Hashgraph

Software

ProductSecurityEngineer

Remote Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid+ candidates.

The Brief

“Product Security Engineer at Hashgraph. Skills: Product Security, Blockchain Security, Vulnerability Discovery. Conduct security assessments. Find real vulnerabilities”

What You'll Achieve.

Security review processes are integrated; Security tooling and automated checks are running; The vulnerability backlog is prioritized and actively shrinking; Engineering teams have meaningfully improved their working knowledge

Industry & Context.

Software
Problems you'll solve

Ability to reason about cryptographic failure modes; Ability to reason through trust model tradeoffs

What They're Looking For.

Must Have

Hands-on vulnerability discovery, security testing across blockchain protocols, smart contracts, nodes, APIs, threat modeling, security architecture review experience applied to distributed cryptographic systems, Experience assessing cross-chain protocols, threshold signature schemes, cryptographic systems with complex trust assumptions, Deep working knowledge of applied cryptography, BLS signatures, pairing-based schemes, polynomial commitments, Fiat-Shamir constructions, Ability to reason about cryptographic failure modes, Direct experience auditing or breaking a cross-chain bridge, Ability to reason through trust model tradeoffs, state proof, multisig, oracle attestation models, Blockchain security, secure coding practices across EVM-compatible and non-EVM chains, Security testing tooling, static analysis, dynamic analysis, fuzzing, Experience developing custom fuzzing harnesses, security test infrastructure, Ability to read and audit Rust, Java cryptographic code, Understanding of memory safety, constant-time correctness, secret handling, security risks at JNI boundaries

Nice to Have

Experience designing and operating grammar-aware fuzzing campaigns against gRPC, JSON-RPC, protocol-level endpoints, Experience building classifier pipelines, Prior work on Ethereum consensus client security, Prior work on production threshold signature systems, Experience building security automation tooling, Experience integrating AI-assisted workflows into security review and triage processes

What You'll Do.

Conduct security assessments

Find real vulnerabilities

Design adversarial test cases

Define and enforce security gates

Partner with engineering teams

Build and improve security tooling

Track emerging blockchain attack patterns

How You'll Work.

Team & Collaboration

Partner directly with engineering teams; structured developer collaboration

Full Job Description

About Hashgraph: Hashgraph is a fast-growing software company committed to supporting, developing and servicing Hedera, an open source, proof-of-stake platform. Hedera is EVM-compatible and has been specifically built to meet the needs of enterprise and web3 applications, which require speed, security, stability and sustainability. Hedera’s public network is governed by industry-leading organizations, spanning 11 sectors and 14 regions who oversee the development and direction of the decentralized platform. The role: We are hiring a Product Security Engineer to embed security into the product development lifecycle and ensure vulnerabilities are found by us before they are found by others. Hedera is an enterprise-grade distributed ledger securing billions of transactions for global developer and institutions. As the platform grows with new protocol upgrades, EVM-compatible services, cross-chain infrastructure, and cryptographic primitives, the attack surface grows with it. This role exists to ensure that security is a first-class property of every protocol upgrade, smart contract, and node shipped to production. In this role, you will: Conduct end-to-end security assessments of blockchain-based systems, from cryptographic primitive design and protocol architecture through smart contract implementation and deployed infrastructure. Find real vulnerabilities through hands-on review, adversarial testing, and proof-of-concept exploit development, not just automated scanning. Design adversarial test cases and proof-of-concept exploits for Hedera-native services, EVM-compatible contracts, cross-chain bridges, and consensus-layer components. Own threat modeling and security architecture reviews across product phases. Define and enforce security gates before new components reach production. Partner directly with engineering teams to translate cryptographic and protocol-level risks into concrete, prioritized remediation work. Build and improve security tooling, fuzzing infrast

Free ATS check

Applying for this Product Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

ANONYMOUS · UNFILTERED

What do employees actually say about Hashgraph?

Real rants from real employees. Read before you apply.

Read Company Rants →