Security Engineer - Digital Asset Custody
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
We are seeking a Senior Security Engineer to serve as the lead technical authority for institutional digital asset custody and cryptographic engineering. In this high-impact, hands-on individual contributor role, you will define custody architecture, drive key management strategies, and establish robust risk postures across enterprise digital asset and blockchain platforms.
You will own foundational design decisions spanning Hardware Security Modules (HSMs), Multi-Party Computation (MPC), automated policy enforcement, disaster recovery, and incident response. Operating with high autonomy, you will bridge the gap between engineering teams, security architects, compliance partners, and executive leadership in a mission-critical, high-trust environment., * Cryptographic Architecture & Key Management: Design, implement, and evolve enterprise-grade cryptographic key management architectures across HSMs and MPC frameworks; define clear trade-offs across hot, warm, and cold storage models for secure key generation, storage, signing, rotation, and recovery.
- Custody Policy Engine & Governance: Architect a deterministic, code-driven custody policy engine governing transaction limits, approvals, authorization rules, exception handling, and segregation of duties in alignment with regulatory and audit standards.
- Resilience, DR & Incident Response: Formulate and maintain custody-specific disaster recovery (DR) runbooks and failover procedures addressing key recovery, quorum loss scenarios, and blockchain network anomalies; lead post-incident technical reviews and long-term remediation.
- Custody Architecture & Scalability: Serve as the domain architecture authority, ensuring consistent security controls across diverse blockchains, smart contracts, wallet infrastructures, and tokenized products without compromising risk posture.
- Security & Audit Collaboration: Partner closely with internal Cybersecurity and external premier security audit firms (e.g., Trail of Bits, Halborn) to remediate vulnerabilities and maintain zero-trust principles.
- AI-Augmented Engineering: Utilize modern generative and agentic AI tools to accelerate threat modeling, architectural reviews, technical documentation, and test scenario generation.
Requirements
- 10+ years of software and security engineering experience, with deep specialization in cryptographic architectures and security-sensitive distributed systems.
- Proven hands-on experience designing and operating systems with Hardware Security Modules (HSMs), Multi-Party Computation (MPC) protocols, and secure key management systems.
- Strong programming proficiency in systems and cryptography implementation languages such as Go, Rust, C++, or C.
- Practical experience utilizing Web3 security and smart contract analysis tools (e.g., Slither, Mythril, Foundry Fuzzing).
- Demonstrated track record of partnering with tier-1 external security auditors and independent assessment teams.
- Proven technical leadership and architectural influence in high-risk, fault-tolerant environments without requiring formal people management authority., * Direct technical background in institutional digital asset custody platforms, wallet architectures, or public/private blockchain protocols.
- Prior experience designing and operationalizing high-availability disaster recovery runbooks, multi-signature/quorum recovery, and security incident response processes.
- Strong ability to articulate complex cryptographic and risk-based trade-offs to both executive and technical stakeholders.
- Practical exposure to applying generative AI and developer tooling to streamline threat modeling, testing, and engineering workflows.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Trustworthy AI Starts at Deployment: 5 Checks Before You Ship
Dev Digest 134 - Where pixels sing?
Dev Digest 121 - AI goes offline