Frequently asked questions
Is this job still open?
GMI Jobs is currently showing this Information Security Engineer, Product role at Aptos Labs as an active listing from employer-controlled hiring sources. Always confirm final availability on the employer application page before applying.
How do I apply for this role?
Use the application link on this page to apply directly with Aptos Labs. GMI Jobs keeps the canonical job page, company context, and market links together so candidates can compare before leaving the site.
What should I compare before applying?
Compare the role location Remote Global (US, EU), any listed pay signal, company profile, related crypto jobs, and salary context before applying. Listed pay signals are not guaranteed offers; confirm compensation with the employer.
Job Description
<div class="content-intro"><p><span style="font-weight: 400;">Aptos is a people-first blockchain on a mission to help billions of people achieve universal and fair access to decentralized assets in a safe and scalable way.</span></p> <p><span style="font-weight: 400;">Founded by some of the original creators and maintainers that researched, designed, and built the Diem blockchain to serve this purpose, we have dedicated several years toward this mission. We believe the open-source Diem technology we have developed is an important foundation of a safe and scalable web3 world where everyone has more equitable opportunities to grow and access financial assets with lower fees and fewer intermediaries.&nbsp;&nbsp;</span></p> <p><span style="font-weight: 400;">Aptos (Ohlone for "The People") encompasses our mission and ethos for why we build.</span></p></div><h3>About the Role</h3> <p>At Aptos Labs we’re pioneering the future of web3 and need a passionate Product Security Engineer to help secure our core technologies. In this role, you’ll be at the forefront of safeguarding our Aptos core infrastructure and Aptos Labs products. Your proactive approach will help us identify and mitigate emerging threats, ensuring our systems remain resilient and trustworthy. You will work closely with our developers, influence security best practices, and lead initiatives that shape the future of web3 security.</p> <h3>Responsibilities</h3> <ul> <li>Analyze and assess novel and recurring security issues via design reviews, code audits, and penetration tests.</li> <li>Design and build security tools, and develop mitigations, frameworks, and hardening strategies tailored for vulnerability prevention and detection.</li> <li>Review and develop secure operational practices, and provide security guidance for engineers.</li> <li>Respond to and triage reports from bug bounty programs.</li> </ul> <h3>Minimum Qualifications</h3> <ul> <li>B.S. or M.S. in Computer Science, a related technical field, or equivalent experience.</li> <li>3+ years of experience in vulnerability research and exploitation.</li> <li>Experience with native development practices and common vulnerability patterns (e.g., Rust, C, etc.)</li> <li>Experience with automated security analysis tooling and frameworks (fuzzing, static analysis, etc.)</li> </ul> <h3>Preferred Qualifications</h3> <ul> <li>Contributions to the security community (public research, blogging, talks in relevant conferences, etc.)</li> <li>Experience with virtual machines or complex runtime environments, such as MoveVM (extra bonus), EVM, WASM, or LLVM-based runtimes, including their security models, sa