Skip to content

Open nowPosted 16 hours ago

Senior Security Engineer, Product

jito-labs4 open roles

Pay
$180,000 – $200,000 a year
Where
USA
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Engineer, Productjito-labs · USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on jito-labs's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 16 hours ago

The posting

ABOUT JITO

Jito builds the market layer of Solana: the execution, capital, and incentive infrastructure behind the network's onchain economy. That includes the validator client running the majority of Solana stake, BAM (a new framework for verifiable ordering, pre-execution privacy, and programmable blockspace), JitoSOL (the leading liquid staking token on Solana), and JTX (trading built directly on our own market infrastructure).

We are a lean, high-density team. Everyone here owns real surface area, works in the open, and ships at pace. The engineers on this team are the people market makers call when milliseconds matter.

About Jito

Jito builds the Market Layer of Solana: the execution systems, capital markets, and incentive mechanisms that power real markets on-chain.

Our products process billions in daily transaction value. The Jito-Solana validator client runs on the vast majority of Solana's active stake. BAM is redefining how blocks get built. JitoSOL is the leading liquid staking token on the network. We are not building at the margins. We are building core infrastructure that Solana's economy runs on.

Now we're moving up the stack, bringing that same infrastructure advantage to products that traders and users interact with directly.

We're a team of around 50 people with product-market fit across multiple product lines and years of runway. We take hard problems seriously and move fast on them. Nothing is out of reach.

About the Role

We've gone from one main product line to four, and the security work on those products has outgrown the one person doing it. This role owns product and protocol security: the surface where our code meets real money.

You'll report to the Head of Security and work alongside an Enterprise Security Engineer who owns internal infrastructure, identity and detection. The split is deliberate. They secure how we work; you secure what we ship.

This is an engineering role. Most of the backlog is code, not policy.

What You'll Own

- Product and protocol security reviews: threat modeling, secure design review, whitebox code review, and getting in early enough to change designs rather than document them

- Deployment hardening across our product lines, including the jito-solana deploy process

- Ongoing internal audits of our own products rather than waiting for an external engagement to surface issues

- Onchain monitoring: standing up tooling like Hypernative or Blockaid and building the detections that catch probing before an attack is underway

- Bug bounty operations as we bring more of the program in-house: triage, severity assessment, remediation tracking, and escalation

- Auditor findings driven through to closure: reviewed, prioritized, assigned, tracked

- AI-assisted security testing and continuous scanning, plus the security surface that comes with agents and AI tooling operating inside a codebase

- High-impact key and asset risks: key hygiene, hot wallet and engineering keys, multisigs, security councils

What We're Looking For

- A software engineering background is essential. You've built production systems, and that foundation shapes how you approach security.

- You've since moved into product security and are fluent across the lifecycle: threat modeling, secure design review, whitebox code review, and vulnerability testing

- 5+ years of professional experience, with a meaningful portion in software engineering before moving into security

- Proficiency in at least one systems or backend language. Rust preferred; Go, C++, or Python also work. You will read production codebases and build tooling as routine parts of this job.

- Demonstrated experience in product or application security, not solely infrastructure or compliance work

- A track record of building security tooling or automation from scratch

- Experience running or contributing to a bug bounty program, or a clear view of how you'd run one

- Genuine interest in AI security, including adversarial testing of agent controls

- Strong written communication. Findings nobody can act on are findings that don't get fixed.

- Comfortable with high ownership and working autonomously on a small team

- Experience in web3, crypto, or DeFi

Nice to Have

- Smart contract or onchain security experience, particularly on Solana or another SVM chain

- Experience with onchain monitoring tooling such as Hypernative or Blockaid

- Familiarity with validator or consensus infrastructure

- Experience with multisig schemes: signing policy design, quorum configuration, or key management in production

- Familiarity with hardware security modules: integration, key lifecycle, or operational use

- Exposure to trusted execution environments: attestation, confidential compute, or secure enclave design

- Experience with fuzzing, formal verification, or property-based testing of financial logic

Why This Role Exists

Security at Jito has been one person covering four product lines, an expanding AI surface, and a validator client running most of Solana's stake. That person has been spending their time on the most likely risks, which means the highest-impact ones get less attention than they deserve.

We're hiring two engineers so that ownership is distributed rather than bottlenecked, and so losing one person doesn't cost the whole function. The goal is not more approval steps. It is safer defaults, earlier input, and engineering that moves faster because security is in the room rather than at the gate.

HOW WE WORK

Remote-first, writing-heavy, and transparent by default: most decisions happen in public Slack channels, and everyone's voice carries. We value ownership, humility, curiosity, and getting it done over getting it perfect. Small egos, high standards.

WHAT WE OFFER

Competitive compensation including salary and token incentives, the tools you need to do your best work, and a seat at the center of Solana's market infrastructure alongside some of the strongest engineers in the ecosystem.

Jito is an equal opportunity employer. We evaluate candidates on the basis of their skills, experience, and potential contribution, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against jito-labs's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on jito-labs's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    jito-labs's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.