Application Security Engineer
Polygon Labs
AI Summary
The vacancy is well-structured with clear responsibilities and company information, but lacks specific salary details.
Check Match โ Just drop your CV
See your fit for Application Security Engineer in seconds.
Description
About Polygon Labs
Polygon Labs is a global blockchain payments company building and operating infrastructure to move money instantly, reliably, and at internet scale, with the mission to move all money onchain. It is building the Polygon Open Money Stack, an open and integrated stack of services and technologies to instantly and reliably move money anywhere, and put it to work. Its infrastructure has facilitated trillions of dollars in onchain value transfer and supported millions of transactions daily for some of the globe's largest banks, fintechs, enterprises, and consumer applications.
Your Responsibilities
- โขOwn end-to-end security reviews across smart contracts (Solidity), backend services (Go, TypeScript, Python), and frontend surfaces, producing written findings at the quality level of a top external audit firm, published and used as the internal standard
- โขBuild and ship an agentic security CI/CD pipeline: agent-driven review that runs autonomously against every PR and release candidate, reasons about changes in context, and gets smarter with each deployment
- โขDesign and maintain specialised AI-powered code reviewers tuned to specific vulnerability classes and surfaces, Solidity-aware, protocol-aware, and calibrated to the actual patterns Polygon's products surface
- โขTriage and manage the bug bounty program: read incoming submissions daily, reproduce valid findings, separate signal from noise, assign severity, and route confirmed issues to engineering with enough context to fix them correctly, using custom AI workflows to maintain rigor at volume
- โขFollow through on remediation: review proposed fixes, close out resolved findings, and push back where a fix addresses symptoms rather than root cause
- โขEmbed across engineering teams at all stages, sprint planning, design review, feature freeze, post-launch, as a working partner, not a sign-off function
- โขLead the team's AI security practice by example: build custom prompt chains, Claude Code workflows, and Codex integrations tailored to specific security tasks, then demo and share them so the whole team's baseline rises
Polygon Labs Perks
The goal of the Polygon Labs total rewards program is to support the health and well-being of you and your family. Our comprehensive compensation plan includes the following benefits for our full time employees
- โขRemote first global workforce
- โขIndustry leading Medical, Dental and Vision health insurance*
- โขCompany matching 401k with 3% match*
- โข$1,500 Home Office Set Up Allowance (life-time max)
- โข$200 Annual AI Allowance Program
- โข$75 Monthly internet or phone reimbursement
- โขFlexible Time Off
- โขCompany issued laptop
- โขEgg freezing, mental health, and employee wellness benefits
*In certain countries medical, dental and vision is fully covered for employees & their dependents. This is country and plan specific. *401k is for United States employees only.
Requirements
What You'll Need
- โขFull-stack security fluency across multiple languages: you can drop into an unfamiliar codebase and produce a meaningful review within a day, Solidity, Go, TypeScript, and Python are the surfaces that matter most here
- โขSmart contract security as a core competency: production experience auditing or building secure Solidity, deep familiarity with EVM internals, common DeFi protocol patterns, and the historical record of smart contract exploits
- โขProven AI workflow depth, not just tool usage: you have built custom prompt chains, CI integrations, and task-specific plugins (using tools like Claude Code and Codex) for security work specifically, and you can speak clearly about where AI accelerates and where human judgment is irreplaceable
- โขExperience making security decisions under real time pressure in a Web3 environment, where speed and rigor have to coexist
- โขA public portfolio that demonstrates your security thinking: audit reports, bug bounty writeups, research posts, or open-source tooling, something that shows what good looks like when you put your name on it