Job Description
The testing team currently covers functional testing, API testing, automation testing, and full Web3 on-chain business process testing. However, there is a gap in smart contract security testing expertise. This role aims to hire a test engineer with Web3 project experience, familiarity with smart contract testing, and some security expertise to strengthen the team's on-chain contract security testing capabilities.
Key Responsibilities
- Conduct smart contract testing for Web3 projects, covering deployment, invocation, upgrades, permissions, and on-chain transactions.
- Design test scenarios based on Solidity contract code and business logic, independently verifying normal, edge, and exception cases.
- Focus on smart contract security testing, analyzing potential risks from an attacker's perspective.
- Validate asset-related contracts for fund security, including transfers, approvals, staking, withdrawals, and settlements.
- Test contract permission security (Owner/Admin/Role controls) to identify unauthorized access or misconfigurations.
- Verify security of high-privilege operations like contract upgrades, pauses, and parameter modifications.
- Troubleshoot issues using on-chain data (transactions, events, hashes, contract states, RPC).
- Participate in contract requirement reviews to preemptively identify security risks.
Job Requirements
- Proven Web3/blockchain testing experience with smart contracts.
- Ability to read Solidity code and understand core business logic.
- Deep knowledge of EVM, wallet signatures, transactions, Gas, Nonce, RPC, Events, and Approve/Allowance mechanisms.
- Experience in smart contract security testing and awareness of common vulnerabilities.
- Proactive in designing attack/exception scenarios beyond normal workflow validation.
- Independent problem reproduction and root cause analysis skills.
Security Competency Focus
Candidate should demonstrate practical experience or advanced understanding of:
- Reentrancy attacks
- Permission controls and privilege escalation
- Signature replay/verification issues
- Front-running/MEV risks
- Approve/Allowance vulnerabilities
- Precision/edge-case handling
- Duplicate transaction execution
- State manipulation bypasses
- Timestamp/block dependency risks
- DoS/Gas-related issues
- External contract call security
- Malicious contract interactions
- Emergency pause mechanisms
- Upgradeable contract/Proxy security
- Owner/Admin/Role permission changes
- Fund risks from unauthorized parameter changes
Preferred Qualifications
- Experience with DeFi, wallets, staking, mining, or trading projects
- Smart contract auditing experience
- Familiarity with Foundry/Hardhat testing frameworks
- Usage of Slither/Mythril/Echidna security tools
- Solidity development background
- Real-world vulnerability discovery/reproduction
Hiring Priorities
While existing team members handle functional/API/automation testing, we specifically seek candidates who can:
- Go beyond basic interface testing to analyze contract logic
- Trace fund flows and permission structures
- Proactively design attack vectors to uncover security flaws
Benefits
Salary negotiable during interview. Contact HR: +60127186434 (WhatsApp/Telegram) Email resumes to: [email protected]