gm
.careers
Back to Roles

Smart Contract Auditor

Learning path available
Highly Remote

Smart Contract Auditors are security specialists who review and analyze smart contract code to identify vulnerabilities, logic errors, and potential exploits. They protect protocols and users by ensuring code is secure before deployment.

Key Responsibilities

  • Conduct comprehensive security audits of smart contracts and DeFi protocols
  • Identify vulnerabilities including reentrancy, access control, and economic exploits
  • Write detailed audit reports with severity classifications and remediation guidance
  • Develop and maintain automated security tooling and fuzzing infrastructure
  • Research new attack vectors, exploits, and security patterns in the ecosystem
  • Collaborate with development teams to implement security fixes and best practices

Hiring expectations

These describe experienced roles. Requirements vary by employer; use the learning path below to build toward them.

  • 3+ years of smart contract development or security research experience
  • Expert-level Solidity knowledge including assembly and low-level EVM operations
  • Experience with security tools (Slither, Mythril, Echidna, Foundry fuzzing)
  • Track record of finding vulnerabilities through bug bounties or CTF competitions
  • Strong understanding of DeFi mechanics, flash loans, and economic attack vectors

Skills & Technologies

Solidity
Security Auditing
Fuzzing
Formal Verification
Slither
DeFi
Learn. Practice. Build.3 steps + a portfolio project

Courses & learning path

For Solidity developers moving into security research and contract review.

Before you start

  • Strong Solidity and EVM knowledge, including storage and external calls.
  • Comfort with Foundry, fuzzing basics and reading unfamiliar code.

New to Solidity? Start with the Solidity Developer learning path, then build experience with testing before taking on security review.

Start with Solidity development
See what you’ll build
  1. Learn a review process

    Develop a method for manual review, invariants and reproducible findings.

    Cyfrin UpdraftFree

    Smart Contract Security

    Advanced · Video + practice audits

    24 hours of course content

    Open on Cyfrin Updraft: Smart Contract Security (opens in a new tab)
    Access & course details: Smart Contract Security
    Access
    Free provider account
    Language
    English; translations available
    Credential
    Provider achievement available
    Reviewed
    Sep 18, 2026

    Put it into practice: Follow a practice audit and write down the system assumptions before looking for bugs.

  2. Recognize failure patterns

    Explore deliberately vulnerable contracts through focused security challenges.

    OpenZeppelinFree

    Ethernaut

    Intermediate · Security challenges

    Time varies by challenge

    Open on OpenZeppelin: Ethernaut (opens in a new tab)
    Access & course details: Ethernaut
    Access
    Wallet and test network for browser challenges
    Language
    English
    Credential
    Focus on challenge write-ups
    Reviewed
    Sep 18, 2026

    Put it into practice: Document the root cause and a possible fix for three solved levels.

  3. Reason about DeFi systems

    Practice finding issues that depend on interactions between contracts and economic assumptions.

    The Red GuildFree

    Damn Vulnerable DeFi

    Advanced · Security challenges

    Time varies by challenge

    Open on The Red Guild: Damn Vulnerable DeFi (opens in a new tab)
    Access & course details: Damn Vulnerable DeFi
    Access
    Public code; local development setup
    Language
    English
    Credential
    Focus on challenge write-ups
    Reviewed
    Sep 18, 2026

    Put it into practice: Reproduce one challenge locally and add a regression test for your proposed fix.

Your portfolio project

A reproducible practice audit

Review a deliberately vulnerable training project and write a report another engineer can verify.

What to include

  • A clear scope and summary of the system assumptions.
  • Findings with impact, reproduction steps and working tests.
  • Suggested mitigations with a regression test and remaining limitations.

Explain why each finding matters and how you ruled out a false positive. Training exercises do not establish readiness to audit production funds.

Selected by gm.careers for relevance and practical learning. Levels reflect our suggested sequence. Listed course times come from providers; allow extra time for practice. Provider credentials are separate from professional experience.

Report an outdated resource

Salary Range

$180,000 - $300,000

Editorial annual USD estimate, not a measured salary sample.

View Salary Details

Quick Stats

Job Demand · Editorial
High Demand
Remote Work
Highly Remote

Find Security Auditor Jobs

Browse open positions and start your Web3 career today.

View Security Auditor Jobs