Aave is looking for a Protocol Security Researcher to help build its internal protocol security function.
The role sits at the intersection of smart contract security, protocol design, adversarial research, and AI-assisted review. You will help assess major protocol changes before deployment, maintain security context across Aave’s deployed systems, and reason about the risks introduced by critical dependencies, integrations, and Aave-adjacent infrastructure.
This is not a narrow audit role. The goal is to improve Aave’s ability to understand and reduce protocol risk continuously.
How you can make an impact:
- Review major Aave protocol changes before external audit or deployment
- Perform attacker-driven analysis of smart contracts, protocol mechanisms, and integrations
- Participate in design and architecture discussions early enough to influence security-relevant decisions
- Identify risks in Aave-adjacent systems, including assets, bridges, oracles, adapters, and critical dependencies
- Contribute to AI-assisted security tooling and evaluate its effectiveness in real review workflows
- Turn review findings into reusable knowledge, invariants, assumptions, and testing or monitoring ideas
- Work with monitoring and incident response teams when review findings imply operational detection or response needs
- Collaborate with external auditors by helping define scope, known risks, and areas of concern
Let's connect if you have:
- 5+ years of relevant security experience
- Strong smart contract security background
- Ability to independently review complex codebases and reason about protocol-level failure modes
- Attacker mindset: you can move from “this looks wrong” to “this is how it could be exploited”
- Strong understanding of DeFi mechanisms, including lending, liquidations, accounting, oracles, collateral, governance, and integrations
- Evidence that you are actively using AI to improve security research, review quality, or review throughput
- Clear written communication: you can explain risk, impact, uncertainty, and trade-offs to engineers and non-security stakeholders
- Good judgment about severity, exploitability, and when a finding matters
Nice to haves:
- Experience with formal methods, fuzzing, invariant testing, or custom security tooling
- Experience building internal tools for security review, code understanding, or knowledge management
- Experience working with external audit firms or leading audit engagements
- Familiarity with governance payloads, upgrade systems, permissioning, and incident response
- Open-source security research, published findings, CTFs, bug bounties, or prior public vulnerability research
Skills Required
- 5+ years of relevant security experience
- Strong smart contract security background
- Ability to independently review complex codebases and reason about protocol-level failure modes
- Ability to analyze risks from an attacker’s perspective and explain how they could be exploited
- Strong understanding of DeFi mechanisms, including lending, liquidations, accounting, oracles, collateral, governance, and integrations
- Evidence of actively using AI to improve security research, review quality, or review throughput
- Clear written communication with technical and non-technical stakeholders
- Sound judgment regarding severity, exploitability, and significance of findings
- Experience with formal methods, fuzzing, invariant testing, or custom security tooling
- Experience building internal tools for security review, code understanding, or knowledge management
- Experience working with external audit firms or leading audit engagements
- Familiarity with governance payloads, upgrade systems, permissioning, and incident response
- Open-source security research, published findings, CTFs, bug bounties, or public vulnerability research
What We Do
Aave Labs is the original author and key contributor of the Aave Protocol and a software technology company founded by Stani Kulechov. The team builds blockchain-based products that power decentralized finance, including the Aave Protocol, the Aave-native stablecoin GHO, and Horizon, an institutional platform for borrowing against tokenized real-world assets. Aave is DeFi’s largest and most trusted lending protocol, where users can earn, borrow, save, and swap alongside millions of others worldwide.








