Full-Time

Full Stack Software Developer

Posted on 9/8/2026

Halborn

Halborn

51-200 employees

Cybersecurity audits and consulting for blockchain

No salary listed

No H1B Sponsorship

Oregon, USA

Remote

Category
Software Engineering (2)
,
Required Skills
Rust
Microsoft Azure
Python
React.js
Node.js
SQL
Postgres
GraphQL
Infrastructure as Code (IaC)
Docker
TypeScript
Blockchain
AWS
Solidity
REST APIs
DevOps
Google Cloud Platform

Get referred to Halborn

See people who can refer or advise you

Requirements
  • At least 4 years of experience building and shipping production web applications, with ownership across both the front end and back end.
  • Strong experience with React and TypeScript, including modern state management, component architecture, and CSS sufficient to build interfaces independently.
  • Strong server-side skills in Python, Node.js, or both, with production experience designing REST or GraphQL APIs.
  • Relational database experience, including schema design, query performance, and migrations.
  • Experience with cloud infrastructure such as AWS, Google Cloud Platform, or Azure, Docker, and self-configured continuous integration and continuous delivery pipelines.
  • Experience integrating large language model APIs into real products and using artificial intelligence coding assistants in daily development.
  • Understanding of common web vulnerability classes and how to prevent them.
  • Ability to communicate effectively in writing asynchronously and independently own outcomes across time zones.
  • Ability to work effectively in an ambiguous and continuously changing environment.
  • Willingness to learn the technical aspects of blockchain and cybersecurity.
Responsibilities
  • Design, build, and ship end-to-end features across a React and TypeScript front end and Python or Node.js services, owning work from technical design through production support.
  • Model data and design APIs with clear contracts, maintainable migrations, and durable schemas.
  • Build artificial intelligence-native product capabilities, including large language model orchestration, agentic and multi-step workflows, retrieval over engagement data, and structured downstream outputs.
  • Use artificial intelligence coding tools in development while reviewing generated code rigorously.
  • Automate internal engineering and security workflows by turning manual researcher processes into durable product functionality.
  • Write secure code using input validation, authentication and authorization, secrets handling, and dependency hygiene, and incorporate security review into the development process.
  • Participate in code review as both an author and reviewer.
  • Deploy and operate containerized services, cloud infrastructure, continuous integration and continuous delivery pipelines, monitoring, and production on-call systems.
  • Collaborate with security researchers, auditors, and product stakeholders to translate domain expertise into accessible software.
  • Contribute to technical direction, including framework choices, architecture, and tradeoffs, and document technical decisions.
Desired Qualifications
  • Postings bonus experience with Web3 development, including ethers.js or viem, wallet integrations, RPC providers, Solidity, or Rust smart contracts.
  • Experience building agentic systems, using the Model Context Protocol, vector databases, or evaluation frameworks for large language model features.
  • DevSecOps experience, including infrastructure as code, secrets management, supply chain security, or automated security scanning in continuous integration.
  • Prior work at a cybersecurity, fintech, or cryptocurrency company, or on products handling sensitive customer data.
  • Experience taking a product from zero to one on a small team.
  • Open source contributions.
  • Knowledge of current blockchain and decentralized finance trends.
  • PostgreSQL experience is preferred.

Halborn is a cybersecurity firm focused on blockchain technology and digital assets. It helps exchanges, DeFi projects, and other crypto businesses with security audits, penetration testing, and consulting to protect digital assets and financial infrastructure. By combining expertise in blockchain-specific threats with traditional financial security, Halborn differentiates itself from competitors. It translates its deep technical knowledge into practical services to launch and maintain secure digital exchanges and smart contract ecosystems. The company’s goal is to strengthen clients’ defensive postures against security threats in the digital asset space, ensuring secure operations and trusted platforms.

Company Size

51-200

Company Stage

Series A

Total Funding

$90M

Headquarters

Miami, Florida

Founded

2019

Get referred to Halborn

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • January 2026 ISO 27001 and NIST CSF 2.0 alignment helps win banks and regulators.
  • April 2026 Hashgraph and QRL deals prove demand for specialized, high-trust security reviews.
  • The 2022 $90 million Summit Partners round gives Halborn runway for product and sales expansion.

What critics are saying

  • Blockchain security demand depends on crypto adoption, and weak markets cut audit pipelines quickly.
  • Competitors like Trail of Bits, OpenZeppelin, and NCC Group attack the same elite audit budgets.
  • If tokenization stalls, Halborn's Solana and Knova partnerships become branding, not durable revenue.

What makes Halborn unique

  • Halborn pairs blockchain audits with traditional security controls, backed by ISO 27001 and SOC 2 Type II.
  • It built SSTS with Solana Foundation support, giving regulated tokens a compliance standard.
  • Its 2026 Hedera, Knova, and QRL work spans enterprise, tokenization, and post-quantum security.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Unlimited Paid Time Off

Company Equity

Growth & Insights and Company News

Headcount

6 month growth

1%

1 year growth

1%

2 year growth

2%
PR Newswire
Apr 15th, 2026
Hashgraph and Halborn partner to elevate security across the Hedera ecosystem.

Hashgraph and Halborn partner to elevate security across the Hedera ecosystem. Apr 15, 2026, 11:25 ET NEW YORK, April 15, 2026 /PRNewswire/ - Hashgraph has partnered with Halborn, a leading blockchain security firm, to strengthen security measures and protections across the Hedera ecosystem. Trust is at the core of any system, and this partnership helps teams build with confidence from the start. Together, Hashgraph and Halborn are helping ensure that applications launching on the Hedera network are resilient from day one and continue to meet high standards as they grow. "Security is fundamental to trust in any distributed system," said Joe Blanchard, CIO and CSO at Hashgraph. "By working with Halborn, we are giving builders in the Hedera ecosystem access to specialized expertise that helps them identify and address risks early, and continue strengthening their systems over time." Halborn brings deep experience securing systems that operate under real-world pressure. The firm has conducted more than 2,500 security assessments, identified over 13,000 vulnerabilities, and helped protect more than $1 trillion in digital assets. Its team of more than 100 security practitioners supports over 800 clients, including financial institutions operating in highly regulated environments. This experience shapes a practical approach to security that focuses on how systems behave when things go wrong. Halborn's methodology focuses on identifying potential exploit paths across the full stack, with the goal to deliver clear, prioritized findings that teams can act on quickly, with validation processes in place to ensure accuracy and completeness. A key element of the partnership is enabling a more structured approach to security as projects evolve, including: * Pre-launch readiness, where early risks are identified and translated into clear go or no-go decisions * Targeted assessments, allowing teams to bring in security expertise as new components are introduced * Continuous engagement, where security becomes an ongoing part of development and operations This model reflects how risk changes as systems grow more complex, integrate with new services, and attract greater usage. For the Hedera ecosystem, it means access to security support that aligns with how projects are actually built and deployed. The partnership between Hashgraph and Halborn is ultimately focused on strengthening trust. By combining Hedera's consensus-level security with Halborn's ability to identify and address real-world threats, the Hedera ecosystem is better positioned to support applications that require a high level of assurance, from financial services to AI and beyond. About Hashgraph Hashgraph is a rapidly growing software company comprising world-renowned leaders and builders in web3. Founded with the mission to foster a secure, trusted, and sustainable decentralized world, Hashgraph powers Hedera, the leading distributed ledger technology (DLT) network for enterprise and web3 builders. With a global presence, Hashgraph spearheads Hedera's marketing, product innovation, and technical development. Committed to accelerating application deployment, Hashgraph introduces pioneering products and services that bridge traditional and decentralized finance, advancing us towards an internet of value. For more information visit Hashgraph.com. About Halborn Halborn is the industry-leading blockchain solutions firm for enterprise-grade digital assets, trusted by the top financial institutions and blockchain ecosystem leaders. Experience world-class, end-to-end security, from smart contract auditing and pen testing to advisory services and beyond. For more information visit halborn.com. SOURCE Hashgraph

Associated Press
Apr 3rd, 2026
QRL's post-quantum cryptography library clears security audit with no vulnerabilities found

The Quantum Resistant Ledger has released results of an independent security audit of its post-quantum cryptography library conducted by blockchain security firm Halborn. The audit found no cryptographic vulnerabilities, with all 13 findings rated informational, the lowest severity level. The audit validated two post-quantum digital signature packages implementing schemes approved by the National Institute of Standards and Technology. These address vulnerabilities in existing blockchain infrastructure, which relies on elliptic curve cryptography that quantum computers could compromise, putting over $2 trillion in digital assets at risk. QRL 2.0 extends the network's quantum-resistant architecture with quantum-safe smart contracts and proof-of-stake consensus. The full audit report is available on Halborn's website, with previous security audits accessible in QRL's GitHub repository.

The QRL
Apr 3rd, 2026
Halborn audit validates QRL's post-quantum cryptography library.

Halborn audit validates QRL's post-quantum cryptography library. Independent review finds no cryptographic vulnerabilities; all 13 findings rated Informational 3rd April 2026 ZUG, Switzerland - April 3, 2026 - The Quantum Resistant Ledger (QRL) released the results of an independent security audit of its post-quantum cryptography library, conducted by blockchain security firm, and security partner, Halborn. The audit found no cryptographic vulnerabilities. All 13 findings were rated Informational, the lowest severity level, and the core signing, verification and key generation logic was validated as correct. All findings have since been resolved through code fixes or formal documentation. The audit covers the two post-quantum digital signature packages at the heart of QRL's network, both implementing signature schemes approved by the National Institute of Standards and Technology (NIST) as part of its post-quantum cryptography standardization process. The validated packages address a structural vulnerability present in most existing blockchain infrastructure. The majority of public blockchain networks rely on elliptic curve cryptography (ECC), a public-key scheme that a cryptographically relevant quantum computer (CRQC) could compromise, putting more than $2 trillion in digital assets at risk. That timeline has grown more concrete in recent years. Google's Willow processor demonstrated below-threshold quantum error correction in December 2024, IonQ's published roadmap projects a CRQC as early as 2028, and a Google research paper published March 30, 2026, warned that cryptographic migrations need to begin without delay while highlighting QRL as a presently post-quantum secure blockchain. Asset managers including BlackRock have flagged quantum computing as a material security risk to Bitcoin. The Halborn audit is the latest in a series of third-party reviews of QRL's architecture. QRL's 1.x network launched in 2018 with post-quantum cryptography as a foundational design requirement and was externally audited by X41 D-sec and Red4sec, among the earliest public blockchain networks to undergo such review at launch. QRL 2.0 extends that posture by incorporating quantum-safe smart contracts, a proof-of-stake consensus layer and continued third-party security audits from qualified firms. "We have successfully completed our security assessment of QRL's post-quantum cryptography library. The fact that all findings were classified as informational highlights the project's strong security posture. Collaboration throughout the engagement was seamless, with the QRL team demonstrating responsiveness and efficiency in addressing all observations. We are happy to support their initiative to advance toward a quantum-secure future." - Gabi Urrutia, SVP Security & Field CISO at Halborn The full audit report is available on the Halborn website. Previous QRL security audits are accessible in the QRL GitHub repository. About The Quantum Resistant Ledger. QRL 2.0 is a proof-of-stake blockchain built with NIST-approved post-quantum cryptography from its initial launch. The network supports EVM-friendly smart contracts, NFTs and digital identities through the QRVM and the Hyperion smart contract language. More information is available at www.theqrl.org. About Halborn. Halborn is the industry-leading blockchain solutions firm for enterprise-grade digital assets, trusted by the top financial institutions and blockchain ecosystem leaders. Experience world-class, end-to-end security, from smart contract auditing and pen testing to advisory services and beyond. Media contact. 3rd April 2026

Halborn
Mar 12th, 2026
Halborn partners with Knova to support secure tokenized market infrastructure.

Halborn partners with Knova to support secure tokenized market infrastructure. 03.12.2026 Halborn is excited to announce its partnership with Knova. As the trusted cybersecurity partner for the Knova ecosystem, Halborn will support institutions operating across traditional financial systems and the digital asset ecosystem. Halborn is also proud to join Knova's Tokenized Markets Circle, a group of leaders shaping the next generation of tokenized financial markets. As banks, asset managers, and fintechs expand into stablecoins and tokenized assets, risk increasingly sits at the seams between systems. Integrations between banking platforms, custodians, wallets, and blockchain networks introduce new operational and security challenges. Knova addresses this challenge with software that runs directly within a client's environment or cloud infrastructure. The platform acts as a unified operating layer that allows institutions to represent, move, and manage fiat, securities, stablecoins, crypto, and tokenized assets through one consistent system. "As institutions expand into stablecoins and tokenized assets, security across interconnected systems becomes mission critical. We chose Halborn for their deep expertise securing digital asset infrastructure alongside traditional systems. Their work is highly value aligned with what we are doing at Knova, and the flexibility in how they work with institutions truly allows them to address real client needs," said Natalya Thakur, CEO of Knova. "We're thrilled to partner with Knova as their trusted cybersecurity partner. Knova is building critical infrastructure for institutions operating at the intersection of traditional finance and digital assets. At Halborn, we bring deep, hands-on security expertise to help organizations scale tokenized market strategies with the confidence, resilience, and security required for institutional adoption," said Julie Aurand, Head of Strategic Partnerships and Business Development at Halborn. Together, Halborn and Knova aim to help institutions scale tokenized asset strategies with the security and operational resilience required for institutional adoption. Get in touch to find out more. Disclaimer. The information in this blog is for general educational and informational purposes only and does not constitute legal, financial, or professional advice. Halborn makes no representations as to the accuracy or completeness of the content, which may be updated or changed without notice. THIS WEBSITE USES COOKIES Halborn Inc. use cookies to personalise content and ads, to provide social media features and to analyse its traffic. Halborn Inc. also share information about your use of its site with its social media, advertising and analytics partners who may combine it with other information that you've provided to them or that they've collected from your use of their services. You consent to its cookies if you continue to use its website. Learn More.

Decrypt
Mar 13th, 2025
Elon Musk’S X Ddos Accusation Ignores Basics Of Cyber Attacks, Expert Says

Decrypt’s Art, Fashion, and Entertainment Hub. Discover SCENEElon Musk’s claim that the DDoS attack on X (formerly Twitter) originated from Ukraine drew skepticism from cybersecurity experts, who argue that attributing attacks based on IP addresses is unreliable.Attackers frequently use virtual private networks (VPNs) and other methods to obfuscate their origins, making pinpointing a specific geographic source difficult.On Monday, X was the target of a distributed denial-of-service attack that intermittently shut down the popular social media site for users worldwide. The X DDoS attack was linked to Dark Storm Team, a notorious hackivist group known for launching similar large-scale cyber disruptions.Hours after the attack, Musk claimed during an interview with Fox Business that the IP addresses associated with the attack originated in the Ukraine area.Tech-savvy users on X quickly pointed out that IP addresses can be masked or spoofed, making them appear to originate from one region when they actually originate from another.Dear Elon:You can't attribute an attack to any geographic location by IP address alone.See: VPN, location spoofing, etc.Also See: How botnets are controlled remotelyAlso Also See: Ask a cybersecurity person to help you. — MikeTalonNYC (@MikeTalonNYC) March 10, 2025Cybersecurity professionals also cautioned against drawing conclusions based solely on IP address data.“If one were conducting a DDoS attack you wouldn't necessarily see each connection originating from an IP address from a specific nation or netblock,” Scott Renna, Senior Solutions Architect with blockchain security firm Halborn, told Decrypt. “By definition, the attack would have to come from multiple IP addresses.”Renna pointed out that attackers distribute their traffic across numerous locations to avoid detection and mitigation efforts.“From an optics perspective and a blocking and prevention standpoint, it's just not how it's typically done,” he said.While the origins of the X attack remain a mystery, DDoS-as-a-Service websites are popping up to facilitate the launch of large-scale attacks. These websites let customers pay to launch DDoS attacks.There are two main types of DaaS."Stresser" services, which are legitimate tools companies use to test and strengthen their IT infrastructure