← Back to results

Protocol Security Engineer

Join Matter Labs as a Protocol Security Engineer to protect ZKsync's core and enhance security in blockchain systems.

Location
Global Remote
Compensation
Not disclosed
Level
mid
Type
full time · Remote

Posted by employer 2 weeks ago

First seen on Joblaze 1 week ago

Last verified on the company career page 1 day ago

Apply at Matter Labs → Save job Scanned from matter-labs.io

Skills & Technologies

AI in the day-to-day

Apply modern AI systems to scale security work, while accounting for attackers using the same tools.

Not disclosed in this posting: compensation, years of experience, visa sponsorship.

Benefits

Equity/Stock Options Remote Work

Joblaze summary

In this role, the Protocol Security Engineer at Matter Labs focuses on safeguarding the core components of ZKsync, including smart contracts and blockchain nodes, through proactive threat modeling and security reviews. The position requires expertise in security engineering, particularly in threat modeling and vulnerability research, along with proficiency in strongly typed languages like Rust and Solidity. Ideal candidates are experienced professionals who can navigate complex distributed systems and have a solid understanding of blockchain security incidents. Matter Labs fosters a culture of ownership and innovation, encouraging team members to influence security practices across developme

Joblaze insights

Quick facts

Is the Protocol Security Engineer role remote?
Yes — Matter Labs lists this as a fully remote position.
What's the tech stack?
Joblaze extracted these technologies from the posting: Blockchain, Rust, Solidity, Zero-knowledge proofs.
What seniority level is this role?
Matter Labs targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Protocol Security Engineer role at Matter Labs.

From the original posting

About Matter Labs

Matter Labs builds private settlement infrastructure that lets regulated institutions settle directly with each other without exposing data, ceding control, or waiting days. Global finance moves $4 quadrillion a year on systems designed for paper and telex. The institutions that built them - from clearing houses to exchanges to the world's largest banks, institutions are now actively replacing them.

Our core product, Prividium, gives each institution its own private settlement environment (a Prividium Zone) with independent governance and built-in interoperability across counterparties, asset classes, and jurisdictions. Settlement happens through zero-knowledge proofs: one party proves a transaction is valid without revealing any underlying data to the counterparty. The only private settlement infrastructure built on zero-knowledge cryptography.

Founded in 2018. Backed by a16z and Union Square Ventures. A fully remote team of around 70 with eight years of production zero-knowledge infrastructure behind us, now pointed at the biggest problem in institutional finance.

The role

You will protect ZKsync's core: smart contracts, ZK circuits, and blockchain nodes. Your reviews, threat models, and incident work decide whether vulnerabilities are found by us or by attackers. The role owns internal security reviews of critical components, threat modeling, adversary research, and the security side of incident response, and it carries broad license to spot gaps and fix them beyond any assigned list. It is a hands-on individual contributor role for someone who wants to know how things break and applies that instinct ethically where the stakes are high.

What you'll do

  • Break things on purpose. Threat-model and review Solidity contracts, blockchain state transition functions in Rust, and other critical systems before an attacker gets the chance.

  • Own protocol components. Take responsibility for the secure architecture and implementation of the components you adopt, from design review through production.

  • Track the adversary. Follow hacks, exploits, and new attack vectors across the industry and convert the lessons into concrete improvements in our systems.

  • Scale security through others. Embed secure-design practice across development teams and influence architecture decisions early, without formal authority.

  • Use AI on defense. Apply modern AI systems to scale security work, while accounting for attackers using the same tools.

  • Respond when it counts. Join security investigations and incident response, often under time pressure with incomplete information.

What we look for

Each of these is a demonstrated capability, shown through work you have done:

  • A record in security engineering or security research: threat modeling, security-focused code review, or vulnerability research on production systems, with findings you can walk through mechanism by mechanism.

  • Proficiency in strongly typed languages such as C++, Go, or Scala. Rust and Solidity are our primary languages, and prior experience with them is not required.

  • Deep grounding in algorithms and data structures, including their computational and memory complexity, with experience implementing them from scratch.

  • Protocol-level debugging and root-cause analysis on complex distributed systems.

  • Working knowledge of recent security incidents in the blockchain space and the prevention techniques behind them.

  • Clear written and spoken English, the company's working language.

If you meet most of these and believe you can do this job, apply anyway.

Nice to have

Hands-on experience with Solidity smart contracts, ZK circuits, or core blockchain protocols. Public security research, audit reports, bug-bounty results, or CTF history all count as evidence.

Work model & pay

  • Competitive base salary. Matter Labs applies no geographic pay discounts.

  • Performance-based variable compensation with a defined annual target is additional. The plan may pay in ZK tokens or cash. A long-term token incentive is also additional and is paid in ZK tokens, with new-hire grants vesting over four years and a one-year cliff.

  • Fully Remote. Occasional travel to team gatherings and industry events.

  • Freedom & ownership culture: no time tracking (where legally applicable), minimum bureaucracy-only results matter.