About the company
*Scroll has a remote-first work culture, our staff base is globally distributed and we are location agnostic. We make hiring decisions based on talent, culture fit and role suitability. If you have the skills and experience requested by this job description then please APPLY! At Scroll, we operate on the bleeding edge of a fast-moving frontier of zk technology, research and innovation. The Application Security Engineer will be responsible for improving the zkEVM-based zkRollup security, ensuring that Scroll is one of the safest Layer 2’s for projects and users. The role is ideal for an individual who thrives in a start-up environment, a self-starter that is dynamic and comfortable to take on responsibilities and can work effectively within a remote setup.
Job Summary
Responsibilities:
📍Establish and maintain security best practices, policies, and procedures across the organization 📍Develop and implement the overall security strategy for Scroll's infrastructure, including the node operations, cloud instances, onchain activities, and associated systems 📍Oversee the bug bounty program, including final decision-making on bug severity and rewards 📍Lead security incident response and coordinate with relevant teams during critical situations 📍Lead security reviews of major protocol upgrades and new feature implementations, and coordinate the audit process with external security vendors and audit firms 📍Work closely with engineering team to ensure security is built into the development lifecycle from the ground up 📍Build and maintain relationships with external security researchers, auditors, and the broader security community 📍Represent Scroll's security initiatives in the broader blockchain community through speaking engagements and technical content
Requirements:
📍5+ years of experience in blockchain security, with experience in a leadership role 📍Knowledge of Solidity, EVM, Layer 2 scaling solutions, and blockchain 📍Experienced in security standards, tools, key management, and cloud security 📍Proven track record of building and leading security teams in a fast-paced environment 📍Proven ability to communicate complex security concepts to both technical and non-technical stakeholders 📍Excellent project management skills and ability to coordinate multiple security initiatives simultaneously