Cantina (cantina.xyz) Logo

Cantina (cantina.xyz)

Cantina Triager

Posted Yesterday
Be an Early Applicant
Remote
29 Locations
Junior
Remote
29 Locations
Junior
As a Bug Bounty Triager, you'll review and validate vulnerability reports, assess their impact, communicate with researchers, and improve the bounty program.
The summary above was generated by AI
About Spearbit & Cantina:

Founded in 2021 by former Ethereum Foundation Solidity engineers, Spearbit tackles Web3 security challenges. Our founding team built the leading blockchain language and secured the largest smart contract, protecting over $160B in value.

We're building Cantina, the "GitHub for Security", connecting security researchers with projects needing expertise. Our Cantina security platform has powered major competitions and serves the leading projects in Web 3. It currently supports collaborative security reviews, public and private security competitions, bug bounty programs, incident response, and AI code analyzer.

Similar to how cloud-security startups emerged previously, Cantina aims to be the definitive code-security platform for the future.

The Opportunity: We’re looking for a Bug Bounty Triager to join our team. In this role, you’ll be the first line of defense in reviewing vulnerability submissions, ensuring both speed and technical accuracy. Your work will help maintain the integrity of Cantina’s bounty ecosystem, foster trust between projects and whitehats, and raise the bar for security practices across the industry.

What you'll do:
  • Review, reproduce, and validate incoming vulnerability reports across smart contracts, DeFi protocols, and blockchain systems.

  • Assess severity and impact in the context of each project’s unique architecture and threat model.

  • Communicate with researchers to clarify missing details and provide constructive feedback on invalid or incomplete submissions.

  • Write clear and concise summaries for each validated report, including reproduction steps, impact analysis, and recommended mitigations.

  • Partner with Cantina’s program managers to ensure smooth workflows between security researchers, project teams, and internal stakeholders.

  • Contribute to the design and continuous improvement of Cantina bounty programs, workflows, and tooling.

  • Support other Cantina Security services that require triaging expertise.

  • Serve as a trusted bridge between projects and whitehats, balancing fairness, transparency, and accuracy in outcomes.

What we’re looking for:
  • Strong foundation in smart contract security, including common vulnerability classes and exploitation techniques.

  • Ability to read and analyze Solidity and other EVM-compatible languages; familiarity with Rust-based blockchains (e.g., Solana, Substrate) or other blockchain infrastructure.

  • Experience reviewing code bases, identifying vulnerabilities, and reproducing exploits.

  • Understanding of DeFi mechanisms (e.g., AMMs, lending protocols, bridges) and ability to quickly learn new protocol designs.

  • Familiarity with vulnerability disclosure workflows and bug bounty ecosystems.

  • Excellent written communication: able to explain technical issues clearly, neutrally, and with professionalism to both security engineers and non-technical stakeholders.

  • Detail-oriented and organized, able to manage a steady flow of incoming reports while maintaining high accuracy.

Benefits
  • Competitive salary and performance-based compensation opportunities

  • Opportunity to work in an early-stage startup with a talented and passionate team

  • Exposure to high-profile clients in the blockchain and cryptocurrency industry

  • Comprehensive health, dental and vision benefits

  • 401k matching program

Join Spearbit and help us build the future of code security!

Top Skills

Blockchain Systems
Evm-Compatible Languages
Rust
Solidity

Similar Jobs

An Hour Ago
In-Office or Remote
34 Locations
Entry level
Entry level
Machine Learning • Natural Language Processing
Join Welo Data to contribute to AI projects involving annotation, evaluation, and prompt creation, while working flexibly with global teams.
Top Skills: Digital Tools
An Hour Ago
In-Office or Remote
13 Locations
10-10
Entry level
10-10
Entry level
Machine Learning • Natural Language Processing
Evaluate e-commerce data and rate its usefulness while following specific guidelines. Assist in advancing AI technology through data annotation.
Top Skills: AIData AnnotationData Rating
Entry level
Machine Learning • Natural Language Processing
Welo Data seeks candidates fluent in Simplified Chinese for remote AI data labeling, evaluation, and instruction tasks, offering flexible hours.
Top Skills: AIDigital Tools

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account