Application Security Engineer

<h2>About Polygon Labs</h2><p style="min-height:1.5em">Polygon Labs is a global blockchain payments company building and operating infrastructure to move money instantly, reliably, and at internet scale, with the mission to move all money onchain. It is building the Polygon Open Money Stack, an open and integrated stack of services and technologies to instantly and reliably move money anywhere, and put it to work. Its infrastructure has facilitated trillions of dollars in onchain value transfer and supported millions of transactions daily for some of the globe's largest banks, fintechs, enterprises, and consumer applications.</p><p style="min-height:1.5em"></p><h2><strong>Your Role</strong></h2><p style="min-height:1.5em">Polygon's Application Security team sits at the intersection of every product we ship. With a growing engineering org, an active bug bounty program fielding 30+ open submissions at any given time, and products going live across smart contracts, backend services, and infrastructure simultaneously, the team needs more depth, not a gatekeeper, a builder. You will report directly to the Application Security Lead and work across every engineering team at every stage of development, from sprint planning to post-ship remediation. Your job is to make security scale faster than the attack surface grows.</p><p style="min-height:1.5em"></p><h2><strong>Your Responsibilities</strong></h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Own end-to-end security reviews across smart contracts (Solidity), backend services (Go, TypeScript, Python), and frontend surfaces, producing written findings at the quality level of a top external audit firm, published and used as the internal standard</p></li><li><p style="min-height:1.5em">Build and ship an agentic security CI/CD pipeline: agent-driven review that runs autonomously against every PR and release candidate, reasons about changes in context, and gets smarter with each deployment</p></li><li><p style="min-height:1.5em">Design and maintain specialised AI-powered code reviewers tuned to specific vulnerability classes and surfaces, Solidity-aware, protocol-aware, and calibrated to the actual patterns Polygon's products surface</p></li><li><p style="min-height:1.5em">Triage and manage the bug bounty program: read incoming submissions daily, reproduce valid findings, separate signal from noise, assign severity, and route confirmed issues to engineering with enough context to fix them correctly, using custom AI workflows to maintain rigor at volume</p></li><li><p style="min-height:1.5em">Follow through on remediation: review proposed fixes, close out resolved findings, and push back where a fix addresses symptoms rather than root cause</p></li><li><p style="min-height:1.5em">Embed across engineering teams at all stages, sprint planning, design review, feature freeze, post-launch, as a working partner, not a sign-off function</p></li><li><p style="min-height:1.5em">Lead the team's AI security practice by example: build custom prompt chains, Claude Code workflows, and Codex integrations tailored to specific security tasks, then demo and share them so the whole team's baseline rises</p></li></ul><p style="min-height:1.5em"></p><h2><strong>What You'll Need</strong></h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Full-stack security fluency across multiple languages: you can drop into an unfamiliar codebase and produce a meaningful review within a day, Solidity, Go, TypeScript, and Python are the surfaces that matter most here</p></li><li><p style="min-height:1.5em">Smart contract security as a core competency: production experience auditing or building secure Solidity, deep familiarity with EVM internals, common DeFi protocol patterns, and the historical record of smart contract exploits</p></li><li><p style="min-height:1.5em">Proven AI workflow depth, not just tool usage: you have built custom prompt chains, CI integrations, and task-specific plugins (using tools like Claude Code and Codex) for security work specifically, and you can speak clearly about where AI accelerates and where human judgment is irreplaceable</p></li><li><p style="min-height:1.5em">Experience making security decisions under real time pressure in a Web3 environment, where speed and rigor have to coexist</p></li><li><p style="min-height:1.5em">A public portfolio that demonstrates your security thinking: audit reports, bug bounty writeups, research posts, or open-source tooling, something that shows what good looks like when you put your name on it</p></li></ul><p style="min-height:1.5em"></p><h2><strong>Preferred Qualifications</strong></h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Experience running or contributing to a structured bug bounty program (triage, researcher communication, severity calibration)</p></li><li><p style="min-height:1.5em">Direct exposure to payments protocols, stablecoin infrastructure, or regulated fintech environments</p></li><li><p style="min-height:1.5em">Prior work building security tooling that other engineers actually use, not just internal scripts, but something with adoption</p></li></ul><h2><br><br>Polygon Labs Perks</h2><p style="min-height:1.5em">The goal of the Polygon Labs total rewards program is to support the health and well-being of you and your family. Our comprehensive compensation plan includes the following benefits for our full time employees:</p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Remote first global workforce</p></li><li><p style="min-height:1.5em">Industry leading Medical, Dental and Vision health insurance*</p></li><li><p style="min-height:1.5em">Company matching 401k with 3% match*</p></li><li><p style="min-height:1.5em">$1,500 Home Office Set Up Allowance (life-time max)</p></li><li><p style="min-height:1.5em">$200 Annual AI Allowance Program </p></li><li><p style="min-height:1.5em">$75 Monthly internet or phone reimbursement</p></li><li><p style="min-height:1.5em">Flexible Time Off</p></li><li><p style="min-height:1.5em">Company issued laptop</p></li><li><p style="min-height:1.5em">Egg freezing, mental health, and employee wellness benefits</p></li></ul><p style="min-height:1.5em">*In certain countries medical, dental and vision is fully covered for employees & their dependents. This is country and plan specific.</p><p style="min-height:1.5em">*401k is for United States employees only</p><p style="min-height:1.5em"></p><p style="min-height:1.5em">Polygon Labs is committed to a diverse and inclusive workplace and is an equal opportunity employer. We do not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. Polygon Labs is committed to treating all people in a way that allows them to maintain their dignity and independence. We believe in integration and equal opportunity. Accommodations are available throughout the recruitment process and applicants with a disability may request to be accommodated throughout the recruitment process. We will work with all applicants to accommodate their individual accessibility needs.</p><p style="min-height:1.5em">If you think you have what it takes, but don't necessarily meet every single point on the job description, please still get in touch. We'd love to have a chat and see if you could be a great fit.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>Learn More about Polygon Labs</strong></p><p style="min-height:1.5em"><a target="_blank" rel="noopener noreferrer nofollow" href="https://polygon.technology/"><strong><u>Website</u></strong></a><strong> |</strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/0xPolygon"><strong><u>Twitter</u></strong></a><strong>|</strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://t.me/polygonofficial"><strong><u>Telegram</u></strong></a><strong> |</strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.reddit.com/r/0xpolygon/"><strong><u>Reddit</u></strong></a><strong> |</strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://discord.gg/0xpolygoncommunity"><strong><u>Discord</u></strong></a><strong> |</strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.instagram.com/0xpolygon/"><strong><u>Instagram</u></strong></a><strong> |</strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.facebook.com/0xPolygon.Technology"><strong><u>Facebook</u></strong></a><strong> |</strong><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.linkedin.com/company/13449964/admin/"><strong><u>LinkedIn</u></strong></a></p><p style="min-height:1.5em"></p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...