Super Complicated Job Requirements

Shashank Mudgal
@0x00auditor
Published: Aug 24, 2026
Updated: Aug 30, 2026
Views: 91

Hey Blockchain and tech freaks,

It's nice to be here and interact with you all. Today I saw a Web3 VAPT Job Posting. They wanted the person to be awesome in web3 security at the same time should know Android and IOS app testing. Web Application Security and should know Web2 OWASP top 10 , AP testing & what not.

Do you guys think such JD's actually make sense. Another question, suppose, a guy is good at werb3 security but do not have a slightest clue of these web2 security should he apply and does he have a chance in securing this job?

Replies

Welcome, guest

Join ArtofBlockchain to reply, ask questions, and participate in conversations.

ArtofBlockchain powered by Jatra Community Platform

  • Shubhada Pande

    @ShubhadaJP Aug 25, 2026

    Honestly, JDs like this happen for two reasons: either the team wants a one-man security department to save money, or HR just combined three different security roles into one post.

    To answer your question: yes, absolutely apply. Most projects will happily take someone who is genuinely good at smart contract security and teach them the basics of API/Web2 testing on the job.

    If you have proof of work (Immunefi submissions, audit reports, CTFs), that matters way more than checking every single buzzword on a generic JD. Don’t filter yourself out.


    Shashank Mudgal

    @0x00auditor Aug 26, 2026

    Thank you Ma'am, working on the proofs.

  • AlexDeveloper

    @Alexdeveloper Aug 26, 2026

    Honestly just go ahead and apply.

    Most of these vague JDs happen because non-tech founders or HR literally Google "security requirements" and copy-paste everything into one post. They want a unicorn on a single salary.

    I would say "don't try to fake the web2/mobile stuff. Put your smart contract audits or CTF stuff right at the top of your resume. When you get on the call, just be upfront: "Look, my core strength is finding protocol-draining bugs in solidity/EVM. I know the basics of web attack vectors, but on-chain logic is my actual edge."

    Any tech lead with a brain knows finding good smart contract auditors is 10x harder than finding standard web pentesting. and honestly, if they reject you because you can't reverse engineer an iOS app while securing their DeFi pools, you probably dodged a mess of a job where you'd be blamed for everything.

    Curious if anyone here got hired for a hybrid role like this and actually had to do both?

    Shashank Mudgal

    @0x00auditor Aug 26, 2026

    Thank you Alex, I am currently a learning smart contract security and saw this JD and it concerns me that what are trying to accomplish with JD.