Back to Aave jobs
A
Protocol Security Researcher
London, England
EngineeringJob Description
#### How you can make an impact:
- Review major Aave protocol changes before external audit or deployment
- Perform attacker-driven analysis of smart contracts, protocol mechanisms, and integrations
- Participate in design and architecture discussions early enough to influence security-relevant decisions
- Identify risks in Aave-adjacent systems, including assets, bridges, oracles, adapters, and critical dependencies
- Contribute to AI-assisted security tooling and evaluate its effectiveness in real review workflows
- Turn review findings into reusable knowledge, invariants, assumptions, and testing or monitoring ideas
- Work with monitoring and incident response teams when review findings imply operational detection or response needs
- Collaborate with external auditors by helping define scope, known risks, and areas of concern
---
#### Let's connect if you have:
- 5+ years of relevant security experience
- Strong smart contract security background
- Ability to independently review complex codebases and reason about protocol-level failure modes
- Attacker mindset: you can move from “this looks wrong” to “this is how it could be exploited”
- Strong understanding of DeFi mechanisms, including lending, liquidations, accounting, oracles, collateral, governance, and integrations
- Evidence that you are actively using AI to improve security research, review quality, or review throughput
- Clear written communication: you can explain risk, impact, uncertainty, and trade-offs to engineers and non-security stakeholders
- Good judgment about severity, exploitability, and when a finding matters
---
#### Nice to haves:
- Experience with formal methods, fuzzing, invariant testing, or custom security tooling
- Experience building internal tools for security review, code understanding, or knowledge management
- Experience working with external audit firms or leading audit engagements
- Familiarity with governance payloads, upgrade systems, permissioning, and incident response
- Open-source security research, published findings, CTFs, bug bounties, or prior public vulnerability research
About Aave
First seen: September 16, 2026
Last updated: September 20, 2026