Senior Security Engineer, Product - Jito Labs

Added
Type
Full-time

About Jito

Jito builds the market layer of Solana: the execution, capital, and incentive infrastructure behind the network's onchain economy. That includes the validator client running the majority of Solana stake, BAM (a new framework for verifiable ordering, pre-execution privacy, and programmable blockspace), JitoSOL (the leading liquid staking token on Solana), and JTX (trading built directly on our own market infrastructure).

We are a lean, high-density team. Everyone here owns real surface area, works in the open, and ships at pace. The engineers on this team are the people market makers call when milliseconds matter.

About Jito

Jito builds the Market Layer of Solana: the execution systems, capital markets, and incentive mechanisms that power real markets on-chain.

Our products process billions in daily transaction value. The Jito-Solana validator client runs on the vast majority of Solana's active stake. BAM is redefining how blocks get built. JitoSOL is the leading liquid staking token on the network. We are not building at the margins. We are building core infrastructure that Solana's economy runs on.

Now we're moving up the stack, bringing that same infrastructure advantage to products that traders and users interact with directly.

We're a team of around 50 people with product-market fit across multiple product lines and years of runway. We take hard problems seriously and move fast on them. Nothing is out of reach.

About the Role

We've gone from one main product line to four, and the security work on those products has outgrown the one person doing it. This role owns product and protocol security: the surface where our code meets real money.

You'll report to the Head of Security and work alongside an Enterprise Security Engineer who owns internal infrastructure, identity and detection. The split is deliberate. They secure how we work; you secure what we ship.

This is an engineering role. Most of the backlog is code, not policy.

What You'll Own

  • Product and protocol security reviews: threat modeling, secure design review, whitebox code review, and getting in early enough to change designs rather than document them
  • Deployment hardening across our product lines, including the jito-solana deploy process
  • Ongoing internal audits of our own products rather than waiting for an external engagement to surface issues
  • Onchain monitoring: standing up tooling like Hypernative or Blockaid and building the detections that catch probing before an attack is underway
  • Bug bounty operations as we bring more of the program in-house: triage, severity assessment, remediation tracking, and escalation
  • Auditor findings driven through to closure: reviewed, prioritized, assigned, tracked
  • AI-assisted security testing and continuous scanning, plus the security surface that comes with agents and AI tooling operating inside a codebase
  • High-impact key and asset risks: key hygiene, hot wallet and engineering keys, multisigs, security councils

What We're Looking For

  • A software engineering background is essential. You've built production systems, and that foundation shapes how you approach security.
  • You've since moved into product security and are fluent across the lifecycle: threat modeling, secure design review, whitebox code review, and vulnerability testing
  • 5+ years of professional experience, with a meaningful portion in software engineering before moving into security
  • Proficiency in at least one systems or backend language. Rust preferred; Go, C++, or Python also work. You will read production codebases and build tooling as routine parts of this job.
  • Demonstrated experience in product or application security, not solely infrastructure or compliance work
  • A track record of building security tooling or automation from scratch
  • Experience running or contributing to a bug bounty program, or a clear view of how you'd run one
  • Genuine interest in AI security, including adversarial testing of agent controls
  • Strong written communication. Findings nobody can act on are findings that don't get fixed.
  • Comfortable with high ownership and working autonomously on a small team
  • Experience in web3, crypto, or DeFi

Nice to Have

  • Smart contract or onchain security experience, particularly on Solana or another SVM chain
  • Experience with onchain monitoring tooling such as Hypernative or Blockaid
  • Familiarity with validator or consensus infrastructure
  • Experience with multisig schemes: signing policy design, quorum configuration, or key management in production
  • Familiarity with hardware security modules: integration, key lifecycle, or operational use
  • Exposure to trusted execution environments: attestation, confidential compute, or secure enclave design
  • Experience with fuzzing, formal verification, or property-based testing of financial logic

Why This Role Exists

Security at Jito has been one person covering four product lines, an expanding AI surface, and a validator client running most of Solana's stake. That person has been spending their time on the most likely risks, which means the highest-impact ones get less attention than they deserve.

We're hiring two engineers so that ownership is distributed rather than bottlenecked, and so losing one person doesn't cost the whole function. The goal is not more approval steps. It is safer defaults, earlier input, and engineering that moves faster because security is in the room rather than at the gate.

How we work

Remote-first, writing-heavy, and transparent by default: most decisions happen in public Slack channels, and everyone's voice carries. We value ownership, humility, curiosity, and getting it done over getting it perfect. Small egos, high standards.

What we offer

Competitive compensation including salary and token incentives, the tools you need to do your best work, and a seat at the center of Solana's market infrastructure alongside some of the strongest engineers in the ecosystem.

Jito is an equal opportunity employer. We evaluate candidates on the basis of their skills, experience, and potential contribution, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by law.

Go to job page

Apply for this position

Want to apply directly from the platform? Please use the form below.

Apply through SailOnChain

Connect your wallet to unlock the application form, as well as future benefits and rewards.

Checking your session…

Or apply directly on the company's website via the link above.

Share job

Want to learn more about how the process works?

Read the documentation for information on the application process.

View Documentation
Apply at Jito Labs
Apply Now →