Cantina (cantina.xyz) Logo

Cantina (cantina.xyz)

Cantina Triager

Posted 8 Days Ago
Be an Early Applicant
Remote
29 Locations
Junior
Remote
29 Locations
Junior
As a Bug Bounty Triager, you'll review and validate vulnerability reports, assess their impact, communicate with researchers, and improve the bounty program.
The summary above was generated by AI
About Spearbit & Cantina:

Founded in 2021 by former Ethereum Foundation Solidity engineers, Spearbit tackles Web3 security challenges. Our founding team built the leading blockchain language and secured the largest smart contract, protecting over $160B in value.

We're building Cantina, the "GitHub for Security", connecting security researchers with projects needing expertise. Our Cantina security platform has powered major competitions and serves the leading projects in Web 3. It currently supports collaborative security reviews, public and private security competitions, bug bounty programs, incident response, and AI code analyzer.

Similar to how cloud-security startups emerged previously, Cantina aims to be the definitive code-security platform for the future.

The Opportunity: We’re looking for a Bug Bounty Triager to join our team. In this role, you’ll be the first line of defense in reviewing vulnerability submissions, ensuring both speed and technical accuracy. Your work will help maintain the integrity of Cantina’s bounty ecosystem, foster trust between projects and whitehats, and raise the bar for security practices across the industry.

What you'll do:
  • Review, reproduce, and validate incoming vulnerability reports across smart contracts, DeFi protocols, and blockchain systems.

  • Assess severity and impact in the context of each project’s unique architecture and threat model.

  • Communicate with researchers to clarify missing details and provide constructive feedback on invalid or incomplete submissions.

  • Write clear and concise summaries for each validated report, including reproduction steps, impact analysis, and recommended mitigations.

  • Partner with Cantina’s program managers to ensure smooth workflows between security researchers, project teams, and internal stakeholders.

  • Contribute to the design and continuous improvement of Cantina bounty programs, workflows, and tooling.

  • Support other Cantina Security services that require triaging expertise.

  • Serve as a trusted bridge between projects and whitehats, balancing fairness, transparency, and accuracy in outcomes.

What we’re looking for:
  • Strong foundation in smart contract security, including common vulnerability classes and exploitation techniques.

  • Ability to read and analyze Solidity and other EVM-compatible languages; familiarity with Rust-based blockchains (e.g., Solana, Substrate) or other blockchain infrastructure.

  • Experience reviewing code bases, identifying vulnerabilities, and reproducing exploits.

  • Understanding of DeFi mechanisms (e.g., AMMs, lending protocols, bridges) and ability to quickly learn new protocol designs.

  • Familiarity with vulnerability disclosure workflows and bug bounty ecosystems.

  • Excellent written communication: able to explain technical issues clearly, neutrally, and with professionalism to both security engineers and non-technical stakeholders.

  • Detail-oriented and organized, able to manage a steady flow of incoming reports while maintaining high accuracy.

Benefits
  • Competitive salary and performance-based compensation opportunities

  • Opportunity to work in an early-stage startup with a talented and passionate team

  • Exposure to high-profile clients in the blockchain and cryptocurrency industry

  • Comprehensive health, dental and vision benefits

  • 401k matching program

Join Spearbit and help us build the future of code security!

Top Skills

Blockchain Systems
Evm-Compatible Languages
Rust
Solidity

Similar Jobs

14 Hours Ago
Easy Apply
Remote
28 Locations
Easy Apply
Mid level
Mid level
Cloud • Security • Software • Cybersecurity • Automation
The Developer Relations Program Manager will develop and lead the implementation of the Education program, advocate for the education community, and align with Developer Relations and Marketing goals to drive growth and contributions.
Yesterday
Remote
28 Locations
Senior level
Senior level
Security • Software • Cybersecurity • Automation
As a Senior Enterprise Solutions Architect, you'll ensure successful implementations of Drata's platform, providing technical expertise and enhancing customer satisfaction through collaboration and complex integrations.
Top Skills: AWSAzureBashGCPJavaScriptJSONNode.jsPythonReactRest ApisShellTypescriptUnix
Yesterday
Remote
28 Locations
Entry level
Entry level
Machine Learning • Natural Language Processing
As a Dutch Expert Rater, you will review online ads to improve their relevance and usefulness, contributing to AI training and quality standards.
Top Skills: Ai SystemsOnline Ads

What you need to know about the Belfast Tech Scene

If asked to name the birthplace of the RMS Titanic, you might not say Belfast. Similarly, if asked to name Europe's leading destination for foreign direct investment in new software development, Belfast might not come to mind. Yet, both are true. The city has emerged as a tech powerhouse, recently ranked among the best in the U.K. for tech careers — especially for software developers. It also leads the U.K. with the highest percentage of software development jobs advertised.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account