1

Blockchain Penetration Testing Jobs (NOW HIRING)

Senior Application Security Engineer

Meridian, ID ยท Remote

$111K - $152K/yr

Perform and support application security assessments, including penetration testing, vulnerability ... blockchain-based applications, or Web3 integrations. * You have an interest in agentic engineering ...

Senior Data Scientist

New York, NY ยท On-site

$110K - $125K/yr

... blockchain protocols, smart contracts, and decentralized applications through cutting-edge security ... penetration testing, on-chain monitoring, incident response, and compliance services for some of ...

... blockchain protocols, smart contracts, and decentralized applications through cutting-edge security ... penetration testing, on-chain monitoring, incident response, and compliance services for some of ...

IT Operations Specialist

New York, NY ยท Remote

$70K - $90K/yr

... blockchain protocols, smart contracts, and decentralized applications through cutting-edge security ... penetration testing, on-chain monitoring, incident response, and compliance services for some of ...

IT Operations Specialist

New York, NY ยท On-site +1

$70K - $90K/yr

... blockchain protocols, smart contracts, and decentralized applications through cutting-edge security ... penetration testing, on-chain monitoring, incident response, and compliance services for some of ...

Cybersecurity Engineer

Herndon, VA ยท On-site +1

$145K - $175K/yr

These factories deliver AI/ML Applications, Data Science Platforms, Blockchain and Microservices ... Lead vulnerability assessment, penetration testing support, and security engineering reviews

Cybersecurity Engineer

Herndon, VA ยท Remote

$145K - $175K/yr

These factories deliver AI/ML Applications, Data Science Platforms, Blockchain and Microservices ... Lead vulnerability assessment, penetration testing support, and security engineering reviews

... blockchain protocols, smart contracts, and decentralized applications through cutting-edge security ... penetration testing, on-chain monitoring, incident response, and compliance services for some of ...

Senior Data Analyst

New York, NY ยท On-site

$110K - $125K/yr

... blockchain protocols, smart contracts, and decentralized applications through cutting-edge security ... penetration testing, on-chain monitoring, incident response, and compliance services for some of ...

HR Business Partner

New York, NY ยท On-site

$70K - $90K/yr

... blockchain protocols, smart contracts, and decentralized applications through cutting-edge security ... penetration testing, on-chain monitoring, incident response, and compliance services for some of ...

... blockchain protocols, smart contracts, and decentralized applications through cutting-edge security ... penetration testing, on-chain monitoring, incident response, and compliance services for some of ...

Mobile Engineer

New York, NY ยท Remote

$125K - $250K/yr

Experience deploying smart contracts on Solana or integrating with blockchain based systems. * Background in security, threat modeling, or penetration testing, especially for consumer finance ...

Mobile Engineer

New York, NY ยท On-site

$125K - $250K/yr

Experience deploying smart contracts on Solana or integrating with blockchain based systems. * Background in security, threat modeling, or penetration testing, especially for consumer finance ...

Mobile Engineer

New York, NY ยท On-site +1

$125K - $250K/yr

Experience deploying smart contracts on Solana or integrating with blockchain based systems. * Background in security, threat modeling, or penetration testing, especially for consumer finance ...

Showing results 21-40

Blockchain Penetration Testing information

See salary details

$22.5K

$119.9K

$168.5K

How much do blockchain penetration testing jobs pay per year?

As of Aug 8, 2026, the average yearly pay for blockchain penetration testing in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed for blockchain penetration testing?

To thrive as a Blockchain Penetration Tester, you need a strong foundation in cybersecurity, cryptography, blockchain protocols (such as Ethereum and Bitcoin), and vulnerability assessment methodologies, often backed by a degree in computer science or a related field. Experience with tools like Metasploit, Burp Suite, smart contract auditing tools (e.g., MythX, Slither), and certifications like CEH or OSCP are highly valued. Critical thinking, meticulous attention to detail, and effective communication are essential soft skills for explaining complex findings and collaborating with development teams. These combined skills are crucial for identifying vulnerabilities in blockchain systems and ultimately safeguarding digital assets and company reputation.

What is blockchain penetration testing?

A Blockchain Penetration Testing job involves assessing the security of blockchain networks, smart contracts, and related applications by simulating cyberattacks. Professionals in this role identify vulnerabilities, test defenses, and provide recommendations to mitigate risks. They use ethical hacking techniques to uncover weaknesses in consensus mechanisms, private keys, and decentralized applications (DApps). Their goal is to ensure blockchain systems remain secure against real-world threats.

What are the typical challenges faced by professionals in blockchain penetration testing?

Professionals in Blockchain Penetration Testing often grapple with rapidly evolving technology, complex decentralized architectures, and the emergence of new attack vectors unique to blockchain ecosystems. Testing smart contracts requires a deep understanding of not only blockchain coding languages, such as Solidity, but also intricate business logic that can introduce subtle vulnerabilities. Staying current with the latest threats and collaborating closely with blockchain developers and security teams are essential parts of the job. These challenges make the work intellectually demanding and highly rewarding for those who enjoy continuous learning in a cutting-edge field.

More about Blockchain Penetration Testing jobs
What cities are hiring for Blockchain Penetration Testing jobs? Cities with the most Blockchain Penetration Testing job openings:
What are the most commonly searched types of Blockchain Penetration Testing jobs? The most popular types of Blockchain Penetration Testing jobs are:
What states have the most Blockchain Penetration Testing jobs? States with the most job openings for Blockchain Penetration Testing jobs include:
Infographic showing various Blockchain Penetration Testing job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 10% Part Time, 4% Contract, and 1% Nights. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Senior Application Security Engineer

MoonPay

Meridian, ID โ€ข Remote

$111K - $152K/yr

Full-time

This job post hasย expired today.ย Applications are no longer accepted.


Job description

About MoonPay


Hi, weโ€™re MoonPay. Weโ€™re here to onboard the world to the decentralized economy by making digital money move as universally and effortlessly as the internet.


Why?


Because crypto, stablecoins and blockchain arenโ€™t just technologies. Theyโ€™re tools for global financial empowerment. They give people and businesses more control over their money, their digital assets, and their future, opening access to legacy financial systems that have been out of reach for many.


What we do

MoonPay is a unified payments platform for digital currency. We make it easy for anyone, anywhere, to buy, sell, swap and pay in digital currencies as easy as sending an email. That simplicity is intentional, our focus is reducing complexity so people can participate confidently, without needing to be crypto experts. We power the entire flow between fiat and crypto end to end, with compliance, identity checks, fraud prevention, and settlement all built in. This end-to-end approach reflects how we work internally: with accountability, rigor, and trust built into everything we ship.


Proven at scale


Trusted by over 30 million customers and over 500 ecosystem partners, our secure, enterprise-grade platform is driving mainstream crypto adoption worldwide. Behind those numbers are millions of real people and organizations relying on MoonPay every day.


We collaborate with innovative brands and projects to build secure, scalable solutions for a blockchain-powered future. This is an opportunity to help shape systems, not just scale them. And weโ€™re committed to doing it right. Fully licensed in the U.S. and regulated across the UK, EU, Canada, and Australia, because trust and compliance are non-negotiable.


But weโ€™re just getting started. Weโ€™ve launched a consumer app that makes crypto accessible, intuitive, and usable for everyone, and itโ€™s growing fast. Weโ€™re iterating every day to make it the best it can be.


If you believe financial freedom should be for everyone. If you believe in building a fairer, more open financial system - we want you with us. To build systems that benefit all, we need contributions from all, regardless of background.


Come build the future of payments and the decentralized economy with MoonPay. Letโ€™s make financial freedom and autonomy the new normal.


Locations Supported
  • US

  • Canada (Toronto)

  • Mexico

Relocation available:No

Work pattern:

  • This role will be remote.

About the Opportunity

Write a clear, high-level overview of the role, outlining its purpose, scope, and impact on the team and wider organisation.

Our SRE/Cloud Security teams are a dynamic blend of proactive defenders and inquisitive problem-solvers. We are dedicated to strengthening our systems through rigorous security reviews and hands-on penetration testing, and we actively manage our Bug Bounty program to ensure timely validation, response, and remediation. 

We leverage cutting-edge tools and techniques to build robust defenses, and collaboration is central to how we work; embedding security best practices throughout the SDLC. We continuously research emerging threats, develop effective mitigation strategies, and empower engineering teams through clear guidance and practical security training. 

We maintain up-to-date security standards and documentation, lead incident response efforts with precision, and are passionate about spreading a secure-by-design culture while contributing to the wider security community. 

What You Will Do

A concise and detailed breakdown of core responsibilities, day-to-day expectations, and key deliverables. Use 5โ€“10 bullets max. 

  • Conduct threat modelling reviews of Technical Design Documents (TDDs) for new and existing features, providing clear, actionable security recommendations early in the design process. 

  • Perform and support application security assessments, including penetration testing, vulnerability assessments, and proof-of-concept (PoC) development where appropriate. 

  • Investigate, triage, and respond to Bug Bounty program submissions, validating findings and working with engineering teams to drive timely remediation. 

  • Own and continuously improve application-layer protections, including managing and tuning Cloudflare WAF and related security controls.

  • Partner closely with engineering teams to embed security best practices throughout the SDLC, from design and development through deployment and maintenance. 

  • Research and track emerging threats and vulnerabilities, translating findings into practical mitigation strategies relevant to our technology stack. 

  • Develop and deliver security guidance, training, and awareness for engineering teams to raise the overall security maturity of the organization.

  • Contribute to the creation, maintenance, and evolution of security standards, processes, and documentation.

  • Participate in and eventually lead incident response activities, supporting investigation, containment, remediation, and post-incident improvements. 

About You

Describe the ideal candidateโ€™s qualifications, skills, experience, and behaviours that show strong culture alignment.

Must-have experience and skills

  • You have developed a breadth of experience across multiple security domains, including web and mobile application security, infrastructure and cloud security, and can connect these areas to drive a holistic security approach. 

  • You have hands-on experience performing white-box, source code-assisted web and mobile application penetration testing, from vulnerability discovery through triage and exploitation. 

  • You have the ability to read, understand, and review source code to identify security issues, with ideally, a particular focus on JavaScript and TypeScript codebases.

  • You have a strong understanding of Threat Modelling principles and their practical application to the secure software development lifecycle (SDLC).

  • You have experience working with web application firewalls to help protect applications, assess coverage, and support tuning rules to mitigate common attack patterns. 

  • You have experience embedding application security practices into CI/CD pipelines, enabling early detection of vulnerabilities and close collaboration with engineering teams throughout the development lifecycle. 

  • You have collaborated closely with engineering teams to clearly communicate security findings, explain vulnerabilities, attack paths, and mitigations, and support the implementation of effective fixes for both technical and non-technical audiences. 

  • You are self-motivated, proactive, and take strong ownership of your work, operating effectively in a remote environment while maintaining a collaborative, team-focused mindset. 

Nice-to-have experience

  • You have experience in JavaScript and TypeScript, including the ability to read, understand, and reason about modern web application codebases. 

  • You have experience working with Cloudflare, including its hosting and Web Application Firewall (WAF) capabilities, to help secure and operate internet-facing applications. 

  • You have experience testing and securing GraphQL, REST APIs, including understanding common GraphQL/REST-specific attack vectors and security considerations. 

  • You have experience or a strong interest in Web3 security testing, including assessing smart contracts, blockchain-based applications, or Web3 integrations. 

  • You have an interest in agentic engineering, including emerging patterns in autonomous systems, tooling, or workflows, and their security implications. 

Bonus Points

Optional extras that would help a candidate stand out (keep this short).

  • You contribute or have contributed to the security community through open source involvement, participation in CTFs, or speaking at local information security meetups and conferences. 

  • Your background includes experience working with disruptive technologies and successfully launching products, ideally within FinTech, SaaS, or Crypto. 

  • You hold one or more security relevant certifications such as OSCP or OSWE. 

\\n


\\n

BLOCK Values


Weโ€™re looking for people who live our core values, those who strive for excellence and want to leave a lasting legacy on the global financial system. Our values:


B - Be Hungry

L - Level Up

O - Own It

C - Crypto Curious

K - Kaizen


Research has shown that women are less likely than men to apply for this role if they do not have experience in 100% of these areas. Please know that this list is indicative, and that we would still love to hear from you even if you feel that you are only a 75% match. Skills can be learnt, diversity cannot.


Benefits & Perks


Competitive salary package


Equity package: We believe financial freedom starts with our employees, so all employees have ownership at MoonPay


Pay for performance equity bonus: Those who drive outsized outcomes receive outsized rewards


Moonshot award. We honor exceptional impact - 10 employees twice a year, each earning a $250,000 equity grant.


Unlimited holidays: We give you the autonomy to choose when to work (and when to switch off)


Hybrid working schedule: Work fully remotely or your nearest Moonbase, the choice is yours


Private Healthcare benefits: To protect you and your loved ones


Enhanced parental leave: So you can spend more time with your loved ones without a second thought


Annual training budget: We support your training journey every step of the way


Home office setup allowance: Create the home office of your dreams


Remote working allowance: Those working fully remotely get a little extra for utilities


Monthly budget to spend on our products and zero fee crypto transactions: Cultivate your inner DEGEN


Employee referral programme: Great people know great people, refer them to receive 10K in USDC


โœˆ๏ธ Regular remote company offsites: Meet your colleagues regularly for high impact in person sessions and hackathons


Working in a disruptive and fast-growing company where excellence is rewarded




Commitment To Diversity


At MoonPay we believe that every voice matters. We strive to create a mindful and respectful environment where everyone can bring their authentic self to work, and experience a culture that is free of harassment, racism, and discrimination. Thatโ€™s why we are committed to diversity and inclusion in the workplace and are a proud equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status or any other characteristic protected by law. This policy applies to all employment practices within our organization, including, but not limited to, hiring, recruiting, promotion, termination, layoff, and leave of absence.


MoonPay is also committed to providing reasonable accommodations in our job application procedures for qualified individuals with disabilities. Please inform our Talent Team if you need any assistance completing any forms or to otherwise participate in the application process.