Following the approval of the Arbitrum Audit Program, and the technical expert application and shortlisting process, the Arbitrum Foundation has shortlisted two candidates for the Technical Expert seat of the Audit Committee. The elections will follow the shielded voting standards described here.
As part of the approved process, an election should be conducted for the DAO to fill the Technical Expert role, who will play a significant role in operationalizing the Audit Program. The role is a paid position ($5k per month) and the expected workload is estimated at ~1-2 days per week.
The Technical Expert will be responsible for:
The following criteria were used to evaluate and shortlist the candidates:
The Arbitrum Foundation, acting in its capacity as chair of the Audit Committee, has shortlisted the following two candidates out of 68 candidates for the technical expert position, Gustavo Grieco and Andrei Andonov, alongside candidate-provided bios.
Hi, I’m Gustavo Grieco (GitHub), a freelance blockchain security engineer. I spent about eight years at Trail of Bits (TOB) working on a wide range of blockchain security projects, dedicating a significant portion of that time to reviewing the Arbitrum stack.
This included deep technical audits across several versions of the protocol, from the original Arbitrum Classic to Nitro and, more recently, Stylus. Alongside Arbitrum, I also audited various DeFi applications such as stablecoins, lending platforms, decentralized exchanges, wallets, and other core blockchain infrastructure.
I tend to keep a low profile and focus on the technical side, but I place a strong emphasis on clear communication, especially in audit reports. As a Principal Security Engineer at TOB, I was involved not only in hands-on code reviews but also in audit planning. This included defining scopes, estimating effort, selecting tools, and ensuring findings were presented with the right balance of technical depth and clarity for non-technical readers. I also participated in early-stage client discussions, which gave me a solid understanding of how audit needs evolve throughout a project’s lifecycle.
For this role, I will bring:
Hey everyone, I’m Andrei (@iamandreiski), and I have been part of the crypto space since 2017, and professionally since 2020. After various non-tech crypto roles, I pivoted to smart contract security in late 2023, working on keeping the Ethereum ecosystem safe — as my fundamental belief is that security is crucial for crypto’s future and the onboarding of new users and capital.
I bring a strong public track record as a Security Researcher, with 10+ Top-5 finishes in public audit contests, and 50+ audits. Prior to the current role, I led teams, processes and operations as a Head of Knowledge Management at Crypto.com, as well as other project management engagements.
In the spirit of transparency and showcasing my technical and research skills, as well as contributing towards ecosystem security, I’ve competed in numerous public audit contests. My public portfolio encompasses:
I’ve spent time on both sides of the fence - scaling dev/operations teams and diving deep into security research - so I bring a unique perspective to the table.
My security research experience, coupled with overseeing many projects enables me to evaluate a codebase’s maturity, potential risks, audit findings, and the overall state of the project/product. And second, through my participation in audit contests and bug bounties, I’ve gained insights into various audit companies, practices, as well as how this market operates. With all of the above, I can ensure protocols are well-prepared for audits, optimizing resource use. I’m excited about the opportunity to contribute to the Arbitrum Audit Program and strengthen its ecosystem.
https://snapshot.org/#/arbitrumfoundation.eth/proposal/0x131574819442cb6da293795ee9faeec4754a5af664b535b654b3d9d3d53f47e1