Startup & VC-Backed Jobs

Protocol Security Researcher

Aave - Remote - Remote

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Aave Labs is seeking a Protocol Security Researcher to build and strengthen its internal protocol security function. This role sits at the intersection of smart contract security, protocol design, adversarial research, and AI-assisted code review. You will be responsible for reviewing major Aave protocol changes before external audit or deployment, performing attacker-driven analysis of smart contracts and protocol mechanisms, and participating in design discussions early enough to influence security-relevant decisions. The role extends beyond traditional auditing to include identifying risks in Aave-adjacent systems such as assets, bridges, oracles, adapters, and critical dependencies. Key responsibilities include: - Review major Aave protocol changes before external audit or deployment - Perform attacker-driven analysis of smart contracts, protocol mechanisms, and integrations - Participate in design and architecture discussions to influence security-relevant decisions - Identify risks in Aave-adjacent systems, including assets, bridges, oracles, adapters, and critical dependencies - Contribute to AI-assisted security tooling and evaluate its effectiveness in real review workflows - Turn review findings into reusable knowledge, invariants, assumptions, and testing or monitoring ideas - Work with monitoring and incident response teams when findings imply operational detection or response needs - Collaborate with external auditors by helping define scope, known risks, and areas of concern The goal is to improve Aave's ability to understand and reduce protocol risk continuously, moving beyond narrow audit work to build a comprehensive security function. Requirements: - 5+ years of relevant security experience - Strong smart contract security background - Ability to independently review complex codebases and reason about protocol-level failure modes - Attacker mindset: ability to move from "this looks wrong" to "this is how it could be exploited" - Strong understanding of DeFi mechanisms, including lending, liquidations, accounting, oracles, collateral, governance, and integrations - Evidence of actively using AI to improve security research, review quality, or review throughput - Clear written communication: ability to explain risk, impact, uncertainty, and trade-offs to engineers and non-security stakeholders - Good judgment about severity, exploitability, and when a finding matters Nice to haves: - Experience with formal methods, fuzzing, invariant testing, or custom security tooling - Experience building internal tools for security review, code understanding, or knowledge management - Experience working with external audit firms or leading audit engagements - Familiarity with governance payloads, upgrade systems, permissioning, and incident response - Open-source security research, published findings, CTFs, bug bounties, or prior public vulnerability research

Similar roles