Public Facing Security Researcher
Job Description
About the Company Born from groundbreaking research at Columbia University and Yale University, CertiK is a leading Web3 security company focused on securing blockchain protocols, smart contracts, and decentralized applications through cutting-edge security research, formal verification, and AI-powered technology. Founded in 2017 and headquartered in New York City, CertiK provides end-to-end security solutions including smart contract audits, penetration testing, on-chain monitoring, incident response, and compliance services for some of the largest projects in the digital asset ecosystem. Today, CertiK supports thousands of enterprise clients and Web3 projects globally, with a distributed international team spanning North America, Asia, and Europe. The company is backed by leading investors including Coatue, Goldman Sachs, Insight Partners, and Sequoia Capital, and has been recognized by organizations such as the World Economic Forum and CB Insights for its contributions to blockchain security innovation. About This Role This role is for a Web3 security researcher who can act as a public face for CertiK. This means having a strong social media presence, speaking at conferences, and being openly helpful to the wider security community. This doesn't mean you have to have tens of thousands of followers on X, but you do need to be comfortable interacting with the general public. The specific type of security researcher is flexible - contract/chain auditors, pen testers, engineers, and multi-talented individuals can apply. This is a great role for a generalist.
Responsibilities
Work closely with the Web3 Task Force Team to create stronger connections to the blockchain ecosystem. Speak at conferences about your area of expertise on behalf of CertiK. Complete interviews about various Web3 security topics. Perform tasks cross-functionally among the various teams at CertiK. Support the marketing and feedback collection of CertiK’s products and services.Requirements
3+ years of experience in the Web3 space. Strong social media presence and high visibility. Experience speaking at conferences or in front of large audiences. Strong technical skills in the areas of web3 security or related fields.Bonus Points
Large number of social media followers. Previous experience being the public face of an organization.How to Stand Out
- Showcase hands‑on experience with formal verification tools (e.g., CertiK Chain’s Skynet, Coq, or Isabelle) by uploading a public GitHub repo that includes a verified smart‑contract module, a brief README explaining the proof strategy, and CI badges that run the verification automatically. Recruiters at CertiK will dive into that repo during the interview to assess depth of formal methods knowledge.
- Prepare a 5‑minute “security case study” of a recent on‑chain incident (e.g., a DeFi hack) that details the vulnerability class, how you would reproduce it in a sandbox, the mitigation steps, and any automated detection you could implement using Python + Web3.py or Hardhat scripts. Bring the slides (PDF) and a live demo ready for the technical interview.
- Highlight familiarity with CertiK’s AI‑driven audit platform by completing the free “CertiK Skynet Demo” on their website, exporting the analysis report, and referencing specific findings in your cover letter (“I leveraged Skynet’s static analysis to uncover X vulnerability in Y contract”). This signals you’ve already engaged with their proprietary tooling.
- Build a concise portfolio page (single‑page site or Notion) that lists: (1) a brief description of each blockchain security project, (2) the tools used (MythX, Slither, Echidna, Formal Verification), (3) quantitative impact (e.g., saved $2M in potential exploits), and (4) links to audited contracts or bug‑bounty proofs. Include a “downloadable PDF” for interviewers to reference offline.
- Research CertiK’s recent grant programs and community initiatives (e.g., “CertiK Community Grant for Formal Verification”). Mention in your interview how you could contribute—e.g., by writing a blog post or open‑source plugin that extends their verification pipeline—demonstrating alignment with their mission and a proactive mindset that interviewers value.
- When discussing compensation, reference the latest remote salary data for senior security researchers in the US (e.g., Levels.fyi or Glassdoor) and frame your ask around “total compensation that reflects my 3‑year track record of delivering zero‑day discoveries and formal verification audits, plus a performance‑based bonus tied to audit throughput.” This shows market awareness and aligns with CertiK’s results‑driven culture.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.