SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Mysten Labs is building foundational infrastructure for decentralized protocols and blockchain technologies. We are seeking a Senior Security Engineer to protect and strengthen the Sui DeFi ecosystem by uncovering vulnerabilities, building monitoring tools, and assessing economic risk across DeFi protocols.
You will work closely with external protocol teams and Mysten's own DeFi products, including DeepBook, to identify and address risks before they become incidents. Your responsibilities will include:
- Building and running continuous monitoring of the Sui DeFi ecosystem for security and economic risk, including oracle issues, misconfigurations, solvency exposure, liquidation capacity, and accounting reconciliation.
- Extending security team tooling through precise static analysis and proprietary agent skills.
- Measuring and driving compliance with DeFi security recommendations across supported protocols, including running compliance cycles, validating security claims against on-chain reality, and tracking remediation commitments.
- Hunting for critical vulnerabilities in high-TVL Sui protocols through full-package audits, variant analysis, pre-execution review of multisig payloads, and post-incident forensics.
- Serving as the security team's point of contact for external DeFi teams and Mysten's own products, handling due diligence, incident coordination, and post-mortems.
- Documenting findings, reports, and runbooks that are actionable for protocol engineers and understandable to non-technical stakeholders, with all claims traceable to bytecode, chain state, or data.
Requirements:
- Bachelor's degree in Computer Science, Computer Engineering, or relevant technical field, or equivalent practical experience.
- 3+ years of hands-on experience in security engineering, smart contract security, or DeFi risk engineering, with a track record of building production tools and finding real vulnerabilities (audit findings, bug bounty reports, published research, or incident work).
- Strong understanding of DeFi mechanics and failure modes: lending markets (LTV, liquidation thresholds, close factors, bad debt), AMMs and concentrated liquidity, perpetuals, liquid staking, oracles (staleness, confidence, TWAP, multi-source aggregation), flash loans, and MEV.
- Proficiency in TypeScript and Python, comfort with Rust, ability to write SQL over large datasets, and experience with blockchain indexers and data warehouses.
- Experience reading smart contract code at source, bytecode, or disassembly level, or demonstrated ability to learn quickly. Move experience is a plus; Solidity or Rust smart contract experience transfers.
- Rigor in verifying claims against bytecode and chain state, building known-clean checks into tools, and clearly stating what was not verified.
- Strong written and verbal communication skills, including ability to influence external teams without formal authority.
- Interest in the web3 space is required.
Preferred Qualifications:
- Sui and Move experience: object and capability model, package upgrades, version gates, programmable transaction blocks, Sui GraphQL and gRPC APIs.
- Knowledge of recent DeFi exploit history on Sui and other chains, including named incidents and defect classes.
- Experience building analysis or monitoring tools with LLM agents (Claude Code or comparable), with clear understanding of where models help versus deterministic tooling.
- Static or dynamic program analysis experience: taint analysis, call graphs, symbolic execution, fuzzing, formal verification.
- Quantitative or economic modeling experience: stress testing, liquidity modeling, risk parameters for lending markets.
- Publications, conference talks, CVEs, or bug bounty rankings.