Job Description

Summary

This is an opportunity for an intermediate/senior level Offensive Security Professional to join our Product Security team. As an experienced researcher you will help maintain critical security systems within our architecture, as well as assisting the wider engineering and devops practices with their activities. In Product Security our mission is to continuously improve the security posture of BitMEX from the inside, and we are looking for someone capable and flexible who can work with our excellent staff on that mission!

A crypto trading exchange is a security environment that is fairly rare in the infosec industry: we regularly get attacked by nation-state APT groups, we have continuous attempts by everyone from script kiddies to our own users trying to find ways to illegitimately extract money from us, and we protect vast amounts of crypto. All at the same time having a software stack that requires extreme uptime, minimal latency, and absolute accuracy in how it takes and processes orders.

If you want to help protect an environment where the threats are very real and continuous, this is the job for you. We will check that you are not from the DPRK, be warned; it would not be the first (or second, or third) time.

Key Responsibilities

  1. Manage our bug bounty program, reviewing reports, engaging with researchers and cooperating with software engineering to fix bugs
  2. Reviewing the outcomes of external penetration tests, replicating issues and again, working with engineering to fix findings
  3. Conducting internal penetration tests on our software and infrastructure stack
  4. Red and purple team exercises to test our monitoring
  5. Security research & threat intelligence, working with security response
  6. Application security & code reviews, internal training of engineers
  7. Being part of incidents to help triage and investigate issues

Qualifications

  1. 5+ Years in Information Security.
  2. Proven expertise in offensive security either through certifications, recognition, or referees.
  3. Strong communication skills and work ethic: contribute actively to the company and become ‘known’
  4. Candidates with less experience will be considered for an Offensive Security Engineer position.

Nice to have

  1. Experience with Kubernetes, Istio, Envoy and the AWS cloud platform would be useful. Advanced skills in these (and affiliated technologies) are a bonus but not required.
  2. Experience with GitHub CI/CD / Actions and/or ArgoCD is a bonus but not required
  3. Experience with derivatives and cryptocurrency is a bonus but not required.
  4. Development expertise in Go is a bonus but not required

Skills
  • Communications Skills
  • Cryptocurrency
  • Team Collaboration
© 2026 cryptojobs.com. All right reserved.