About the job
About the Role
As a Security Researcher at Cantina.xyz, you will play a crucial role in safeguarding blockchain technologies by conducting thorough security assessments of smart contracts, protocols, and the underlying blockchain infrastructure. Your expertise will help identify vulnerabilities and enhance the security posture of decentralized finance (DeFi) systems.
Your Key Responsibilities
Conduct in-depth security evaluations of smart contracts, protocols, and blockchain infrastructure.
Examine protocol designs to uncover attack vectors in areas such as DeFi primitives, tokenomics, governance, MEV, bridges, and ZK systems.
Collaborate within a specialized team or pod alongside experienced researchers.
Offer actionable insights with detailed technical and business impact assessments.
Reproduce exploits, develop proofs of concept (POCs), and contribute occasional patches.
Write and publish post-mortems, technical articles, and internal reports to foster a culture of knowledge sharing.
Who You Are
Experienced: You have a substantial background in auditing complex smart contracts and possess deep knowledge of Solidity, EVM behavior, and common vulnerabilities, including reentrancy, logic flaws, gas griefing, and access control. Familiarity with Move, ZK, Cairo, Rust, or low-level protocol implementations is a plus.
Curious and Relentless: You dig deeper than surface-level issues, modeling systems holistically and challenging assumptions from first principles.
Collaborative: You thrive in teamwork with fellow security researchers and protocol developers to deliver secure products.
Detail-Oriented: You produce rigorous, clear, and concise technical documentation, ensuring that your GitHub issues are actionable and professional.
Credible: You have a proven track record through contributions to open-source projects, published research, audits, CTF participation, or recognition in the bug bounty arena.
Decentralization-Aligned: You appreciate the value of open networks, cryptographic advancements, and building resilient systems.
Preferred Qualifications
In-depth understanding of the EVM and Solidity.
Experience in auditing production smart contracts, whether independently or as part of a team.
Familiarity with cross-chain protocols, bridging solutions, rollups, or ZK systems.
A record of identifying significant bugs in bounty programs, audits, or competitions (e.g., Cantina, Paradigm CTF).
Knowledge of Ethereum security tools such as Foundry, Echidna, or Slither.
Experience in drafting or reviewing technical specifications or protocol documentation.

