Institute of Free Technology hiring Application Security Engineer • Remote (Work from Home) | Himalayas
Institute of Free TechnologyIT

Application Security Engineer

The Institute of Free Technology (IFT) is a mission-driven tech startup studio that supports the development of open-source projects focused on safeguarding civil liberties in the digital age. They provide financial, technical, legal, and operational support to a portfolio of projects including Status, Logos, and Waku.

Institute of Free Technology

Employee count: 201-500

About Vac:

Vac builds public good protocols for the decentralised web. We do applied research based on which we build protocols, libraries and publications.

Vac’s R&D Service Units are integral to supporting IFT (The Institute of Free Technology) projects by researching and developing base components and secure, unbiased protocols.

The Vac Security service unit provides comprehensive support to IFT projects by conducting security audits and helping develop robust security plans. In addition to assisting IFT projects, the security team also supports other IFT services by offering expert guidance on security best practices and risk management strategies. This collaborative approach ensures that all aspects of the IFT ecosystem benefit from enhanced security measures.

By identifying potential vulnerabilities, assessing risks, and implementing effective security solutions tailored to specific needs, the Vac Security service unit plays a crucial role in strengthening the overall security posture of IFT.

The role:

We are looking for an Application Security Engineer to join our security service unit. In this role, you’ll perform in-depth reviews of critical code (with a focus on low-level languages like Rust, Nim, and C++), identify both code-level and protocol-level vulnerabilities, and support incident response efforts.

You’ll collaborate closely with development teams to remediate security issues and ensure best practices are followed. You’ll also play a key role in preparing for external security audits—defining audit scope, organising technical documentation, and working directly with auditors to ensure valuable and actionable results.

This is a hands-on position for someone passionate about secure software development and proactive risk mitigation.

Key responsibilities:

  • Perform in-depth manual and automated reviews of source code (with a focus on low-level languages such as Rust, Nim, and C++) to identify security vulnerabilities and logic flaws.
  • Analyse and review critical code paths for potential weaknesses.
  • Identify and assess both code-level vulnerabilities (e.g., buffer overflows, injection flaws) and protocol-level issues (e.g., insecure cryptographic implementations, protocol misconfigurations).
  • Execute incident response activities, including detection, analysis, containment, and recovery, while documenting findings and lessons learned for continuous improvement.
  • Collaborate with development and product teams to remediate identified vulnerabilities, provide security guidance, and ensure secure coding practices are followed.
  • Define clear audit objectives and scope for external audits, focusing on the most critical components and protocols.
  • Prepare and organise all relevant documentation (architecture diagrams, codebase, threat models, protocol specifications) to facilitate an efficient and valuable external audit process.
  • Engage with external auditors early to clarify expectations and provide necessary context, ensuring the audit delivers actionable results.
  • Address and remediate issues identified in previous audits, and document improvements to demonstrate ongoing security maturity.

You ideally will have:

  • Minimum of 5 years of experience in Web3 security engineering, with proven experience securing blockchain protocols, smart contracts, or cryptographic systems.
  • Proficiency in low-level programming languages (Rust, Nim, C++).
  • Expertise in secure coding practices, including identification of code/protocol-level vulnerabilities (e.g., buffer overflows, injection attacks) and code analysis/debugging.
  • Experience with manual/automated code review techniques and penetration testing in Web3 ecosystems.
  • Familiarity with cryptographic protocols, secure protocol design, and blockchain/distributed systems security.
  • Incident response capabilities (detection, analysis, containment, recovery).
  • Experience collaborating with development/product teams to remediate vulnerabilities, including SSDLC processes and external audit preparation.
  • Strong documentation and communication skills for technical materials and stakeholder interactions (internal teams, auditors).
  • Deep interest in blockchain technology and decentralisation.

Bonus points:

  • Experience with static and dynamic analysis tools (e.g. CodeQL, Valgrind).
  • Knowledge of formal verification methods and tools.
  • Background in penetration testing or red teaming.
  • Ability to educate and train others on security best practices.
  • Contributions to open-source security projects or published security research.

Hiring process:

  • Interview with our POps team.
  • Interview with the Vac Security unit lead.
  • Take home assignment + discussion with a team member from the Vac Security unit.
  • Interview with a Vac team lead.

Compensation:

We are happy to pay in any mix of fiat/crypto.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level

Location requirements

Open to candidates from all countries.

Hiring timezones

Worldwide

About Institute of Free Technology

Learn more about Institute of Free Technology and their company culture.

View company profile

We are the Institute of Free Technology (IFT), a mission-driven tech startup studio that emerged from Status, which we, Jarrad Hope and Carl Bennetts, founded in 2017. Our initial goal with Status was to enable the free flow of information and protect the right to private, secure conversations. However, as we delved deeper, we recognized gaps in the existing infrastructure needed to fully realize these values. This realization led to an expansion of our project's scope and ultimately, the formation of IFT and the startups it now incubates. Our core mission is to support the development, adoption, and accessibility of solutions to digital age problems. We are guided by a strong set of principles: liberty, censorship resistance, security, privacy, and inclusivity. We actively seek to connect with and support innovators who are dedicated to defending our digital rights.

At IFT, we provide comprehensive support to take ideas from the drawing board to market. This includes financial backing, technical expertise, legal guidance, people operations, and brand-building assistance at every stage. We empower our startups to concentrate on their core strength: building public goods designed to safeguard civil liberties in the digital age. Our portfolio of open source projects is continually growing and currently includes prominent names like Status, Logos, Codex, Waku, Nimbus, Nomos, and Keycard. As a team, IFT has been completely distributed since its inception. We boast a strong core of over 220 contributors from diverse backgrounds, spread across the globe. We are deeply passionate about open source, and our organizational structure reflects this with minimal hierarchy and no fixed work hours. We champion a high degree of autonomy, encouraging our team members to work independently while aligning with the organization's overarching priorities.

Employee benefits

Learn about the employee benefits and perks provided at Institute of Free Technology.

View benefits

Co-working space

Access to co-working spaces is provided.

Unlimited vacation

We offer unlimited vacation to our contributors.

Entirely remote

Our team is completely distributed since inception.

Flexible working hours

Our organizational structure has minimal hierarchy and no fixed work hours.

View Institute of Free Technology's employee benefits
Claim this profileInstitute of Free Technology logoIT

Institute of Free Technology

Company size

201-500 employees

Founded in

2017

Chief executive officer

Jarrad Hope, Carl Bennetts

Employees live in

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

9 remote jobs at Institute of Free Technology

Explore the variety of open remote roles at Institute of Free Technology, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Institute of Free Technology

Remote companies like Institute of Free Technology

Find your next opportunity by exploring profiles of companies that are similar to Institute of Free Technology. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 85,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan