Full-Time

QA Engineer

Posted on 9/9/2026

Halborn

Halborn

51-200 employees

Cybersecurity audits and consulting for blockchain

No salary listed

No H1B Sponsorship

Oregon, USA + 1 more

More locations: Miami, FL, USA

Remote

Category
QA & Testing (1)
Required Skills
Python
JavaScript
GitHub Actions
Software Testing
Git
GraphQL
Smart Contracts
Docker
Quality Assurance (QA)
TypeScript
Blockchain
Jenkins
Observability
Playwright
REST APIs
Selenium
DevOps

Get referred to Halborn

See people who can refer or advise you

Requirements
  • Three to five years of experience in QA engineering, software development engineering in test, or test automation, with demonstrated progression from manual execution toward automated coverage.
  • Strong programming ability in at least one of TypeScript, JavaScript, or Python, including writing maintainable test code.
  • Hands-on experience with modern automation frameworks such as Playwright, Cypress, Selenium, pytest, or equivalent.
  • Practical API testing experience, including contract, integration, and negative-path testing against REST or GraphQL services.
  • Working knowledge of continuous integration and continuous delivery systems such as GitHub Actions, GitLab CI, Jenkins, or similar, including pipeline configuration.
  • Daily use of AI coding assistants and large language model tooling, with the ability to assess where they help and where their output requires verification.
  • Comfort with Git, containerized local environments, and reading application code to understand what is being tested.
  • Willingness to learn the technical aspects of blockchain, smart contracts, and cybersecurity.
Responsibilities
  • Own the test strategy for internal engineering platforms and client-facing products, covering unit, integration, end-to-end, and regression testing.
  • Design, build, and maintain automated UI, API, and data-layer test suites that are fast, deterministic, and trusted by engineers.
  • Use large language model-assisted tooling to accelerate test authoring, generate edge cases from specifications and diffs, triage failing runs, and summarize regressions.
  • Build and tune quality gates in continuous integration and continuous delivery so broken builds do not reach client environments and feedback remains measured in minutes.
  • Identify manual quality-assurance processes and automate release checklists, environment setup, test-data generation, smoke verification, and reporting.
  • Reproduce, isolate, and file defects with clear reproduction steps, expected and actual behavior, and sufficient context for engineers to resolve them.
  • Partner with security engineers to incorporate authentication, authorization, input-handling, and secrets-exposure regression checks into the standard pipeline.
  • Run performance, load, and reliability testing against services handling sensitive audit and engagement data.
  • Define and report quality metrics including escaped defect rate, flake rate, critical-path coverage, and time to detection.
  • Contribute to release-readiness decisions and provide an informed assessment of whether software should ship.
Desired Qualifications
  • Experience testing Web3 applications, including wallet flows, testnets, remote procedure call interactions, or smart-contract tooling such as Foundry or Hardhat.
  • Experience building evaluation harnesses for large language model-powered features, including regression testing of non-deterministic output.
  • Background in security testing, Open Worldwide Application Security Project methodology, or hands-on experience with tools such as Burp Suite.
  • Performance and load testing with k6, Locust, JMeter, or similar tools.
  • Experience with observability tooling and using production telemetry to identify gaps in test coverage.
  • Open-source contributions to testing frameworks or developer tooling.
  • Knowledge of current blockchain and decentralized-finance trends.

Halborn is a cybersecurity firm focused on blockchain technology and digital assets. It helps exchanges, DeFi projects, and other crypto businesses with security audits, penetration testing, and consulting to protect digital assets and financial infrastructure. By combining expertise in blockchain-specific threats with traditional financial security, Halborn differentiates itself from competitors. It translates its deep technical knowledge into practical services to launch and maintain secure digital exchanges and smart contract ecosystems. The company’s goal is to strengthen clients’ defensive postures against security threats in the digital asset space, ensuring secure operations and trusted platforms.

Company Size

51-200

Company Stage

Series A

Total Funding

$90M

Headquarters

Miami, Florida

Founded

2019

Get referred to Halborn

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • January 2026 ISO 27001 and NIST CSF 2.0 alignment helps win banks and regulators.
  • April 2026 Hashgraph and QRL deals prove demand for specialized, high-trust security reviews.
  • The 2022 $90 million Summit Partners round gives Halborn runway for product and sales expansion.

What critics are saying

  • Blockchain security demand depends on crypto adoption, and weak markets cut audit pipelines quickly.
  • Competitors like Trail of Bits, OpenZeppelin, and NCC Group attack the same elite audit budgets.
  • If tokenization stalls, Halborn's Solana and Knova partnerships become branding, not durable revenue.

What makes Halborn unique

  • Halborn pairs blockchain audits with traditional security controls, backed by ISO 27001 and SOC 2 Type II.
  • It built SSTS with Solana Foundation support, giving regulated tokens a compliance standard.
  • Its 2026 Hedera, Knova, and QRL work spans enterprise, tokenization, and post-quantum security.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Unlimited Paid Time Off

Company Equity

Growth & Insights and Company News

Headcount

6 month growth

1%

1 year growth

1%

2 year growth

2%
PR Newswire
Apr 15th, 2026
Hashgraph and Halborn partner to elevate security across the Hedera ecosystem.

Hashgraph and Halborn partner to elevate security across the Hedera ecosystem. Apr 15, 2026, 11:25 ET NEW YORK, April 15, 2026 /PRNewswire/ - Hashgraph has partnered with Halborn, a leading blockchain security firm, to strengthen security measures and protections across the Hedera ecosystem. Trust is at the core of any system, and this partnership helps teams build with confidence from the start. Together, Hashgraph and Halborn are helping ensure that applications launching on the Hedera network are resilient from day one and continue to meet high standards as they grow. "Security is fundamental to trust in any distributed system," said Joe Blanchard, CIO and CSO at Hashgraph. "By working with Halborn, we are giving builders in the Hedera ecosystem access to specialized expertise that helps them identify and address risks early, and continue strengthening their systems over time." Halborn brings deep experience securing systems that operate under real-world pressure. The firm has conducted more than 2,500 security assessments, identified over 13,000 vulnerabilities, and helped protect more than $1 trillion in digital assets. Its team of more than 100 security practitioners supports over 800 clients, including financial institutions operating in highly regulated environments. This experience shapes a practical approach to security that focuses on how systems behave when things go wrong. Halborn's methodology focuses on identifying potential exploit paths across the full stack, with the goal to deliver clear, prioritized findings that teams can act on quickly, with validation processes in place to ensure accuracy and completeness. A key element of the partnership is enabling a more structured approach to security as projects evolve, including: * Pre-launch readiness, where early risks are identified and translated into clear go or no-go decisions * Targeted assessments, allowing teams to bring in security expertise as new components are introduced * Continuous engagement, where security becomes an ongoing part of development and operations This model reflects how risk changes as systems grow more complex, integrate with new services, and attract greater usage. For the Hedera ecosystem, it means access to security support that aligns with how projects are actually built and deployed. The partnership between Hashgraph and Halborn is ultimately focused on strengthening trust. By combining Hedera's consensus-level security with Halborn's ability to identify and address real-world threats, the Hedera ecosystem is better positioned to support applications that require a high level of assurance, from financial services to AI and beyond. About Hashgraph Hashgraph is a rapidly growing software company comprising world-renowned leaders and builders in web3. Founded with the mission to foster a secure, trusted, and sustainable decentralized world, Hashgraph powers Hedera, the leading distributed ledger technology (DLT) network for enterprise and web3 builders. With a global presence, Hashgraph spearheads Hedera's marketing, product innovation, and technical development. Committed to accelerating application deployment, Hashgraph introduces pioneering products and services that bridge traditional and decentralized finance, advancing us towards an internet of value. For more information visit Hashgraph.com. About Halborn Halborn is the industry-leading blockchain solutions firm for enterprise-grade digital assets, trusted by the top financial institutions and blockchain ecosystem leaders. Experience world-class, end-to-end security, from smart contract auditing and pen testing to advisory services and beyond. For more information visit halborn.com. SOURCE Hashgraph

Associated Press
Apr 3rd, 2026
QRL's post-quantum cryptography library clears security audit with no vulnerabilities found

The Quantum Resistant Ledger has released results of an independent security audit of its post-quantum cryptography library conducted by blockchain security firm Halborn. The audit found no cryptographic vulnerabilities, with all 13 findings rated informational, the lowest severity level. The audit validated two post-quantum digital signature packages implementing schemes approved by the National Institute of Standards and Technology. These address vulnerabilities in existing blockchain infrastructure, which relies on elliptic curve cryptography that quantum computers could compromise, putting over $2 trillion in digital assets at risk. QRL 2.0 extends the network's quantum-resistant architecture with quantum-safe smart contracts and proof-of-stake consensus. The full audit report is available on Halborn's website, with previous security audits accessible in QRL's GitHub repository.

The QRL
Apr 3rd, 2026
Halborn audit validates QRL's post-quantum cryptography library.

Halborn audit validates QRL's post-quantum cryptography library. Independent review finds no cryptographic vulnerabilities; all 13 findings rated Informational 3rd April 2026 ZUG, Switzerland - April 3, 2026 - The Quantum Resistant Ledger (QRL) released the results of an independent security audit of its post-quantum cryptography library, conducted by blockchain security firm, and security partner, Halborn. The audit found no cryptographic vulnerabilities. All 13 findings were rated Informational, the lowest severity level, and the core signing, verification and key generation logic was validated as correct. All findings have since been resolved through code fixes or formal documentation. The audit covers the two post-quantum digital signature packages at the heart of QRL's network, both implementing signature schemes approved by the National Institute of Standards and Technology (NIST) as part of its post-quantum cryptography standardization process. The validated packages address a structural vulnerability present in most existing blockchain infrastructure. The majority of public blockchain networks rely on elliptic curve cryptography (ECC), a public-key scheme that a cryptographically relevant quantum computer (CRQC) could compromise, putting more than $2 trillion in digital assets at risk. That timeline has grown more concrete in recent years. Google's Willow processor demonstrated below-threshold quantum error correction in December 2024, IonQ's published roadmap projects a CRQC as early as 2028, and a Google research paper published March 30, 2026, warned that cryptographic migrations need to begin without delay while highlighting QRL as a presently post-quantum secure blockchain. Asset managers including BlackRock have flagged quantum computing as a material security risk to Bitcoin. The Halborn audit is the latest in a series of third-party reviews of QRL's architecture. QRL's 1.x network launched in 2018 with post-quantum cryptography as a foundational design requirement and was externally audited by X41 D-sec and Red4sec, among the earliest public blockchain networks to undergo such review at launch. QRL 2.0 extends that posture by incorporating quantum-safe smart contracts, a proof-of-stake consensus layer and continued third-party security audits from qualified firms. "We have successfully completed our security assessment of QRL's post-quantum cryptography library. The fact that all findings were classified as informational highlights the project's strong security posture. Collaboration throughout the engagement was seamless, with the QRL team demonstrating responsiveness and efficiency in addressing all observations. We are happy to support their initiative to advance toward a quantum-secure future." - Gabi Urrutia, SVP Security & Field CISO at Halborn The full audit report is available on the Halborn website. Previous QRL security audits are accessible in the QRL GitHub repository. About The Quantum Resistant Ledger. QRL 2.0 is a proof-of-stake blockchain built with NIST-approved post-quantum cryptography from its initial launch. The network supports EVM-friendly smart contracts, NFTs and digital identities through the QRVM and the Hyperion smart contract language. More information is available at www.theqrl.org. About Halborn. Halborn is the industry-leading blockchain solutions firm for enterprise-grade digital assets, trusted by the top financial institutions and blockchain ecosystem leaders. Experience world-class, end-to-end security, from smart contract auditing and pen testing to advisory services and beyond. Media contact. 3rd April 2026

Halborn
Mar 12th, 2026
Halborn partners with Knova to support secure tokenized market infrastructure.

Halborn partners with Knova to support secure tokenized market infrastructure. 03.12.2026 Halborn is excited to announce its partnership with Knova. As the trusted cybersecurity partner for the Knova ecosystem, Halborn will support institutions operating across traditional financial systems and the digital asset ecosystem. Halborn is also proud to join Knova's Tokenized Markets Circle, a group of leaders shaping the next generation of tokenized financial markets. As banks, asset managers, and fintechs expand into stablecoins and tokenized assets, risk increasingly sits at the seams between systems. Integrations between banking platforms, custodians, wallets, and blockchain networks introduce new operational and security challenges. Knova addresses this challenge with software that runs directly within a client's environment or cloud infrastructure. The platform acts as a unified operating layer that allows institutions to represent, move, and manage fiat, securities, stablecoins, crypto, and tokenized assets through one consistent system. "As institutions expand into stablecoins and tokenized assets, security across interconnected systems becomes mission critical. We chose Halborn for their deep expertise securing digital asset infrastructure alongside traditional systems. Their work is highly value aligned with what we are doing at Knova, and the flexibility in how they work with institutions truly allows them to address real client needs," said Natalya Thakur, CEO of Knova. "We're thrilled to partner with Knova as their trusted cybersecurity partner. Knova is building critical infrastructure for institutions operating at the intersection of traditional finance and digital assets. At Halborn, we bring deep, hands-on security expertise to help organizations scale tokenized market strategies with the confidence, resilience, and security required for institutional adoption," said Julie Aurand, Head of Strategic Partnerships and Business Development at Halborn. Together, Halborn and Knova aim to help institutions scale tokenized asset strategies with the security and operational resilience required for institutional adoption. Get in touch to find out more. Disclaimer. The information in this blog is for general educational and informational purposes only and does not constitute legal, financial, or professional advice. Halborn makes no representations as to the accuracy or completeness of the content, which may be updated or changed without notice. THIS WEBSITE USES COOKIES Halborn Inc. use cookies to personalise content and ads, to provide social media features and to analyse its traffic. Halborn Inc. also share information about your use of its site with its social media, advertising and analytics partners who may combine it with other information that you've provided to them or that they've collected from your use of their services. You consent to its cookies if you continue to use its website. Learn More.

Decrypt
Mar 13th, 2025
Elon Musk’S X Ddos Accusation Ignores Basics Of Cyber Attacks, Expert Says

Decrypt’s Art, Fashion, and Entertainment Hub. Discover SCENEElon Musk’s claim that the DDoS attack on X (formerly Twitter) originated from Ukraine drew skepticism from cybersecurity experts, who argue that attributing attacks based on IP addresses is unreliable.Attackers frequently use virtual private networks (VPNs) and other methods to obfuscate their origins, making pinpointing a specific geographic source difficult.On Monday, X was the target of a distributed denial-of-service attack that intermittently shut down the popular social media site for users worldwide. The X DDoS attack was linked to Dark Storm Team, a notorious hackivist group known for launching similar large-scale cyber disruptions.Hours after the attack, Musk claimed during an interview with Fox Business that the IP addresses associated with the attack originated in the Ukraine area.Tech-savvy users on X quickly pointed out that IP addresses can be masked or spoofed, making them appear to originate from one region when they actually originate from another.Dear Elon:You can't attribute an attack to any geographic location by IP address alone.See: VPN, location spoofing, etc.Also See: How botnets are controlled remotelyAlso Also See: Ask a cybersecurity person to help you. — MikeTalonNYC (@MikeTalonNYC) March 10, 2025Cybersecurity professionals also cautioned against drawing conclusions based solely on IP address data.“If one were conducting a DDoS attack you wouldn't necessarily see each connection originating from an IP address from a specific nation or netblock,” Scott Renna, Senior Solutions Architect with blockchain security firm Halborn, told Decrypt. “By definition, the attack would have to come from multiple IP addresses.”Renna pointed out that attackers distribute their traffic across numerous locations to avoid detection and mitigation efforts.“From an optics perspective and a blocking and prevention standpoint, it's just not how it's typically done,” he said.While the origins of the X attack remain a mystery, DDoS-as-a-Service websites are popping up to facilitate the launch of large-scale attacks. These websites let customers pay to launch DDoS attacks.There are two main types of DaaS."Stresser" services, which are legitimate tools companies use to test and strengthen their IT infrastructure