Aptos Labs Logo

Aptos Labs

Information Security Engineer, Product

Posted 17 Days Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in Canada
Mid level
Remote or Hybrid
Hiring Remotely in Canada
Mid level
Secure Aptos core infrastructure and products via design reviews, code audits, penetration tests; build security tools and mitigations; define secure operational practices; advise engineers; and triage bug bounty reports.
The summary above was generated by AI

Aptos is a people-first blockchain on a mission to help billions of people achieve universal and fair access to decentralized assets in a safe and scalable way.

Founded by some of the original creators and maintainers that researched, designed, and built the Diem blockchain to serve this purpose, we have dedicated several years toward this mission. We believe the open-source Diem technology we have developed is an important foundation of a safe and scalable web3 world where everyone has more equitable opportunities to grow and access financial assets with lower fees and fewer intermediaries.  

Aptos (Ohlone for "The People") encompasses our mission and ethos for why we build.

About the Role

At Aptos Labs we’re pioneering the future of web3 and need a passionate Product Security Engineer to help secure our core technologies. In this role, you’ll be at the forefront of safeguarding our Aptos core infrastructure and Aptos Labs products. Your proactive approach will help us identify and mitigate emerging threats, ensuring our systems remain resilient and trustworthy. You will work closely with our developers, influence security best practices, and lead initiatives that shape the future of web3 security.

Responsibilities
  • Analyze and assess novel and recurring security issues via design reviews, code audits, and penetration tests.
  • Design and build security tools, and develop mitigations, frameworks, and hardening strategies tailored for vulnerability prevention and detection.
  • Review and develop secure operational practices, and provide security guidance for engineers.
  • Respond to and triage reports from bug bounty programs.
Minimum Qualifications
  • B.S. or M.S. in Computer Science, a related technical field, or equivalent experience.
  • 3+ years of experience in vulnerability research and exploitation.
  • Experience with native development practices and common vulnerability patterns (e.g., Rust, C, etc.)
  • Experience with automated security analysis tooling and frameworks (fuzzing, static analysis, etc.)
Preferred Qualifications
  • Contributions to the security community (public research, blogging, talks in relevant conferences, etc.)
  • Experience with virtual machines or complex runtime environments, such as MoveVM (extra bonus), EVM, WASM, or LLVM-based runtimes, including their security models, sandboxing, and execution isolation.
  • Familiarity with smart contract programming languages (extra bonus for Move), security tools, and frameworks, including formal verification.

Our Benefits

  • 100% insurance premium coverage for medical, dental, and vision for you and your dependents (US Employees)
  • Equipment of your choice
  • Flexible vacation time, 11 holidays, and floating company days off 
  • Competitive Salary
  • Protocol Token Grants
  • 401k matching (US Employees)
  • Fun and inclusive in-person and digital events

Aptos is committed to diversity in the workplace, and we’re proud to be an Equal Opportunity Employer. We do not hire on the basis of race, color, religion, creed, gender, national origin, citizenship, age, disability, veteran status, marital status, pregnancy, parental status, sex, gender expression or identity, sexual orientation, or any other basis protected by local, state or federal law. All employment is decided based on qualifications, merit, and business need.

We are committed to providing a safe and secure hiring process for all applicants. Unfortunately, there are individuals who may attempt to impersonate Aptos or our employees for fraudulent purposes.
To protect yourself, please be aware of the following:
  • We will never ask you for payment of any kind during the application or onboarding process, including fees for background checks, training, or equipment.
  • We will always communicate with you using our official company email domain.
  • We will never request your personal financial information, such as your social security number or bank account details, during the initial application stages or via email or a video/voice call when onboarding.

Similar Jobs

Senior level
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Create high-quality 3D character gameplay animations for navigation, interactions, conversations, traversal, and other gameplay systems. Export, implement, and test animations in the game engine; troubleshoot animation issues; collaborate with animators, designers, and gameplay programmers; participate in reviews; and mentor junior animators. The role requires strong knowledge of body mechanics, biped locomotion, motion capture, keyframe animation, gameplay systems, and animation workflows, with experience shipping an AAA game.
Top Skills: Animation Blend SystemsAnimation GraphsKeyframe AnimationMayaMotion CaptureMotion MatchingMotionbuilderRiggingRoot MotionUnreal Engine
3 Hours Ago
Remote
Canada
Internship
Internship
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Participate in a 15-week full-time software engineering internship in Vancouver, Burnaby, or Richmond. Build and ship product features, contribute code to Atlassian products, apply data structures and algorithms, and learn full-lifecycle development through mentorship and collaboration with senior engineers. Work may involve cloud initiatives and AI-driven features.
Top Skills: CC++JavaPython
5 Hours Ago
Easy Apply
Remote
Canada
Easy Apply
Senior level
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Own and evolve GitLab’s authorization systems across its Ruby on Rails monolith and next-generation Rust policy engine. Design fine-grained permissions for users, tokens, roles, and AI agents; secure GraphQL and REST APIs; lead feature-flagged rollouts and migrations; improve performance and reliability; and collaborate across authentication, platform, AI, and modular-service teams in a distributed asynchronous environment.
Top Skills: CedarGoGraphQLGrpcProtocol BuffersRestRubyRuby On RailsRustYamlZanzibar-Style Authorization

What you need to know about the Calgary Tech Scene

Employees can spend up to one-third of their life at work, so choosing the right company is crucial, not just for the job itself but for the company culture as well. While startups often offer dynamic culture and growth opportunities, large corporations provide benefits like career development and networking, especially appealing to recent graduates. Fortunately, Calgary stands out as a hub for both, recognized as one of Startup Genome's Top 100 Emerging Ecosystems, while also playing host to a number of multinational enterprises. In Calgary, job seekers can find a wide range of opportunities.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account