Principal Security Engineer - Crypto and Digital Assets
Remote · Full Time
Be the first to apply
- Experience
- 6+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 5 days ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
We are seeking a Principal Security Engineer with in-depth expertise in the cryptocurrency domain to lead the security efforts across our regulated digital asset operations. This position is pivotal as we expand our offerings in spot trading, custody, staking, and on-chain services. The security of these digital asset services is fundamental and will be owned end-to-end by you.
Key Responsibilities
- Take full ownership of the crypto platform's custody and on-chain layer, covering architecture, engineering, operational security, and adherence to regulations.
- Manage all aspects of the custody stack: multi-party computation (MPC) key management, transaction authorization mechanisms, signing quorums, address whitelisting, and withdrawal restrictions.
- Oversee segregation of hot and cold wallets, execute key ceremonies, and manage delegated cold custodianship.
- Design and secure staking architecture along with on-chain deposit and withdrawal processes.
- Collaborate with infrastructure security, application security, and identity and access management teams to define and embed crypto-specific security hardening requirements within cloud (AWS preferred), application lifecycle, and privileged access management.
- Lead threat detection by developing custody- and blockchain-specific detection rules for Security Operations Center (SOC) monitoring and alerting systems.
- Own incident response concerning crypto-related incidents such as key compromises, unauthorized transactions, and on-chain security events, working alongside corporate security for forensic analysis and breach reporting.
- Contribute to penetration testing and red-teaming initiatives targeting custody and blockchain functionality.
- Lead evaluation and ongoing security assurance of third-party crypto vendors including custody platforms, execution systems, blockchain analytics, compliance tooling, and treasury software.
- Manage regulatory mapping specific to crypto regulations including MiCA, DORA, and FCA rules, and coordinate with governance teams on compliance frameworks like ISO 27001, SOC 2, NIST CSF, and GDPR.
- Support business continuity and disaster recovery strategies for crypto services and maintain crypto-specific security policies.
Qualifications and Experience
- At least 6 years in information security with recent senior roles such as security engineer, architect, or lead.
- Direct hands-on experience securing cryptocurrency platforms, digital asset custody services, or regulated financial platforms with a strong grasp of blockchain security concepts, wallet architectures, and key management.
- Solid foundation in cloud security, preferably AWS, within regulated environments.
- Proficient knowledge of security standards and compliance for regulated finance, including ISO 27001, SOC 2, and NIST.
- Experienced in performing threat modeling, risk analyses, and incident management.
- Comfortable working in a matrixed environment partnering with specialized security teams rather than owning all disciplines.
Preferred Additional Skills
- Hands-on expertise with Kubernetes, containers, API security, and infrastructure as code.
- Python scripting proficiency for automation and tooling.
- Experience managing third-party security vendor assessments.
- Certified credentials such as CISSP, CISM, or CCSP.
- Experience with MPC custody solutions, key ceremony orchestration, and signing policy design.
- Familiarity with crypto-specific regulations like MiCA, DORA, and FCA frameworks.
- Applied knowledge in secure software development lifecycle and DevSecOps practices.
- Expertise in smart contract security reviews, including threat modeling, managing external audit processes, and resolving audit findings.
- Designing secure transaction signing and approval workflows ensuring transactional integrity.
- Ability to analyze business logic flaws affecting money flow such as withdrawal sequences and ledger integrity.
- Understanding of supply chain security for crypto dependencies like wallet SDKs, node clients, and signature tools, including version control and provenance tracking.
- Experience defining bug bounty programs for crypto assets and managing vulnerability triage for on-chain issues.
Soft Skills
- Excellent analytical and problem-solving abilities.
- Capability to translate complex technical risks into understandable business impact and regulatory implications.
- Effective communication skills for explaining security risks to non-technical stakeholders and regulators.
- Collaborative mindset working across risk, compliance, product, and engineering teams.
- Strong documentation and interpersonal communication proficiency.
What We Offer
- Competitive salary designed to reward talent and effort.
- Focus on work-life balance supporting your personal and professional needs.
- Generous vacation policy to ensure time to recharge.
- Employee referral program with incentives for recommending qualified candidates.
- Comprehensive health insurance and pension benefits, with location-specific perks.
- Opportunity for remote work from anywhere in the world up to 30 additional days annually (subject to conditions).
- Two paid volunteer days each year to support community or personal causes.
Additional Information
This company values innovation and talent, offering a collaborative environment where you will be part of a leading team in the digital assets industry. Artificial intelligence tools may be used during the recruitment process to assist evaluations, but final decisions will always be made by humans.
Industry
FinTech