Principal Security Engineer
Mlabs Ltd
New York, NY, United States
19 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.indeed.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$160,000.0 - $240,000.0
Working hours
Regular working hours
Job source
Tech stack
Amazon Web Services
Authentication Protocols
Cyber Security
Continuous Integration
Distributed Systems
Cryptographic Protocols
Key Management
Network Protocols
Blockchain
Software Engineering
TypeScript
Cloud Platform System
+1 more
Infrastructure as Code (IaC)
Job description
- Architectural Leadership: Lead product security architecture, ensuring security principles are embedded into core platform design and development cycles.
- Core Infrastructure Security: Analyze and secure key management systems, transaction pipelines, and signing workflows across modern distributed networks.
- Threat Modeling & Review: Perform system-level threat modeling for new product features, protocols, and multi-chain integrations.
- Cryptographic & Auth Security: Design and evaluate security-sensitive components, including authentication protocols, authorization frameworks, and applied cryptographic workflows.
- Defense-in-Depth: Define, implement, and maintain multi-layered security controls across the application, infrastructure, and protocol layers.
- Supply Chain & Environment Security: Own and expand end-to-end software supply-chain security, spanning dependency scanning in CI pipelines to local developer environments.
- Infrastructure as Code (IaC): Enforce security configurations into version-controlled repositories to prevent configuration drift and enhance auditability.
- Risk Research & Mitigation: Investigate emerging security risks related to blockchain protocols, institutional custody models, and novel cryptographic techniques.
- Compliance & Audits: Support ongoing SOC 2, ISO 27001, and ISO 22301 compliance frameworks alongside expanding control surfaces.
- Technical Enablement & Incident Response: Provide day-to-day guidance to engineering teams to make secure patterns accessible, while supporting incident response and root-cause analysis when necessary.
- External Representation: Participate in security architecture reviews with tier-one banking partners, external auditors, and enterprise clients.
- Industry Thought Leadership: Contribute to technical research, whitepapers, and conference presentations to advance the digital asset security field.
Requirements
- Experience: 10+ years in security engineering, product security, or security architecture roles.
- Domain Expertise: Demonstrated track record of securing financial infrastructure, institutional blockchain platforms, or both.
- Cryptographic Systems: Deep understanding of cryptographic protocols, wallet architectures, and key management frameworks. Direct experience with Multi-Party Computation (MPC), threshold signatures, or HSM-backed solutions is strongly preferred.
- Threat Modeling: Extensive experience performing comprehensive system-level threat models and architecture reviews.
- Infrastructure & Networks: Solid foundational knowledge of distributed systems, networking protocols, and cloud computing platforms (primarily AWS).
- Supply Chain & IaC: Hands-on experience implementing software supply-chain defenses and managing security configurations via code to prevent drift.
- Compliance & Frameworks: Familiarity with maintaining live audit cycles for frameworks such as SOC 2, ISO 27001, ISO 22301, and the NIST Cybersecurity Framework.
- Development Skills: Professional familiarity with modern backend languages such as Rust or TypeScript.
- Communication: Exceptional ability to communicate complex security concepts effectively to both internal engineering teams and external enterprise stakeholders., * Critical Thinking
- Verbal Reasoning
- Attention to Detail (Textual)
- Numerical Reasoning
- Problem Solving
-
(Note: Practice questions are provided prior to each timed 10-minute section).
- Take-Home Technical Exercise: A practical assignment designed to assess technical problem-solving and architectural design capabilities.
- Group Technical Interview (120 mins): A multi-part panel review covering
Benefits & conditions
Pulled from the full job description Health insurance Paid time off, * Competitive executive-level compensation package.
- Flexible, remote-first work environment.
- Comprehensive health, wellness, and benefits coverage tailored to regional standards.
- Generous paid time off (PTO) and personal Leave policy.
- Professional development budget for security research, certifications, and industry conferences.
- Exposure to cutting-edge cryptographic engineering alongside leading global financial institutions.
Interview Process
The selection process for this position consists of the following structured phases:
- Initial Screening Call (30 mins): Introductory discussion with the Co-CEO to align on background, expectations, and role scope.
- Cognitive & Skills Assessment (45 mins): A series of brief, timed assessments via TestGorilla evaluating
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
CH
Chris Heilmann
almost 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
10 days ago
CH
Chris Heilmann
Dev Digest 121 - AI goes offline
about 2 years ago