Hiring · Remote · Pre-launch product
Security Engineer — Remote
EVM · Solidity · Threat modeling · AppSec
Join the engineering team building ZyncSwap, a non-custodial Web3 trading platform currently in active development.
Apply with name, email, LinkedIn, GitHub/portfolio, and resume. We reply at james@zynccoin.com.
Responsibilities
Contract and architecture review, threat models, findings, remediation guidance, release readiness.
- Review smart contracts and protocol changes.
- Produce findings with severity, impact, and remediation.
- Build threat models for ZyncSwap and the public site.
- Advise engineering before code freeze.
- Help coordinate external audits and bounty triage.
Requirements
Proven EVM audit or application-security experience; clear reporting; ability to review Solidity and web attack surface.
- Proven EVM audit experience and/or strong AppSec background.
- Deep knowledge of common web and DeFi failure classes.
- Precise, actionable written reports.
- Comfort reading Solidity and tracing call flows.
Web3 experience
Required for contract review; broader AppSec is welcome.
Process
Profile review → GitHub technical assessment → technical interview with a stack specialist → final review.
- 01
Profile review
We read your LinkedIn, GitHub/portfolio, and resume against the role stack.
- 02
GitHub technical assessment
A practical task in the role’s stack. We look at judgment, clarity, and production habits — not trick questions.
- 03
Technical interview with a stack specialist
Remote conversation on past work, ZyncSwap scope, and how you would ship in this codebase.
- 04
Final review
We decide and reply by email at james@zynccoin.com.
Engagement
Remote · Full-time / long-term. 40 hours / week. BST (UTC+1) core hours — expect meaningful overlap with the UK / BST team during the workday.
About the role
You are the adversarial voice before capital is at risk. ZYNC is pre-launch; this role exists so we do not ship unsafe contracts or a fragile web surface when we do launch.
Nice to have
- Published audits or competitive-audit rankings.
- Formal verification or advanced fuzzing.
- Web API auth and infrastructure security.
Compensation
$130,000–$220,000 USD / year · ZYNC + bounty