Protocol Security Engineer

Location

Remote (US or EU, up to GMT+2 to ensure sufficient overlap with the rest of the team).

Role

The mission of this role is to make Morpho's protocol safer and faster to ship by owning the security lifecycle end-to-end: from formal verification and smart contract audits to bug bounty program management. As the protocol team scales and takes on more complexity, this person reduces risk and shortens audit cycles so the team can move with confidence.

Responsibilities

  • Apply formal verification methods to Morpho's smart contracts using tools like Certora to prove protocol invariants and catch bugs before audit.

  • Conduct thorough security reviews of smart contracts developed internally, identifying critical vulnerabilities before they reach production.

  • Own the bug bounty program end-to-end: triage incoming reports, communicate with security researchers, validate findings, and coordinate war rooms when needed.

  • Develop periphery smart contracts that extend Morpho's protocol in a safe and auditable way.

  • Research emerging attack vectors, new bug classes, and evolving security tooling to keep Morpho's practices at the frontier.

  • Represent Morpho at security-focused conferences, meetups, and in published articles or research writeups to strengthen the protocol's credibility in the security community.

What Success Looks Like

First 30 days

Built a deep working knowledge of Morpho v1 and Vault v2. Started implementing formal verification rules using Certora on existing contracts. Got familiar with how the protocol team works and ships.

First 4 months

Reached complete command of Morpho v1 and v2. Independently formulates and implements the most important invariants across the contracts. Leads the weekly Morpho call with Certora. Owns triage and validation of the smart contract bug bounty program.

In 1 year

Makes meaningful security contributions that measurably reduce Morpho's attack surface. Identifies new attack vectors, shares security best practices across the protocol team, and helps speed up audit cycles so the team ships faster without cutting corners.

Must-have Experience & Skills

  • Master's degree in Computer Science, Cybersecurity, Software Engineering, or a related field, or equivalent depth of knowledge.

  • 3+ years of experience in smart contract auditing, with a proven track record of identifying critical vulnerabilities.

  • Deep knowledge of the Ethereum Virtual Machine, Solidity, and the broader blockchain ecosystem.

  • Hands-on experience with formal verification tools (Certora or equivalent).

  • Strong written and verbal communication skills: able to write a clear vulnerability report as well as a research article.

  • Genuine interest in DeFi and lending protocols specifically.

  • Comfortable operating in a fast-moving, async-first environment where priorities shift and ambiguity is normal.

  • Strong ownership and autonomy: identifies what needs to be done and does it, without waiting to be managed.

  • Clear and crisp async communication: writes well and shares context proactively across time zones.

  • Team-first mindset: treats the protocol's safety as a shared mission, not a personal agenda.

  • Humble.

Perks & benefits

We design benefits around deep work and growth, so you can do the best work of your career. Expect fair, top-tier compensation, real flexibility, time together in Paris, great health coverage, and support to keep learning.

Equal opportunity

We welcome applicants from all backgrounds and hire based on talent, potential, and values alignment.

Ready to shape the future of finance?

Apply hereApply here