How you can make an impact:
-
Review major Aave protocol changes before external audit or deployment
-
Perform attacker-driven analysis of smart contracts, protocol mechanisms, and integrations
-
Participate in design and architecture discussions early enough to influence security-relevant decisions
-
Identify risks in Aave-adjacent systems, including assets, bridges, oracles, adapters, and critical dependencies
-
Contribute to AI-assisted security tooling and evaluate its effectiveness in real review workflows
-
Turn review findings into reusable knowledge, invariants, assumptions, and testing or monitoring ideas
-
Work with monitoring and incident response teams when review findings imply operational detection or response needs
-
Collaborate with external auditors by helping define scope, known risks, and areas of concern
Let's connect if you have:
-
5+ years of relevant security experience
-
Strong smart contract security background
-
Ability to independently review complex codebases and reason about protocol-level failure modes
-
Attacker mindset: you can move from “this looks wrong” to “this is how it could be exploited”
-
Strong understanding of DeFi mechanisms, including lending, liquidations, accounting, oracles, collateral, governance, and integrations
-
Evidence that you are actively using AI to improve security research, review quality, or review throughput
-
Clear written communication: you can explain risk, impact, uncertainty, and trade-offs to engineers and non-security stakeholders
-
Good judgment about severity, exploitability, and when a finding matters
Nice to haves:
-
Experience with formal methods, fuzzing, invariant testing, or custom security tooling
-
Experience building internal tools for security review, code understanding, or knowledge management
-
Experience working with external audit firms or leading audit engagements
-
Familiarity with governance payloads, upgrade systems, permissioning, and incident response
-
Open-source security research, published findings, CTFs, bug bounties, or prior public vulnerability research
