MT
Blockchain Developer
Accepting applicationsMcKinley's Tech N Trade International USA · India
Contract Entry
Estimated market salary
₹4-6 LPA
This is a SiliconBoard market estimate, not an employer-posted salary.
Posted
2d ago
Category
Verification
Experience
Entry
Country
India
Company Description
McKinley's Tech N Trade International USA, operating as McKinley's Technologies, is a smart contract security and blockchain assurance firm dedicated to supporting serious Web3 teams. The company specializes in rigorous audits across major blockchain languages, helping organizations build, launch, and scale with confidence. Services include pre-audit assessments, detailed code reviews, and remediation-focused guidance to strengthen security and reliability. Team members collaborate with innovative clients in the Web3 ecosystem, contributing to the integrity and resilience of decentralized applications.
Role Description About the Role
You'll spend most of your time reading code adversarially, hunting for the logic flaw, the missed edge case, the economic assumption that breaks under pressure. You'll own findings end to end: discovery, proof of concept, write-up, and remediation verification with the client's engineering team.
This is a role for someone who enjoys the puzzle. Tools help, but the findings that matter come from understanding what the protocol is supposed to do and where that intent diverges from what the code actually does.
Key Responsibilities
- Perform manual, line-by-line security reviews of smart contracts in Solidity
- Conduct threat modelling and architecture review at the start of each engagement, trust assumptions, privileged roles, upgrade paths, external dependencies
- Analyse protocol-level and economic risk: oracle manipulation, MEV and sandwiching, liquidation logic, governance capture, cross-chain and bridge assumptions
- Write proof-of-concept exploits in Foundry or Hardhat to demonstrate impact concretely
- Apply fuzzing, invariant testing, static analysis, and (where appropriate) symbolic execution or formal methods to supplement manual review
- Produce clear, well-reasoned audit reports: reproducible findings, severity ratings grounded in impact and likelihood, and remediation guidance a developer can act on
- Run client-facing calls, kickoff, findings walkthrough, and fix review and defend or revise severity ratings under challenge
- Verify remediations and confirm fixes don't introduce new issues
- Peer-review teammates' findings before reports ship
- Contribute to internal methodology: checklists, tooling, and a shared knowledge base of vulnerability patterns
- Track live incidents and post-mortems, and feed lessons back into how we audit
Required Qualifications & Experience
- 2–4 years of hands-on experience in smart contract development/security, EVM protocol engineering, or a closely related security discipline
- A demonstrable track record, at least one of:
- Published audit reports (solo, team, or firm-attributed)
- Strong placements in competitive audits (Code4rena, Sherlock, Cantina, CodeHawks)
- Validated bug bounty submissions (Immunefi or equivalent)
- Significant security research, disclosed vulnerabilities, or well-regarded open-source tooling
- Deep working knowledge of Solidity and EVM internals: storage layout, delegatecall and proxy patterns, gas mechanics, ABI encoding, low-level calls
- Practical understanding of DeFi primitives : AMMs, lending markets, vaults (ERC-4626), staking, liquid staking, bridges, oracles and the common failure modes of each
- Fluency with the standard toolchain: Foundry, Hardhat, Slither, Echidna or Medusa, and Tenderly or equivalent
- Bachelor's degree in Engineering, Mathematics, or a related field or equivalent demonstrated ability. We weight portfolio and technical assessment far more heavily than credentials.
Professional
- Technical writing. A finding nobody understands doesn't get fixed. Report quality is a core deliverable, not an afterthought.
- Client communication. Explaining a critical issue to a stressed founder on a deadline requires clarity and tact.
- Precision and follow-through. Missed findings have direct financial consequences.
- Independent judgement. You'll often be the only person looking at a given contract.
- Discretion. All engagements are under NDA; unreleased code and unfixed vulnerabilities stay confidential and proprietary.
Department / Team - Security Research & Audit
Work Arrangement - Remote
Show more Show less
McKinley's Tech N Trade International USA, operating as McKinley's Technologies, is a smart contract security and blockchain assurance firm dedicated to supporting serious Web3 teams. The company specializes in rigorous audits across major blockchain languages, helping organizations build, launch, and scale with confidence. Services include pre-audit assessments, detailed code reviews, and remediation-focused guidance to strengthen security and reliability. Team members collaborate with innovative clients in the Web3 ecosystem, contributing to the integrity and resilience of decentralized applications.
Role Description About the Role
You'll spend most of your time reading code adversarially, hunting for the logic flaw, the missed edge case, the economic assumption that breaks under pressure. You'll own findings end to end: discovery, proof of concept, write-up, and remediation verification with the client's engineering team.
This is a role for someone who enjoys the puzzle. Tools help, but the findings that matter come from understanding what the protocol is supposed to do and where that intent diverges from what the code actually does.
Key Responsibilities
- Perform manual, line-by-line security reviews of smart contracts in Solidity
- Conduct threat modelling and architecture review at the start of each engagement, trust assumptions, privileged roles, upgrade paths, external dependencies
- Analyse protocol-level and economic risk: oracle manipulation, MEV and sandwiching, liquidation logic, governance capture, cross-chain and bridge assumptions
- Write proof-of-concept exploits in Foundry or Hardhat to demonstrate impact concretely
- Apply fuzzing, invariant testing, static analysis, and (where appropriate) symbolic execution or formal methods to supplement manual review
- Produce clear, well-reasoned audit reports: reproducible findings, severity ratings grounded in impact and likelihood, and remediation guidance a developer can act on
- Run client-facing calls, kickoff, findings walkthrough, and fix review and defend or revise severity ratings under challenge
- Verify remediations and confirm fixes don't introduce new issues
- Peer-review teammates' findings before reports ship
- Contribute to internal methodology: checklists, tooling, and a shared knowledge base of vulnerability patterns
- Track live incidents and post-mortems, and feed lessons back into how we audit
Required Qualifications & Experience
- 2–4 years of hands-on experience in smart contract development/security, EVM protocol engineering, or a closely related security discipline
- A demonstrable track record, at least one of:
- Published audit reports (solo, team, or firm-attributed)
- Strong placements in competitive audits (Code4rena, Sherlock, Cantina, CodeHawks)
- Validated bug bounty submissions (Immunefi or equivalent)
- Significant security research, disclosed vulnerabilities, or well-regarded open-source tooling
- Deep working knowledge of Solidity and EVM internals: storage layout, delegatecall and proxy patterns, gas mechanics, ABI encoding, low-level calls
- Practical understanding of DeFi primitives : AMMs, lending markets, vaults (ERC-4626), staking, liquid staking, bridges, oracles and the common failure modes of each
- Fluency with the standard toolchain: Foundry, Hardhat, Slither, Echidna or Medusa, and Tenderly or equivalent
- Bachelor's degree in Engineering, Mathematics, or a related field or equivalent demonstrated ability. We weight portfolio and technical assessment far more heavily than credentials.
Professional
- Technical writing. A finding nobody understands doesn't get fixed. Report quality is a core deliverable, not an afterthought.
- Client communication. Explaining a critical issue to a stressed founder on a deadline requires clarity and tact.
- Precision and follow-through. Missed findings have direct financial consequences.
- Independent judgement. You'll often be the only person looking at a given contract.
- Discretion. All engagements are under NDA; unreleased code and unfixed vulnerabilities stay confidential and proprietary.
Department / Team - Security Research & Audit
Work Arrangement - Remote
Show more Show less