Senior Rust Backend Engineer — Applied Cryptography & Secure APIs (with some WebAssembly)
Worldwide
OVERVIEW We are building a secure, high-integrity content system from the ground up in Rust. This is a from-scratch build: a Rust backend service and API that encrypts content and issues/verifies signed access grants, plus a smaller client-side WebAssembly component that decrypts content in the browser. The majority of the work is backend/API — the encryption service, key handling, grant issuing and verification, and streaming. The WebAssembly piece is one focused component on top of that, not the center of the role. The core is being written rapidly with the help of AI coding agents supervised by our lead engineer. We want a senior Rust engineer who builds fast but reviews like a security engineer — someone with the instinct to spot the subtle cryptographic flaw, whether in their own code or in generated code. WHAT YOU'LL BUILD The Rust backend service and API: content encryption (AES-256-GCM), key wrapping, and a signed-grant system that authorizes each read Key handling and lifecycle done correctly — nonce/IV discipline, constant-time operations, no key material lingering where it shouldn't Session-bound access: server-side windowing, throttling, and anomaly detection on the API A smaller Rust → WebAssembly component that performs client-side decryption, hardened against reverse-engineering and automated analysis Alongside our lead: review AI-generated Rust for soundness and security — unsafe blocks, FFI boundaries, memory-safety invariants REQUIRED Senior Rust — demonstrable production or open-source work, not tutorial-level Backend / API engineering in Rust — async services (Axum or Actix-web; tokio), typed data access, real production API work Applied cryptography in Rust — hands-on with AEAD (AES-GCM), key wrapping, nonce/IV discipline, constant-time code, and the common misuse pitfalls. Familiarity with ring, aws-lc-rs, and/or RustCrypto (aes-gcm, rsa, sha2, hkdf) Experience reviewing/auditing Rust — unsafe review and soundness analysis Some Rust → WebAssembly — wasm-bindgen / wasm-pack, and an understanding of what Wasm does and does not protect in the browser Fluency in at least one other statically-typed backend/systems language (Java, Kotlin, C++, Swift, or Go) STRONGLY PREFERRED Security research, pen-testing, or anti-tamper / RASP background Wasm obfuscation / diversification (wasm-mutate), LLVM-level obfuscation, or opaque-predicate techniques Byte-level document / binary-format, parsing, or serialization work Experience supervising or reviewing AI-coding-agent output FRAMEWORKS / STACK Rust async backend (Axum or Actix-web; tokio), typed data access (sqlx-style) Crypto: ring / aws-lc-rs / RustCrypto Client component: Rust compiled to WebAssembly via wasm-bindgen / wasm-pack Hardening: wasm-mutate diversification, LLVM-IR obfuscation, symbolic-execution-resistant predicates
- Less than 30 hrs/weekHourly
- 1-3 monthsDuration
- ExpertExperience Level
$15.00
-
$50.00
Hourly- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Last viewed by client:3 weeks ago
- Hires:2
- Interviewing:4
- Invites sent:0
- Unanswered invites:0
About the client
- United StatesBellmore3:58 PM
- $659K total spent223 hires, 81 active
- 19,773 hours
- EducationMid-sized company (10-99 people)
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by