SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 200,000 - 250,000 / annual
Phantom is a leading multi-chain crypto wallet with 7M+ active users, backed by a16z, Sequoia Capital, and Paradigm. The company is on a mission to connect the world to open markets through self-custody and access to decentralized networks.
As a Staff Product Security Engineer, you will be responsible for identifying, exploiting, and mitigating security vulnerabilities in Phantom's software applications and infrastructure. Security is core to the product and the reason millions of people trust Phantom to securely store their crypto assets.
Key responsibilities include:
- Perform regular security assessments on new projects, infrastructure, and code
- Identify and mitigate security vulnerabilities through manual testing, automated tools, threat modeling, and threat intelligence
- Stay current with offensive security techniques, application security threats, and blockchain security best practices, recommending improvements to security posture
- Write detailed reports of findings and present them to management and technical teams to help prevent real-world attacks
- Work with development teams to implement secure coding practices and ensure the integrity of cryptographic functions
- Collaborate across development and platform teams to integrate security throughout the organization
- Participate in incident response and incident management activities
- Lead large cross-team security projects
You will work in a fully remote environment with a team of 180 experienced builders in the blockchain and crypto industry. The company supports Solana, Ethereum, Polygon, and Bitcoin with plans to expand to additional networks.
REQUIREMENTS:
- 7+ years of experience in offensive security techniques, with a focus on blockchain technology and cryptography
- Strong understanding of security risks, vulnerabilities, and concepts in web and mobile applications
- Proficient in code review for JavaScript & TypeScript with strong understanding of application security threats and offensive security techniques
- Ability to write proofs-of-concept to demonstrate vulnerabilities and review patch code against repository standards
- Strong analytical and problem-solving skills
- Good verbal and written communication skills