Full-Time

Staff Application Security Engineer

Confirmed live in the last 24 hours

Uniswap

Uniswap

51-200 employees

Decentralized platform for cryptocurrency trading

Crypto & Web3
Financial Services

Compensation Overview

$264k - $294kAnnually

Senior

New York, NY, USA

Category
Cybersecurity
IT & Security
Required Skills
Kubernetes
Microsoft Azure
Python
JavaScript
Java
Docker
AWS
Cryptography
Google Cloud Platform
Requirements
  • Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field.
  • 7+ years of experience in application security or related fields, with at least 3 years in a leadership or senior technical role.
  • Deep understanding of application security principles, practices, and technologies.
  • Experience with security testing tools and methodologies (e.g., static and dynamic analysis, penetration testing).
  • Proficiency in programming and scripting languages (e.g., Java, Python, JavaScript).
  • Strong knowledge of web application security standards (e.g., OWASP Top Ten, SANS/CWE Top 25).
  • Experience with cloud security (AWS, Azure, GCP) and container security (Docker, Kubernetes).
  • Excellent problem-solving skills and the ability to work under pressure in a fast-paced environment.
  • Strong communication and interpersonal skills, with the ability to influence and lead teams.
  • Relevant certifications such as CISSP, CEH, OSCP, or CSSLP.
  • Experience with DevSecOps practices and tools.
  • Knowledge of regulatory compliance standards (e.g., GDPR, HIPAA, PCI-DSS).
  • Experience with identity and access management (IAM) and authentication protocols (OAuth, SAML).
Responsibilities
  • Lead the application security team, setting technical direction and priorities.
  • Mentor and guide junior security engineers, fostering a culture of continuous learning and improvement.
  • Conduct regular code reviews and security audits to ensure high standards of security practices are maintained.
  • Design, implement, and maintain security measures for our software applications to protect against threats and vulnerabilities.
  • Understand browser based attack vectors as well as android and iOS attack vectors.
  • Understand cryptographic primitive and their security applications.
  • Perform threat modeling, security code reviews, and vulnerability assessments.
  • Develop and maintain secure coding guidelines and best practices for developers.
  • Work closely with development teams to integrate security into the software development lifecycle (SDLC).
  • Lead incident response efforts for application security incidents, including investigation, mitigation, and post-incident analysis.
  • Develop and maintain incident response plans and procedures.
  • Conduct root cause analysis and implement corrective actions to prevent future incidents.
  • Collaborate with cross-functional teams, including developers, product managers, and infrastructure teams, to ensure comprehensive security coverage.
  • Communicate security risks, vulnerabilities, and requirements to stakeholders effectively.
  • Advocate for security best practices and foster a security-first mindset across the organization.
  • Stay current with the latest security trends, vulnerabilities, and technologies.
  • Evaluate and implement new security tools and technologies to enhance our security posture.
  • Continuously improve security processes and practices to ensure robust and scalable security solutions.

Uniswap is a decentralized finance platform that enables users to trade cryptocurrencies directly from their wallets on the Ethereum blockchain. It eliminates the need for a centralized intermediary, allowing individual traders, developers, and liquidity providers to engage in crypto trading. Users can swap tokens, provide liquidity to earn fees, and create decentralized applications using Uniswap's protocol. The platform generates revenue by charging a small fee on each trade, which is shared with liquidity providers to encourage their participation in liquidity pools. Uniswap also supports developers through its governance program and expands its reach by integrating with other platforms like Robinhood. The goal of Uniswap is to foster an open and permissionless financial system using blockchain technology.

Company Stage

Series B

Total Funding

$192.6M

Headquarters

New York City, New York

Founded

2018

Simplify Jobs

Simplify's Take

What believers are saying

  • The $10 million UNI token airdrop with the launch of Uniswap V4 could significantly boost user engagement and adoption.
  • Uniswap's strategic partnerships and integrations, such as with OKX and Across Protocol, enhance its ecosystem and provide users with more seamless and cost-effective trading options.
  • The acquisition of Crypto: The Game opens new avenues for growth and user engagement by merging DeFi with on-chain gaming.

What critics are saying

  • Regulatory scrutiny, as evidenced by the Wells notice from the SEC, could pose significant legal and operational challenges for Uniswap.
  • The complexity and rapid evolution of DeFi could lead to security vulnerabilities, potentially undermining user trust and platform stability.

What makes Uniswap unique

  • Uniswap's integration of gaming through the acquisition of Crypto: The Game sets it apart from other DeFi platforms that primarily focus on financial services.
  • The adoption of a new ERC standard for cross-chain intents and the integration with OKX DEX's 'Snap' trading feature highlight Uniswap's commitment to enhancing user experience and liquidity.
  • Uniswap's multichain support and collaboration with protocols like Blast and Across Protocol demonstrate its versatility and forward-thinking approach in the DeFi space.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Unlimited and encouraged time off

100% company-paid medical, dental, & vision for you and your dependents

401(k) participation

Daily lunches at NY HQ

For remote employees: up to $2,000 USD home office setup stipend