Jito Labs Logo

Jito Labs

Senior Security Engineer, Product

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in United States
180K-200K Annually
Senior level
Remote
Hiring Remotely in United States
180K-200K Annually
Senior level
Own product and protocol security across Jito’s Solana-based products. Responsibilities include threat modeling, secure design and code reviews, deployment hardening, internal audits, onchain monitoring, bug bounty operations, remediation tracking, AI-assisted security testing, and key and asset risk management. The role requires production software engineering experience, strong application security expertise, security automation skills, and familiarity with Web3, crypto, or DeFi.
The summary above was generated by AI
About Jito


Jito builds the market layer of Solana: the execution, capital, and incentive infrastructure behind the network's onchain economy. That includes the validator client running the majority of Solana stake, BAM (a new framework for verifiable ordering, pre-execution privacy, and programmable blockspace), JitoSOL (the leading liquid staking token on Solana), and JTX (trading built directly on our own market infrastructure).
We are a lean, high-density team. Everyone here owns real surface area, works in the open, and ships at pace. The engineers on this team are the people market makers call when milliseconds matter.

About Jito

Jito builds the Market Layer of Solana: the execution systems, capital markets, and incentive mechanisms that power real markets on-chain.

Our products process billions in daily transaction value. The Jito-Solana validator client runs on the vast majority of Solana's active stake. BAM is redefining how blocks get built. JitoSOL is the leading liquid staking token on the network. We are not building at the margins. We are building core infrastructure that Solana's economy runs on.

Now we're moving up the stack, bringing that same infrastructure advantage to products that traders and users interact with directly.

We're a team of around 50 people with product-market fit across multiple product lines and years of runway. We take hard problems seriously and move fast on them. Nothing is out of reach.

About the Role

We've gone from one main product line to four, and the security work on those products has outgrown the one person doing it. This role owns product and protocol security: the surface where our code meets real money.

You'll report to the Head of Security and work alongside an Enterprise Security Engineer who owns internal infrastructure, identity and detection. The split is deliberate. They secure how we work; you secure what we ship.

This is an engineering role. Most of the backlog is code, not policy.

What You'll Own

  • Product and protocol security reviews: threat modeling, secure design review, whitebox code review, and getting in early enough to change designs rather than document them

  • Deployment hardening across our product lines, including the jito-solana deploy process

  • Ongoing internal audits of our own products rather than waiting for an external engagement to surface issues

  • Onchain monitoring: standing up tooling like Hypernative or Blockaid and building the detections that catch probing before an attack is underway

  • Bug bounty operations as we bring more of the program in-house: triage, severity assessment, remediation tracking, and escalation

  • Auditor findings driven through to closure: reviewed, prioritized, assigned, tracked

  • AI-assisted security testing and continuous scanning, plus the security surface that comes with agents and AI tooling operating inside a codebase

  • High-impact key and asset risks: key hygiene, hot wallet and engineering keys, multisigs, security councils

What We're Looking For

  • A software engineering background is essential. You've built production systems, and that foundation shapes how you approach security.

  • You've since moved into product security and are fluent across the lifecycle: threat modeling, secure design review, whitebox code review, and vulnerability testing

  • 5+ years of professional experience, with a meaningful portion in software engineering before moving into security

  • Proficiency in at least one systems or backend language. Rust preferred; Go, C++, or Python also work. You will read production codebases and build tooling as routine parts of this job.

  • Demonstrated experience in product or application security, not solely infrastructure or compliance work

  • A track record of building security tooling or automation from scratch

  • Experience running or contributing to a bug bounty program, or a clear view of how you'd run one

  • Genuine interest in AI security, including adversarial testing of agent controls

  • Strong written communication. Findings nobody can act on are findings that don't get fixed.

  • Comfortable with high ownership and working autonomously on a small team

  • Experience in web3, crypto, or DeFi

Nice to Have

  • Smart contract or onchain security experience, particularly on Solana or another SVM chain

  • Experience with onchain monitoring tooling such as Hypernative or Blockaid

  • Familiarity with validator or consensus infrastructure

  • Experience with multisig schemes: signing policy design, quorum configuration, or key management in production

  • Familiarity with hardware security modules: integration, key lifecycle, or operational use

  • Exposure to trusted execution environments: attestation, confidential compute, or secure enclave design

  • Experience with fuzzing, formal verification, or property-based testing of financial logic

Why This Role Exists

Security at Jito has been one person covering four product lines, an expanding AI surface, and a validator client running most of Solana's stake. That person has been spending their time on the most likely risks, which means the highest-impact ones get less attention than they deserve.

We're hiring two engineers so that ownership is distributed rather than bottlenecked, and so losing one person doesn't cost the whole function. The goal is not more approval steps. It is safer defaults, earlier input, and engineering that moves faster because security is in the room rather than at the gate.

How we work


Remote-first, writing-heavy, and transparent by default: most decisions happen in public Slack channels, and everyone's voice carries. We value ownership, humility, curiosity, and getting it done over getting it perfect. Small egos, high standards.


What we offer


Competitive compensation including salary and token incentives, the tools you need to do your best work, and a seat at the center of Solana's market infrastructure alongside some of the strongest engineers in the ecosystem.
Jito is an equal opportunity employer. We evaluate candidates on the basis of their skills, experience, and potential contribution, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by law.

 

Similar Jobs

Yesterday
Remote
Senior level
Senior level
Artificial Intelligence • Productivity • Software • Automation
Create motion design across product explainers, websites, paid social, events, campaigns, and product launches. Develop Zapier’s motion language, branded animation systems, motion guidelines, component libraries, and reusable templates. Collaborate with brand, product, marketing, web, social, agencies, and external partners. Produce storyboards, UI-based animations, scalable video formats, and experiment with AI and motion tools to help teams create on-brand assets independently.
Top Skills: Ai Video ToolsFigmaFigma MotionJitter
Yesterday
Remote or Hybrid
Entry level
Entry level
Cloud • Healthtech • Social Impact • Software • Biotech
Drive new business and revenue growth across the Nordic territory by generating pipeline, managing complex SaaS sales cycles, forecasting accurately, presenting solutions, negotiating with technical and executive stakeholders, and closing strategic accounts. The role also involves account relationship management, collaboration with marketing, product, customer success, and channel teams, Salesforce data integrity, and use of structured sales methodologies such as MEDDICC.
Top Skills: Artificial IntelligenceMeddiccSaaSSalesforce
Yesterday
In-Office or Remote
USA
163K-272K Annually
Senior level
163K-272K Annually
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Leads product strategy, roadmap, lifecycle ownership, adoption, and measurable outcomes for a greenfield enterprise AI platform. Defines platform boundaries, governance controls, evaluation, registration, and cost-tracking capabilities while translating evolving risk, privacy, security, and GxP requirements into usable product features. Partners with engineering, design, legal, compliance, risk, security, and global agent-building teams to prioritize investments, guide delivery, communicate direction, and drive platform adoption.
Top Skills: AgileAIAi AgentsAi GovernanceGxpLeanModel Evaluation

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account