Protocol Security Researcher

Fully remote

Added
Locations
Type
Full-time

How you can make an impact:

  • Review major Aave protocol changes before external audit or deployment

  • Perform attacker-driven analysis of smart contracts, protocol mechanisms, and integrations

  • Participate in design and architecture discussions early enough to influence security-relevant decisions

  • Identify risks in Aave-adjacent systems, including assets, bridges, oracles, adapters, and critical dependencies

  • Contribute to AI-assisted security tooling and evaluate its effectiveness in real review workflows

  • Turn review findings into reusable knowledge, invariants, assumptions, and testing or monitoring ideas

  • Work with monitoring and incident response teams when review findings imply operational detection or response needs

  • Collaborate with external auditors by helping define scope, known risks, and areas of concern


Let's connect if you have:

  • 5+ years of relevant security experience

  • Strong smart contract security background

  • Ability to independently review complex codebases and reason about protocol-level failure modes

  • Attacker mindset: you can move from “this looks wrong” to “this is how it could be exploited”

  • Strong understanding of DeFi mechanisms, including lending, liquidations, accounting, oracles, collateral, governance, and integrations

  • Evidence that you are actively using AI to improve security research, review quality, or review throughput

  • Clear written communication: you can explain risk, impact, uncertainty, and trade-offs to engineers and non-security stakeholders

  • Good judgment about severity, exploitability, and when a finding matters


Nice to haves:

  • Experience with formal methods, fuzzing, invariant testing, or custom security tooling

  • Experience building internal tools for security review, code understanding, or knowledge management

  • Experience working with external audit firms or leading audit engagements

  • Familiarity with governance payloads, upgrade systems, permissioning, and incident response

  • Open-source security research, published findings, CTFs, bug bounties, or prior public vulnerability research

Share job

Want to learn more about how the process works?

Read the documentation for information on the application process.

View Documentation
Apply at Avara
Apply Now →