Protocol Security Engineer

il y a 5 jours


Paris, Île-de-France Morpho Temps plein

Job Description
About Morpho

Morpho is a leading Decentralized Finance (DeFi) lending protocol that raised $70 million from Ribbit Capital, a16z crypto, Coinbase Ventures, Variant, Brevan Howard, Pantera, Blocktower, and 50 others to build an
open lending network giving anyone, anywhere, access to the best possible terms.
Morpho is experiencing explosive growth, with over $10 billion in
deposits on the network
, solidifying itself as the new standard for DeFi lending. Now, Morpho is scaling its team of contributors to establish itself as a cornerstone, not just of DeFi, but of a new internet-native financial system.

Our Mission

Morpho's mission is to power human ambition with open access to capital. Human ambition has no borders, but the capital to fuel it does. Today's financial system is closed and fragmented. No one sees all opportunities, most overpay, and some are excluded entirely. We believe capital should flow efficiently to where it's needed most — giving anyone, anywhere, access to the best possible terms.

Location

Paris or remote (from -5h GMT up to +2h GMT to ensure sufficient overlap with the rest of the team).

How We Work
We move fast on hard problems in a nascent market with no set playbook : navigating uncertainty is part of the job. You'll be challenged: anyone can question work and decisions must be justified. We keep a high bar and match it with high support: we help each other unblock and share context openly, with low ego. More about our values:

Role

The mission of this role is to ensure the security and robustness of Morpho's smart contracts by conducting formal verification, security reviews, and managing bug bounty programs to ship safer protocols and reduce audit cycle times.

Responsibilities

  • Implement formal verification rules using Certora on Morpho smart contracts to validate critical invariants and reduce vulnerabilities before deployment.
  • Conduct comprehensive security reviews of protocol smart contracts to identify critical bugs and strengthen the attack surface before audits.
  • Own the bug bounty program by triaging submissions, communicating with security researchers, and coordinating response to critical findings.
  • Build periphery smart contracts that integrate with the core protocol to extend functionality while maintaining security standards.
  • Research emerging attack vectors and new vulnerability classes to keep the team ahead of threats and inform security best practices.
  • Represent Morpho's security approach at conferences, meetups, and through published research to build credibility in the security community.

What Success Looks Like

In your first 30 days
You will gain a solid understanding of Morpho v1 and vault v2 architecture, and implement initial formal verification rules using Certora on Vault/Market V2 contracts.

By Month 4–6
You will have complete understanding of Morpho v1 and v2, autonomously formulate and implement the most important contract invariants, lead the weekly call with Certora, and own triage and validation of the smart contract bug bounty program.

By Month 12
You will have made meaningful security contributions that increase robustness and reduce attack surface, identified new attack vectors, and distilled security best practices that the entire Protocol team relies on.

Job requirements

Competencies & Traits

Adaptability
You thrive in a fast-moving, remote-first environment where protocol priorities and timelines shift based on research findings and ecosystem developments.

Clear Communication
You excel at async communication through Slack and meetings, articulating complex security concepts clearly to help the team make progress through discussion and collaboration.

Ownership & Autonomy
You take full ownership of security domains, make decisions independently, and drive work forward without waiting for direction.

Low Ego & Team-First Mindset
You prioritize mission over personal goals, share credit transparently, and view security as a collective responsibility rather than individual heroics.

Critical Thinking & Curiosity
You challenge assumptions, provide constructive feedback, and continuously research new methods to stay ahead of emerging threats.

Must-have Experience & Skills

  • Master's degree in Computer Science, Cybersecurity, Software Engineering, or a related field
  • 3+ years of experience in smart contracts auditing
  • Proven track record of identifying critical vulnerabilities in smart contracts
  • Extensive knowledge of Ethereum Virtual Machine, Solidity and the blockchain ecosystem
  • Excellent written and verbal communication skills
  • Interest in DeFi and lending protocols
  • Low ego and collaborative mindset

Nice to Have

  • Experience with bug bounty programs and platforms, including triage, validation, and researcher communication
  • Experience writing smart contracts securing significant TVL
  • Publication record in applied cryptography, security, or related domains

Perks & Benefits
We design benefits around deep work and growth, so you can do the best work of your career. Expect fair, top-tier compensation, real flexibility, time together in Paris, great health coverage, and support to keep learning.

Equal opportunity
We welcome applicants from all backgrounds and hire based on talent, potential, and values alignment.

Ready to shape the future of finance?


  • Security Engineer

    il y a 1 semaine


    Paris, Île-de-France Dashlane Temps plein

    About DashlaneDashlane's mission is to deliver the credential security every business and employee needs to thrive. Millions of consumers, and over 25,000 brands worldwide, such as Michelin, Air France, and Forrester, trust Dashlane for industry-leading innovations, patented zero-knowledge security, and an unmatched user experience. Founded in Paris,...

  • Security Engineer

    il y a 5 jours


    Paris, Île-de-France Dashlane Temps plein

    About DashlaneDashlane's mission is to deliver the credential security every business and employee needs to thrive. Millions of consumers, and over 25,000 brands worldwide, such as Michelin, Air France, and Forrester, trust Dashlane for industry-leading innovations, patented zero-knowledge security, and an unmatched user experience. Founded in Paris,...

  • Security Engineer

    il y a 5 jours


    Paris, Île-de-France Dashlane Temps plein

    About DashlaneDashlane's mission is to deliver the credential security every business and employee needs to thrive. Millions of consumers, and over 25,000 brands worldwide, such as Michelin, Air France, and Forrester, trust Dashlane for industry-leading innovations, patented zero-knowledge security, and an unmatched user experience. Founded in Paris,...

  • Senior Security Engineer

    il y a 6 jours


    Paris, Île-de-France Qonto Temps plein

    Our mission? Creating the freedom for SMEs to succeed in business and beyond, by delivering Europe's leading finance workspace. We combine business-class tools (seamless invoicing, spend management, and pre-accounting) with unwaveringly attentive 24/7 support, designed to help businesses breeze through all things finance.Our journey:Founded by Alexandre and...

  • Senior Security Engineer

    il y a 7 jours


    Paris, Île-de-France Qonto Temps plein

    Our mission? Creating the freedom for SMEs to succeed in business and beyond, by delivering Europe's leading finance workspace. We combine business-class tools (seamless invoicing, spend management, and pre-accounting) with unwaveringly attentive 24/7 support, designed to help businesses breeze through all things finance. Our journey: Founded by...

  • Product engineer

    il y a 1 semaine


    Paris, Île-de-France Symbiotic Security Temps plein

    Product Engineer (Backend-leaning) – AI & Security Paris (Morning Laffitte) | 2 remote days/week | Full-timeAbout Symbiotic SecuritySymbiotic Security is a cybersecurity startup helping developers write secure code through an AI-powered assistant integrated into their IDE and CI/CD pipelines.Our product does two things extremely well:Detect & fix...

  • Senior Security Engineer

    il y a 2 semaines


    Paris, Île-de-France Doctolib Temps plein

    We are looking for an Application Security Engineer to join the Security team in Paris.   As an Application Security Engineer, your mission will be to safeguard the security and privacy of millions of practitioners and patients while helping deliver an exceptional user experience across Europe's leading healthcare products. You will build and scale...


  • Paris, Île-de-France Ledger Temps plein

    Job title: Senior Cloud Security EngineerLocation: ParisAbout LedgerWe're a team of experts pushing the limits of what's possible, united by our common goal to unlock true freedom through digital ownership, making technology accessible for all. We believe in a world where users, creators and enterprises manage their value with ownership and freedom. Our...

  • Site Security Manager

    il y a 1 semaine


    Paris, Île-de-France Nebius Group Temps plein

    Why work at NebiusNebius is leading a new era in cloud computing to serve the global AI economy. We create the tools and resources our customers need to solve real-world challenges and transform industries, without massive infrastructure costs or the need to build large in-house AI/ML teams. Our employees work at the cutting edge of AI cloud infrastructure...

  • Senior Security Engineer

    il y a 2 semaines


    Paris, Île-de-France Doctolib Temps plein

    We are looking for an Application Security Engineer to join the Security team in Paris.As an Application Security Engineer, your mission will be to safeguard the security and privacy of millions of practitioners and patients while helping deliver an exceptional user experience across Europe's leading healthcare products. You will build and scale...