Senior Application Security Engineer
MetaMask · UNITED STATES - Remote, EMEA - Remote
- Senior
- Full-time
- $130,000 – $218,000
- Posted 2026-03-30
- Confirmed live on 25 September 2026
Job description
Please note that we are unable to consider applications from candidates based in France, Italy, or Germany for this role.
Money is moving onto the internet, and the shift has a name: Open Money. This is money that is open, portable, agentic, and owned by you. MetaMask spent the last ten years building it; with 100M+ downloads, users in ~190 countries, and trillions in cumulative transaction volume, it's the most trusted self-custodial financial platform on the internet. Now we're building the operating system for your money: one place to hold, move, grow, and use anything you own. Join a remote-first, global team rebuilding how money works: a problem that touches everyone, every day.
About MetaMask
We’re building for a future where the internet and world economy empowers people through interactions based on consent, privacy, and free association. Where both communities and individuals flourish. To accomplish that, we’re working hard to make web3 accessible for everyone around the world.
MetaMask is both a crypto wallet and a gateway to the decentralized web. Our tools help people create communities, play video games, access financial services, make payments, invest in assets, protect against economic turmoil, and more. Our browser extension and mobile platforms meet the needs of millions of users and developers across the world.
Originally a humble key manager, today MetaMask serves over 30 million monthly active users as a decentralized application development platform, an aggregator of decentralized cryptocurrency exchanges, and a decentralized identity manager.
About the Role
MetaMask has experienced explosive user growth over the past year as a cryptographic key manager and web3 application development platform. As this user base continues to grow, an immense amount of trust is being placed in MetaMask as a tool that manages and wields their digital authority, controlling assets, identities and more. It is of highest importance to us that we keep our users as safe and secure as possible.
We are looking for a Senior Application Security Engineer to join our rapidly growing security team to help embed security into all phases of the software development lifecycle. You would work closely with development teams and product managers to ensure MetaMask products are designed and implemented to the highest security standards. Consenys’s application security team primarily supports MetaMask with opportunities to expand to additional products in the Consensys family.
To apply for this position, you must have:
• 6+ years of experience building and securing software, including hands-on product or application security experience.
• Experience securing modern backend systems, web applications, and APIs.
• Experience performing threat modelling, security design reviews, and vulnerability assessment.
• Experience securing JavaScript-based applications across web and/or mobile (Node.js, React, React Native preferred).
• Strong coding skills, with the ability to work directly with engineers to identify and fix vulnerabilities or build secure solutions.
• Familiarity with Blockchain technology (particularly Ethereum), Decentralized Applications and crypto wallets
• Solid understanding of the modern web and mobile security landscape, including common attack vectors and mitigations.
• Strong communication skills, with the ability to influence engineering decisions and collaborate effectively in a remote environment.
• Self-driven and proactive, comfortable operating in a high-autonomy, distributed team.
• Alignment with our mission and values.
Timezone: Most timezones will work. Regardless of where you are, some overlap with EU and US-Pacific time zones will be necessary.
Nice to have:
• Experience working as a software developer.
• Deep knowledge of Ethereum (and other blockchains), Decentralized Applications and crypto wallets.
• Knowledge of smart contract implementation and security.
• You’re a MetaMask user!
Responsibilities
• Determine the root cause and severity of vulnerabilities reported to us through our bug bounty platform.
• Interface with ethical hackers, triage reports, and guide product engineering teams to resolution.
• Document identified vulnerabilities in a way that allows for our engineering team to take quick action.
• Write code to support the development of security engineering projects, or fix vulnerabilities in MetaMask client applications. This includes the development of AI tooling for vulnerability determination and resolution in order to keep pace with the changing AI-powered vulnerability detection landscape.
• Assess potential security vulnerabilities within our applications, and work with development teams to ensure remediation in our established SLAs.
• Support product teams as they develop new features by conducting design reviews, threat modeling, security testing, and code reviews.
• Identify gaps in MetaMask’s secure software development life cycle (SSDL
Prepare for the interview
Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.
More at MetaMask
- Risk & Controls Manager · UNITED STATES - Remote, LATAM - Remote, EMEA - Remote
- Lead Product Designer · UNITED STATES - Remote, EMEA - Remote, CANADA - Remote, LATAM - Remote
- Senior HRIS Administrator II · UNITED STATES - Remote, CANADA - Remote, LATAM - Remote
- Product Marketing Lead - Trade · UNITED STATES - Remote, EMEA - Remote, LATAM - Remote
- Staff UX Motion Designer · UNITED STATES - Remote, CANADA - Remote, LATAM - Remote
- Senior Design Engineer - MetaMask · United States - Remote, EMEA - Remote