Resume and JobRESUME AND JOB
Coinbase logo

Offensive Security Engineer, Assessments (Web3)

Coinbase

Offensive Security Engineer, Assessments (Web3)

Coinbase logo

Coinbase

full-time

Posted: June 27, 2025

Number of Vacancies: 1

Job Description

Responsibilities

  • Conduct security assessments of Web3 products and services, including smart contracts, DeFi protocols, and blockchain infrastructure.
  • Collaborate with partner teams to enhance detection and response capabilities for Web3 vulnerabilities.
  • Stay informed on emerging security trends, advisories, and academic research in the Web3 space.
  • Lead Web3 bug bounty triage and validation, ensuring timely and accurate assessments of reported vulnerabilities.
  • Develop and implement strategies to incentivize high-quality bug bounty submissions and engage with the hacker community.
  • Manage the Web3 bug bounty program, including scope updates, researcher communication, and payout disbursements.
  • Analyze bug bounty data to identify trends, common vulnerabilities, and areas for improvement.
  • Collaborate with engineering teams to prioritize and remediate vulnerabilities identified through the bug bounty program.
  • Mentor and train junior security engineers in Web3 bug bounty triage and analysis.
  • Provide on-call support for critical Web3 bug bounty-related incidents.
  • Document and report on Web3 bug bounty metrics and program effectiveness.

Required Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Software Engineering, or a related field.
  • 3+ years of experience in Web3 application security and penetration testing.
  • Proven track record of identifying critical vulnerabilities across the blockchain protocol stack, Web2, and Web3 components.
  • Extensive knowledge of the blockchain ecosystem, including L1/L2 networks, DeFi protocols, and staking mechanisms.
  • Deep understanding of Web2 security concepts and common vulnerabilities (e.g., OWASP Top 10, SANS Top 25).
  • Strong analytical skills to identify trends and patterns in vulnerabilities.
  • Excellent communication skills for engaging with internal teams.
  • Passion for security and a drive to improve Web3 security posture.
  • Ability to work independently and take ownership of penetration testing initiatives.
  • Energy and self-drive for continuous learning in the rapidly evolving crypto space.
  • Excellence in clear, direct, and kind communication with technical and non-technical stakeholders.
  • Experience building relationships with product, engineering, and security teams.

Preferred Qualifications

  • Participation in CTFs, bug bounty programs, or open-source security research.
  • Expertise in Application Security, Network Security, or Cloud Security.
  • Relevant security certifications (e.g., OSCP, GPEN).
  • Experience developing and implementing security tooling to support bug bounty triage and analysis.
  • Experience with bug bounty programs and platforms, including triage, validation, and researcher communication.
  • Strong analytical skills to identify trends and patterns in bug bounty submissions.
  • Excellent communication skills to effectively engage with bug bounty researchers.

Required Skills

  • Web3 application security
  • penetration testing
  • identifying critical vulnerabilities
  • blockchain ecosystem knowledge (L1/L2 networks, DeFi protocols, staking mechanisms)
  • Web2 security concepts (OWASP Top 10, SANS Top 25)
  • analytical skills
  • communication skills
  • independent work and ownership
  • continuous learning
  • building relationships

Benefits

  • bonus eligibility
  • equity eligibility
  • benefits (including medical, dental, vision and 401(k))

Salary Range

$152405 - $179300 USD

Locations

  • US Zone 1 (Job Requisitions Only), United States (Remote)

Salary

152,405 - 179,300 USD / yearly

Skills Required

  • Web3 application securityintermediate
  • penetration testingintermediate
  • identifying critical vulnerabilitiesintermediate
  • blockchain ecosystem knowledge (L1/L2 networks, DeFi protocols, staking mechanisms)intermediate
  • Web2 security concepts (OWASP Top 10, SANS Top 25)intermediate
  • analytical skillsintermediate
  • communication skillsintermediate
  • independent work and ownershipintermediate
  • continuous learningintermediate
  • building relationshipsintermediate

Required Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Software Engineering, or a related field. (experience)
  • 3+ years of experience in Web3 application security and penetration testing. (experience)
  • Proven track record of identifying critical vulnerabilities across the blockchain protocol stack, Web2, and Web3 components. (experience)
  • Extensive knowledge of the blockchain ecosystem, including L1/L2 networks, DeFi protocols, and staking mechanisms. (experience)
  • Deep understanding of Web2 security concepts and common vulnerabilities (e.g., OWASP Top 10, SANS Top 25). (experience)
  • Strong analytical skills to identify trends and patterns in vulnerabilities. (experience)
  • Excellent communication skills for engaging with internal teams. (experience)
  • Passion for security and a drive to improve Web3 security posture. (experience)
  • Ability to work independently and take ownership of penetration testing initiatives. (experience)
  • Energy and self-drive for continuous learning in the rapidly evolving crypto space. (experience)
  • Excellence in clear, direct, and kind communication with technical and non-technical stakeholders. (experience)
  • Experience building relationships with product, engineering, and security teams. (experience)

Preferred Qualifications

  • Participation in CTFs, bug bounty programs, or open-source security research. (experience)
  • Expertise in Application Security, Network Security, or Cloud Security. (experience)
  • Relevant security certifications (e.g., OSCP, GPEN). (experience)
  • Experience developing and implementing security tooling to support bug bounty triage and analysis. (experience)
  • Experience with bug bounty programs and platforms, including triage, validation, and researcher communication. (experience)
  • Strong analytical skills to identify trends and patterns in bug bounty submissions. (experience)
  • Excellent communication skills to effectively engage with bug bounty researchers. (experience)

Responsibilities

  • Conduct security assessments of Web3 products and services, including smart contracts, DeFi protocols, and blockchain infrastructure.
  • Collaborate with partner teams to enhance detection and response capabilities for Web3 vulnerabilities.
  • Stay informed on emerging security trends, advisories, and academic research in the Web3 space.
  • Lead Web3 bug bounty triage and validation, ensuring timely and accurate assessments of reported vulnerabilities.
  • Develop and implement strategies to incentivize high-quality bug bounty submissions and engage with the hacker community.
  • Manage the Web3 bug bounty program, including scope updates, researcher communication, and payout disbursements.
  • Analyze bug bounty data to identify trends, common vulnerabilities, and areas for improvement.
  • Collaborate with engineering teams to prioritize and remediate vulnerabilities identified through the bug bounty program.
  • Mentor and train junior security engineers in Web3 bug bounty triage and analysis.
  • Provide on-call support for critical Web3 bug bounty-related incidents.
  • Document and report on Web3 bug bounty metrics and program effectiveness.

Benefits

  • general: bonus eligibility
  • general: equity eligibility
  • general: benefits (including medical, dental, vision and 401(k))

Target Your Resume for "Offensive Security Engineer, Assessments (Web3)" , Coinbase

Get personalized recommendations to optimize your resume specifically for Offensive Security Engineer, Assessments (Web3). Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Offensive Security Engineer, Assessments (Web3)" , Coinbase

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

EngineeringCryptocurrencyBlockchainFinanceCryptoWeb3Engineering

Related Jobs You May Like

No related jobs found at the moment.

Coinbase logo

Offensive Security Engineer, Assessments (Web3)

Coinbase

Offensive Security Engineer, Assessments (Web3)

Coinbase logo

Coinbase

full-time

Posted: June 27, 2025

Number of Vacancies: 1

Job Description

Responsibilities

  • Conduct security assessments of Web3 products and services, including smart contracts, DeFi protocols, and blockchain infrastructure.
  • Collaborate with partner teams to enhance detection and response capabilities for Web3 vulnerabilities.
  • Stay informed on emerging security trends, advisories, and academic research in the Web3 space.
  • Lead Web3 bug bounty triage and validation, ensuring timely and accurate assessments of reported vulnerabilities.
  • Develop and implement strategies to incentivize high-quality bug bounty submissions and engage with the hacker community.
  • Manage the Web3 bug bounty program, including scope updates, researcher communication, and payout disbursements.
  • Analyze bug bounty data to identify trends, common vulnerabilities, and areas for improvement.
  • Collaborate with engineering teams to prioritize and remediate vulnerabilities identified through the bug bounty program.
  • Mentor and train junior security engineers in Web3 bug bounty triage and analysis.
  • Provide on-call support for critical Web3 bug bounty-related incidents.
  • Document and report on Web3 bug bounty metrics and program effectiveness.

Required Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Software Engineering, or a related field.
  • 3+ years of experience in Web3 application security and penetration testing.
  • Proven track record of identifying critical vulnerabilities across the blockchain protocol stack, Web2, and Web3 components.
  • Extensive knowledge of the blockchain ecosystem, including L1/L2 networks, DeFi protocols, and staking mechanisms.
  • Deep understanding of Web2 security concepts and common vulnerabilities (e.g., OWASP Top 10, SANS Top 25).
  • Strong analytical skills to identify trends and patterns in vulnerabilities.
  • Excellent communication skills for engaging with internal teams.
  • Passion for security and a drive to improve Web3 security posture.
  • Ability to work independently and take ownership of penetration testing initiatives.
  • Energy and self-drive for continuous learning in the rapidly evolving crypto space.
  • Excellence in clear, direct, and kind communication with technical and non-technical stakeholders.
  • Experience building relationships with product, engineering, and security teams.

Preferred Qualifications

  • Participation in CTFs, bug bounty programs, or open-source security research.
  • Expertise in Application Security, Network Security, or Cloud Security.
  • Relevant security certifications (e.g., OSCP, GPEN).
  • Experience developing and implementing security tooling to support bug bounty triage and analysis.
  • Experience with bug bounty programs and platforms, including triage, validation, and researcher communication.
  • Strong analytical skills to identify trends and patterns in bug bounty submissions.
  • Excellent communication skills to effectively engage with bug bounty researchers.

Required Skills

  • Web3 application security
  • penetration testing
  • identifying critical vulnerabilities
  • blockchain ecosystem knowledge (L1/L2 networks, DeFi protocols, staking mechanisms)
  • Web2 security concepts (OWASP Top 10, SANS Top 25)
  • analytical skills
  • communication skills
  • independent work and ownership
  • continuous learning
  • building relationships

Benefits

  • bonus eligibility
  • equity eligibility
  • benefits (including medical, dental, vision and 401(k))

Salary Range

$152405 - $179300 USD

Locations

  • US Zone 1 (Job Requisitions Only), United States (Remote)

Salary

152,405 - 179,300 USD / yearly

Skills Required

  • Web3 application securityintermediate
  • penetration testingintermediate
  • identifying critical vulnerabilitiesintermediate
  • blockchain ecosystem knowledge (L1/L2 networks, DeFi protocols, staking mechanisms)intermediate
  • Web2 security concepts (OWASP Top 10, SANS Top 25)intermediate
  • analytical skillsintermediate
  • communication skillsintermediate
  • independent work and ownershipintermediate
  • continuous learningintermediate
  • building relationshipsintermediate

Required Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Software Engineering, or a related field. (experience)
  • 3+ years of experience in Web3 application security and penetration testing. (experience)
  • Proven track record of identifying critical vulnerabilities across the blockchain protocol stack, Web2, and Web3 components. (experience)
  • Extensive knowledge of the blockchain ecosystem, including L1/L2 networks, DeFi protocols, and staking mechanisms. (experience)
  • Deep understanding of Web2 security concepts and common vulnerabilities (e.g., OWASP Top 10, SANS Top 25). (experience)
  • Strong analytical skills to identify trends and patterns in vulnerabilities. (experience)
  • Excellent communication skills for engaging with internal teams. (experience)
  • Passion for security and a drive to improve Web3 security posture. (experience)
  • Ability to work independently and take ownership of penetration testing initiatives. (experience)
  • Energy and self-drive for continuous learning in the rapidly evolving crypto space. (experience)
  • Excellence in clear, direct, and kind communication with technical and non-technical stakeholders. (experience)
  • Experience building relationships with product, engineering, and security teams. (experience)

Preferred Qualifications

  • Participation in CTFs, bug bounty programs, or open-source security research. (experience)
  • Expertise in Application Security, Network Security, or Cloud Security. (experience)
  • Relevant security certifications (e.g., OSCP, GPEN). (experience)
  • Experience developing and implementing security tooling to support bug bounty triage and analysis. (experience)
  • Experience with bug bounty programs and platforms, including triage, validation, and researcher communication. (experience)
  • Strong analytical skills to identify trends and patterns in bug bounty submissions. (experience)
  • Excellent communication skills to effectively engage with bug bounty researchers. (experience)

Responsibilities

  • Conduct security assessments of Web3 products and services, including smart contracts, DeFi protocols, and blockchain infrastructure.
  • Collaborate with partner teams to enhance detection and response capabilities for Web3 vulnerabilities.
  • Stay informed on emerging security trends, advisories, and academic research in the Web3 space.
  • Lead Web3 bug bounty triage and validation, ensuring timely and accurate assessments of reported vulnerabilities.
  • Develop and implement strategies to incentivize high-quality bug bounty submissions and engage with the hacker community.
  • Manage the Web3 bug bounty program, including scope updates, researcher communication, and payout disbursements.
  • Analyze bug bounty data to identify trends, common vulnerabilities, and areas for improvement.
  • Collaborate with engineering teams to prioritize and remediate vulnerabilities identified through the bug bounty program.
  • Mentor and train junior security engineers in Web3 bug bounty triage and analysis.
  • Provide on-call support for critical Web3 bug bounty-related incidents.
  • Document and report on Web3 bug bounty metrics and program effectiveness.

Benefits

  • general: bonus eligibility
  • general: equity eligibility
  • general: benefits (including medical, dental, vision and 401(k))

Target Your Resume for "Offensive Security Engineer, Assessments (Web3)" , Coinbase

Get personalized recommendations to optimize your resume specifically for Offensive Security Engineer, Assessments (Web3). Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Offensive Security Engineer, Assessments (Web3)" , Coinbase

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

EngineeringCryptocurrencyBlockchainFinanceCryptoWeb3Engineering

Related Jobs You May Like

No related jobs found at the moment.