Job Description
- Description
- Lead Security Engineer (Web3 Wallet/DeFi) at Binance Holdings Limited is a critical role responsible for safeguarding the integrity, confidentiality, and availability of Binance’s Web3 wallet infrastructure and decentralized finance (DeFi) products, which serve over 300 million users globally. This position directly contributes to maintaining user trust by preventing exploits, securing smart contract interactions, and ensuring the resilience of Binance’s expanding Web3 ecosystem against evolving blockchain-specific threats.
- The role involves leading security initiatives for Binance’s Web3 wallet and DeFi offerings, including threat modeling, vulnerability assessment, secure code review, penetration testing, and incident response tailored to blockchain environments. You will collaborate with product, engineering, and blockchain research teams to embed security into the software development lifecycle (SDLC) from design through deployment, ensuring compliance with industry standards and Binance’s internal security frameworks.
- Day-to-day responsibilities include conducting architectural security reviews of smart contracts (Solidity, Rust, Move), evaluating cross-chain bridge mechanisms, analyzing transaction flows for front-running, reentrancy, and oracle manipulation risks, and developing automated security scanning tools for dApp integrations. You will also lead red team exercises simulating real-world attack vectors on Web3 interfaces, advise on secure key management practices (HSM, MPC, threshold signatures), and contribute to Binance’s bug bounty program by validating and prioritizing external security reports.
- You will mentor junior security engineers, establish security best practices for Web3 development, and drive adoption of formal verification techniques and static/dynamic analysis tools specific to blockchain protocols. Regularly, you will produce security advisories, contribute to Binance’s security blog, and represent the company in industry forums focused on DeFi security and wallet safety.
- The Web3 Wallet and DeFi team at Binance operates at the forefront of blockchain innovation, building non-custodial wallet solutions, decentralized exchange (DEX) aggregators, yield aggregators, and NFT infrastructure that empower users with self-custody and access to global DeFi markets. This team is part of Binance’s broader Security Organization, which employs a defense-in-depth strategy across centralized and decentralized services, leveraging threat intelligence, behavioral analytics, and zero-trust principles to protect user assets.
- Binance’s security culture emphasizes proactive defense, continuous learning, and collaboration across global teams in Asia, Europe, and the Americas. As a leader in this role, you will have the opportunity to shape the security posture of one of the most widely used Web3 wallets in the world, influence industry standards for DeFi safety, and gain deep expertise in emerging blockchain security challenges such as MEV mitigation, social attack vectors, and post-quantum cryptography readiness.
- In this role, you will achieve mastery in blockchain security domains including smart contract auditing, cross-chain protocol security, wallet key management, and decentralized identity (DID) risks. You will also develop leadership skills by guiding a multidisciplinary team, influencing product security roadmaps, and contributing to Binance’s mission of building an open, secure, and inclusive financial ecosystem powered by blockchain technology.
- Requirements
- 5+ years of hands-on experience in application security, penetration testing, or blockchain security, with proven expertise in Ethereum Virtual Machine (EVM) and non-EVM smart contract languages (Solidity, Rust, Move).
- Deep understanding of Web3 attack surfaces including reentrancy, flash loan exploits, oracle manipulation, MEV, front-running, and insecure randomness in dApps and DeFi protocols.
- Experience conducting security assessments of Web3 wallets, decentralized exchanges (DEXs), bridges, and lending/borrowing platforms, preferably in production environments at scale.
- Proficiency with blockchain security tools (Slither, MythX, Echidna, Foundry, Waffle, Hardhat, Truffle) and familiarity with formal verification frameworks (CertiK, Certora, K Framework).
- Strong knowledge of cryptographic primitives used in Web3 (threshold signatures, MPC, ZKPs, hash functions, elliptic curve cryptography) and secure key management practices.
- Excellent communication and mentoring abilities, with experience leading security initiatives across engineering teams and presenting findings to technical and non-technical stakeholders.
- ️ Benefits
- Competitive global compensation package including base salary, performance bonuses, and equity-like incentives tied to Binance’s long-term success.
- Comprehensive health, dental, and vision coverage for employees and dependents, supplemented by wellness programs and mental health resources.
- Flexible remote-first work arrangements with options to work from Binance’s regional hubs in Asia (e.g., Singapore, Dubai, Taipei) or fully remote, supporting work-life balance.
- Access to cutting-edge blockchain research, internal tech talks, and conferences (e.g., Binance Blockchain Week, Devcon, EthGlobal) to stay at the forefront of Web3 innovation.
- Opportunities for rapid career growth within Binance’s global Security Organization, including pathways to lead broader Web3, infrastructure, or application security domains.
- Generous learning and development budget for certifications (e.g., OSCP, GWAPT, CSSLP), blockchain courses, and attendance at industry-leading security events.
Apply tot his job
Apply To this Job