Back to Aave jobs
A

Protocol Security Researcher

London, England
Engineering

Job Description

#### How you can make an impact:

  • Review major Aave protocol changes before external audit or deployment
  • Perform attacker-driven analysis of smart contracts, protocol mechanisms, and integrations
  • Participate in design and architecture discussions early enough to influence security-relevant decisions
  • Identify risks in Aave-adjacent systems, including assets, bridges, oracles, adapters, and critical dependencies
  • Contribute to AI-assisted security tooling and evaluate its effectiveness in real review workflows
  • Turn review findings into reusable knowledge, invariants, assumptions, and testing or monitoring ideas
  • Work with monitoring and incident response teams when review findings imply operational detection or response needs
  • Collaborate with external auditors by helping define scope, known risks, and areas of concern

---

#### Let's connect if you have:

  • 5+ years of relevant security experience
  • Strong smart contract security background
  • Ability to independently review complex codebases and reason about protocol-level failure modes
  • Attacker mindset: you can move from “this looks wrong” to “this is how it could be exploited”
  • Strong understanding of DeFi mechanisms, including lending, liquidations, accounting, oracles, collateral, governance, and integrations
  • Evidence that you are actively using AI to improve security research, review quality, or review throughput
  • Clear written communication: you can explain risk, impact, uncertainty, and trade-offs to engineers and non-security stakeholders
  • Good judgment about severity, exploitability, and when a finding matters

---

#### Nice to haves:

  • Experience with formal methods, fuzzing, invariant testing, or custom security tooling
  • Experience building internal tools for security review, code understanding, or knowledge management
  • Experience working with external audit firms or leading audit engagements
  • Familiarity with governance payloads, upgrade systems, permissioning, and incident response
  • Open-source security research, published findings, CTFs, bug bounties, or prior public vulnerability research

About Aave

First seen: September 16, 2026
Last updated: September 20, 2026