About the company
MoonPay is the worldās leading web3 infrastructure company. We provide end-to-end solutions for payments, enterprise-scale smart contract development, and digital asset management. Many of the worldās most iconic brands rely on MoonPay to power their web3 strategies and ideas.
Job Summary
About the role:
MoonPay's Product Security team is a dynamic blend of proactive defenders and inquisitive problem-solvers, dedicated to strengthening systems through rigorous security reviews and hands-on penetration testing. As a Product Security Engineer, you will embed security best practices throughout the SDLC, manage the Bug Bounty program, research emerging threats, and help spread a secure-by-design culture across the organisation.
Responsibilities:
šConduct threat modelling reviews of Technical Design Documents (TDDs) for new and existing features, providing clear, actionable security recommendations early in the design process. šPerform and support application security assessments, including penetration testing, vulnerability assessments, and proof-of-concept (PoC) development where appropriate. šInvestigate, triage, and respond to Bug Bounty program submissions, validating findings and working with engineering teams to drive timely remediation. šOwn and continuously improve application-layer protections, including managing and tuning Cloudflare WAF and related security controls. šPartner closely with engineering teams to embed security best practices throughout the SDLC, from design and development through deployment and maintenance. šResearch and track emerging threats and vulnerabilities, translating findings into practical mitigation strategies relevant to our technology stack. šDevelop and deliver security guidance, training, and awareness for engineering teams to raise the overall security maturity of the organization. šContribute to the creation, maintenance, and evolution of security standards, processes, and documentation. šParticipate in and eventually lead incident response activities, supporting investigation, containment, remediation, and post-incident improvements.
Requirements:
šBreadth of experience across multiple security domains, including web and mobile application security, infrastructure and cloud security. šHands-on experience performing white-box, source code-assisted web and mobile application penetration testing, from vulnerability discovery through triage and exploitation. šAbility to read, understand, and review source code to identify security issues, with a particular focus on JavaScript and TypeScript codebases. šStrong understanding of Threat Modelling principles and their practical application to the secure SDLC. šExperience working with web application firewalls to help protect applications, assess coverage, and support tuning rules to mitigate common attack patterns. šExperience embedding application security practices into CI/CD pipelines, enabling early detection of vulnerabilities and close collaboration with engineering teams. šDemonstrated ability to clearly communicate security findings, explain vulnerabilities, attack paths, and mitigations to both technical and non-technical audiences. šSelf-motivated, proactive, and takes strong ownership of work, operating effectively in a remote environment while maintaining a collaborative, team-focused mindset.
Nice-to-have: šExperience in JavaScript and TypeScript, including the ability to read, understand, and reason about modern web application codebases. šExperience working with Cloudflare, including its hosting and Web Application Firewall (WAF) capabilities. šExperience testing and securing GraphQL and REST APIs, including understanding common attack vectors and security considerations. šExperience or a strong interest in Web3 security testing, including assessing smart contracts, blockchain-based applications, or Web3 integrations. šInterest in agentic engineering, including emerging patterns in autonomous systems, tooling, or workflows, and their security implications. šContributions to the security community through open source involvement, CTFs, or speaking at information security meetups and conferences. šBackground working with disruptive technologies within FinTech, SaaS, or Crypto. šOne or more security relevant certifications such as OSCP or OSWE.
If this role isn't the perfect fit, there are plenty of exciting opportunities in blockchain technology, cryptocurrency startups, and remote crypto jobs to explore. Check them on our Jobs Board.



