Home › Companies › Mystenlabs › Security Engineer
Security Engineer
Mystenlabs · USA (Remote) · Remote · Active · Ashby
Job facts
| Field | Value |
|---|---|
| Company | Mystenlabs |
| Title | Security Engineer |
| Normalized title | - |
| Department / team | Security / Security |
| Location | United States |
| Work model | Remote / Remote |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | Ashby |
| Posted / first seen | — / 2026-05-29 |
| Changed / last seen | 2026-05-29 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Mystenlabs. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through Ashby. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| Department jobs | Active postings in Security. | Open |
| Work model jobs | Active Remote postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Mystenlabs |
| Source | 4addb966-00de-4add-b653-a5e6cc43bf7f |
| ATS provider | Ashby |
Description
Mysten Labs believes that decentralized and open protocols are the bedrock of the internet of value. This is why at Mysten Labs, we are creating foundational infrastructure to accelerate the adoption of decentralized protocols based on blockchain technologies.
Overview
Security engineers own the operational and software security of the Sui blockchain, wallet, Move language, and other Mysten systems.
Security engineers support and work closely with the engineers working on the sensitive components of these systems. In addition, they are the key points of contact for audit engagements and bug bounty reports.
We are hiring security engineers now as we expand the ecosystem and production services. We have a strong team in protocol security, but we need experts in operational and software security who can help us navigate the challenges of running world class infrastructure.
Responsibilities
Maintain and improve the custody systems that hold validator keys, operational keys, and important objects for Mysten-run smart contracts and general on-chain operations, including key generation, storage, access controls, signing workflows, aggregation, rotation, and recovery procedures
Harden the signing path end-to-end: review and improve the code, infrastructure, and operational practices around how transactions are authorized, reviewed, and submitted on-chain
Build and improve anti-scam and anti-abuse tooling for the Sui ecosystem, detecting phishing sites, malicious dApps, drainer contracts, and other threats that target Sui users, and partnering with wallet ecosystem teams on mitigations.
Conduct code and design reviews of components that interact with sensitive keys or handle on-chain assets, with a focus on cryptographic correctness, access control, and operational safety
Participate in investigation and response for security issues and incidents that touch custody or ecosystem abuse, and drive concrete fixes that prevent the same class of issue from recurring
Preferred Qualifications
3+ years of hands-on experience in security engineering, application security, or product security.
Knowledge relevant to key management in production, for example HSMs, cloud KMS, MPC or threshold-signature systems, hardware wallets, or comparable custody infrastructure.
Proficiency in one or more of: Rust, TypeScript, Python, or Move, and experience reviewing and writing security-sensitive code.
Solid understanding of applied cryptography fundamentals and the common ways cryptographic systems are misused in practice.
A builder mentality: comfortable operating with ambiguity, diving into unfamiliar codebases, and shipping the fix yourself rather than handing it off.
Strong written and verbal communication: you can explain a finding or an issue clearly to the engineer who needs to fix it and to a non-technical stakeholder who needs to understand the risk.
Interest in the web3 space is required; prior experience shipping in crypto, fintech, or other regulated/high-stakes environments is a plus.
Employment is contingent upon the successful completion of a background check, which may include verification of employment history, education credentials, criminal history, and other relevant information.
Regarding the recent rash of technology job scams: Be aware that emails from genuine Mysten Labs group recruiters will always come from the @ mystenlabs.com domain or related subdomains (e.g., mystenlabs.com/careers ). Remember: you can always verify positions on our job boards at www.mystenlabs.com/careers .
To support an efficient and fair hiring process, we may use technology-assisted tools, including artificial intelligence (AI), to help identify and evaluate candidates. All hiring decisions are ultimately made by human reviewers.
Our team is remote first and we are hiring across the world. Here at Mysten Labs, you’ll be joining a world-class team with tremendous growth potential as we bring the next billion users to web3. We raised a $300M Series B round from top Silicon Valley led venture funds like Jump Crypto, Andreessen Horowitz (a16z), Binance Labs, Redpoint, Lightspeed, Coinbase Ventures, Electric Capital, Standard Crypto, NFX, Slow Ventures, Scribble Ventures, Samsung Next, Lux Capital, among other investment firms and strategic partners. Come join us and build the future of web3!
Full job record
| Job ID | d6db00a1e4593f56c6fa1844e5a2842e511aadb4 |
| Org ID | 0dc350c7-30ce-4cd6-895e-7fac7366cb5b |
| Source ID | 4addb966-00de-4add-b653-a5e6cc43bf7f |
| Board ID | 4addb966-00de-4add-b653-a5e6cc43bf7f |
| Provider | ashby |
| Provider Job Key | c5f1f701-0cee-46f1-8eaa-59952a71a42f |
| Title | Security Engineer |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | USA (Remote) |
| Department | Security |
| Team | Security |
| Employment Type | full_time |
| Workplace Type | remote |
| Remote Policy | remote |
| Country | United States |
| Region | — |
| City | — |
| Salary Raw | — |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | — |
| Source URL | https://jobs.ashbyhq.com/mystenlabs/c5f1f701-0cee-46f1-8eaa-59952a71a42f |
| Apply URL | https://jobs.ashbyhq.com/mystenlabs/c5f1f701-0cee-46f1-8eaa-59952a71a42f/application |
| First Seen At | 2026-05-29 05:46:49Z |
| Last Seen At | 2026-06-06 20:13:33Z |
| Last Checked At | 2026-06-06 20:13:33Z |
| Last Changed At | 2026-05-29 05:46:49Z |
| Inactive At | — |
| Source Posted At | — |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=ashby/board=mystenlabs/date=2026-06-06/2026-06-06T20-13-32-093Z-b839b06378d408b97fcb817d09b240c6e0f2f0774d08713ac16e39429cabcb3c.json |
Event Fields
{
"content_hash": "87c99acaf95072a5a2c1327c801410543782b35c659f88335f192b8b25cadecc",
"source_hash": "e7ee65958fa226f95a4a797d470819153e3c9149832dd31412f2fdc6fa72257d",
"last_changed_at": "2026-05-29T05:46:49.047Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "USA (Remote)",
"city": null,
"region": null,
"country": "United States",
"is_remote": true,
"confidence": 0.95
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-06T20:13:33.349Z",
"launch_scope": {
"reason": "english_us_canada",
"included": true,
"language": "en",
"location": {
"raw": "USA (Remote)",
"city": null,
"region": null,
"country": "United States",
"is_remote": true,
"confidence": 0.95
},
"countries": [
"United States"
]
},
"remote_policy": "remote",
"salary_period": null,
"workplace_type": "remote",
"salary_currency": null
}Extensions
{}Native Structured
{
"id": "c5f1f701-0cee-46f1-8eaa-59952a71a42f",
"team": "Security",
"title": "Security Engineer",
"jobUrl": "https://jobs.ashbyhq.com/mystenlabs/c5f1f701-0cee-46f1-8eaa-59952a71a42f",
"address": null,
"applyUrl": "https://jobs.ashbyhq.com/mystenlabs/c5f1f701-0cee-46f1-8eaa-59952a71a42f/application",
"isListed": true,
"isRemote": true,
"location": "USA (Remote)",
"updatedAt": null,
"apiVersion": "ashby-non-user-graphql-v1",
"department": "Security",
"publishedAt": null,
"workplaceType": "Remote",
"employmentType": "FullTime",
"secondaryLocations": []
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/d6db00a1e4593f56c6fa1844e5a2842e511aadb4?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/0dc350c7-30ce-4cd6-895e-7fac7366cb5bJSONGET https://api.bluedoor.sh/job-postings/v1/sources/4addb966-00de-4add-b653-a5e6cc43bf7fJSONGET https://api.bluedoor.sh/job-postings/v1/jobs/d6db00a1e4593f56c6fa1844e5a2842e511aadb4/eventsJSON