Principal Security Architect (On-Chain & Digital Assets)

Jobgether
Germany
1 day ago
Apply on www.adzuna.de
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Languages
Chinese
Job source

Tech stack

Amazon Web Services Business Analytics Applications Cloud Computing Security Cyber Security Digital Assets Hardware Security Module Identity and Access Management Python (Programming Language) Key Management Blockchain Software Engineering Cloud Platform System
+4 more
Software Security Kubernetes Web3.js Terraform

Job description

Own security architecture across the custody and on-chain layer of a regulated digital-asset platform operating globally. You will define and implement security requirements spanning architecture, engineering, operations, and regulatory assurance. The role covers critical areas including MPC and HSM key management, transaction authorization, wallet security, staking, and blockchain integrations. You will work closely with dedicated Infrastructure Security, Application Security, IAM, and SOC teams while providing specialized crypto-security leadership. Your expertise will help protect transaction flows, digital assets, and key management systems against sophisticated operational and cyber risks. You will also lead threat modeling, security assessments, incident response, and regulatory control mapping across international markets. This is a hands-on principal-level opportunity for a security architect with deep digital-asset expertise who can translate complex technical risks into resilient controls and clear business outcomes. Accountabilities

  • Own end-to-end security architecture for the custody and on-chain technology stack.
  • Define security requirements and controls for HSM and MPC-based key management, transaction authorization, signing quorums, address whitelisting, and hot/cold wallet segregation.
  • Establish secure processes for key ceremonies, delegated cold custody, staking deposits and withdrawals, and other critical digital-asset operations.
  • Develop crypto-specific security standards, privileged-access controls, and secure SDLC requirements within a multi-account AWS environment.
  • Partner with centralized Infrastructure Security, Application Security, IAM, and SOC teams to implement and maintain platform security capabilities.
  • Define blockchain and custody-specific detection use cases for the SOC.
  • Lead incident response procedures for crypto-specific scenarios, including key compromise, unauthorized transactions, and significant on-chain incidents, in collaboration with Corporate Security.
  • Conduct detailed threat modeling and security reviews covering internal ledger mechanisms, balance idempotency, withdrawal sequencing, and smart contract integrations.
  • Protect the integrity of transaction and funds flows across the platform by identifying and mitigating architectural and operational risks.
  • Direct security assessments and ongoing assurance activities for external custody providers, execution systems, blockchain analytics solutions, Travel Rule tools, and treasury integrations.
  • Map security controls to relevant international regulatory frameworks, including MiCA, DORA, FCA, and MAS requirements.
  • Collaborate with market and regulatory teams to maintain appropriate security and compliance controls as the platform expands internationally.
  • Translate complex cryptographic, infrastructure, and digital-asset risks into clear business and regulatory implications for non-security stakeholders.

Requirements

  • 10+ years of professional experience in information security, with a proven track record as a Security Architect, Principal Security Engineer, or technical security lead.
  • Demonstrated experience securing digital-asset custody platforms, high-throughput crypto environments, or regulated financial infrastructure.
  • Deep practical knowledge of crypto custody and wallet architecture, including Multi-Party Computation (MPC), Hardware Security Modules (HSMs), key ceremonies, and signing-policy design.
  • Strong cloud security expertise, preferably within AWS environments and regulated organizations.
  • Practical experience mapping security controls to recognized frameworks and regulatory requirements, including ISO 27001, SOC 2, and NIST.
  • Strong experience conducting threat modeling, security assessments, risk analysis, and incident response.
  • Ability to communicate sophisticated cryptographic and technical security risks clearly to business leaders, product teams, engineers, compliance professionals, and regulators.
  • Proven ability to operate effectively within a matrixed security organization and collaborate with dedicated IAM, AppSec, SOC, and Infrastructure Security functions.
  • Strong understanding of security architecture, secure software development, access controls, operational security, and risk management.
  • Experience working with regulated digital-asset, fintech, financial services, or blockchain environments.
  • Hands-on experience with Kubernetes, containers, Terraform or other Infrastructure as Code technologies, API security, or Python automation is an advantage.
  • Experience with Web3 dependency and software supply-chain security is a plus.
  • Industry certifications such as CISSP, CISM, CCSP, or CCSSA are advantageous.
  • Professional fluency in spoken and written Mandarin is beneficial for regional operations and cross-functional engineering collaboration.

Benefits & conditions

  • Competitive compensation package.
  • Fully remote working opportunity.
  • International and distributed working environment.
  • Opportunity to work on security architecture for digital-asset custody, blockchain, and on-chain infrastructure.
  • Exposure to complex fintech, cryptocurrency, and regulated financial technology environments.
  • Collaboration with specialized security, engineering, compliance, risk, product, and operations teams.
  • Opportunities to influence security architecture and controls across international markets.
  • Team-building initiatives and company events.
  • Senior-level scope with significant ownership over critical security architecture and risk management.
  • Opportunity to contribute to the development of secure, scalable digital-asset infrastructure.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.de
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:12 min

Using contract managers for blockchain operations

Soumaya Erradi · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:26 min

Automating programmable logic using smart contracts and JavaScript tools

Ryan Arndt · World Congress 2023

2:31 min

Monitoring active blockchain integrations for errors and malicious behavior

Michiel Mulders Michiel Mulders · World Congress 2025

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

Videos

See all

Related articles

See all