Specialty Software Engineer 3 - Contingent

PTR Global
Concord, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$124,800.0 - $145,600.0
Working hours
Regular working hours
Job source

Tech stack

Business Logic Cloud Computing Digital Assets Disaster Recovery Hardware Security Module Information Systems Security Architecture Professional Key Management OpenID Software Engineering Build Management Kubernetes

Job description

  • Client is engineering a next-generation Digital Asset Platform designed to solve the "Approval-to-Execution Gap" in institutional finance: ensuring that digital asset transactions are signed only when strictly authorized by policy, without exposing private keys to cloud operators or insiders.
  • Client is moving beyond standard hot wallets to build an institutional-grade Confidential Custody Infrastructure.
  • Client’s platform combines Multi-Party Computation (MPC) with hardware-enforced Confidential Computing (TEEs) to create a "glass vault"-a system where key operations are cryptographically isolated, attestable, and mathematically proven secure.

Responsibilities:

  • MPC Protocol Implementation: Architect and implement high-performance threshold signature schemes (specifically DKLS23 or similar) for ECDSA key generation and signing.
  • Confidential Computing Architecture: Design and build services that run inside Trusted Execution Environments (TEEs), specifically targeting AMD SEV-SNP and Intel TDX via Confidential Containers (CoCo).
  • Attestation Framework: Implement the RATS (Remote Attestation Procedures) architecture (RFC 9334) to ensure that no key share is released until the requesting node proves its hardware and software integrity to a Key Broker Service.
  • Hardware Security Integration: Design "Cold Ceremony" workflows that integrate offline hardware tokens as offline Key Encryption Keys (KEKs) for disaster recovery and deep storage.
  • Secure Enclave Development: Write and optimize memory-safe code (Rust/Go) that operates on key material exclusively within encrypted memory regions, ensuring zero leakage to the host OS or hypervisor.
  • Policy-to-Cryptography Binding: Design mechanisms to cryptographically bind business logic approvals (e.g., WebAuthn assertions) directly to the MPC signing session, eliminating the gap between "approval" and "execution"., * Consult on or participate in moderately complex initiatives and deliverables within Specialty Software Engineering and contribute to large-scale planning related to Specialty Software Engineering deliverables.
  • Review and analyze moderately complex Specialty Software Engineering challenges that require an in-depth evaluation of variable factors.
  • Contribute to the resolution of moderately complex issues and consult with others to meet Specialty Software Engineering deliverables while leveraging solid understanding of the function, policies, procedures, and compliance requirements.
  • Collaborate with client personnel in Specialty Software Engineering.

Requirements

  • 7 plus years of experience in systems-level engineering, with expert proficiency in Go (for orchestration) and Rust (for cryptographic primitives).

Applied Cryptography:

  • Deep experience implementing Threshold Cryptography and Multi-Party Computation (MPC).
  • Candidate should be comfortable implementing papers like GG20 from scratch.

Confidential Computing:

  • Hands-on experience with TEE technologies, specifically Confidential Containers (CoCo), AMD SEV-SNP, or Intel SGX/TDX.
  • Candidate must understand attestation flows, measurements, and memory encryption.

Attestation Standards:

  • Familiarity with the RATS architecture and components like Key Broker Services (KBS) and Attestation Services (AS).

Secure Architecture:

  • Experience designing "Defense-in-Depth" systems where infrastructure (Kubernetes/Cloud) is treated as untrusted.

Preferred (Nice-to-Haves):

  • Experience with OIDC/Identity standards (integrating WebAuthn/FIDO2 with cryptographic operations).
  • Familiarity with CNCF Trustee or similar attestation frameworks.
  • Experience in institutional custody, key management, or high-security fintech environments., * 4 plus years of Specialty Software Engineering experience, or equivalent demonstrated through one or a combination of the following: work or consulting experience, training, military experience, education.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · WWC 2022

1:32 min

Decoupling business logic with policy as code

Anderson Dadario +1 · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all