Jobgether
Jobgether

Principal Security Architect (On-Chain & Digital Assets)

engineeringfull-timeSwitzerland
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities

    • Own end-to-end security architecture for the custody and on-chain technology stack.

    • Define security requirements and controls for HSM and MPC-based key management, transaction authorization, signing quorums, address whitelisting, and hot/cold wallet segregation.

    • Establish secure processes for key ceremonies, delegated cold custody, staking deposits and withdrawals, and other critical digital-asset operations.

    • Develop crypto-specific security standards, privileged-access controls, and secure SDLC requirements within a multi-account AWS environment.

    • Partner with centralized Infrastructure Security, Application Security, IAM, and SOC teams to implement and maintain platform security capabilities.

    • Define blockchain and custody-specific detection use cases for the SOC.

    • Lead incident response procedures for crypto-specific scenarios, including key compromise, unauthorized transactions, and significant on-chain incidents, in collaboration with Corporate Security.

    • Conduct detailed threat modeling and security reviews covering internal ledger mechanisms, balance idempotency, withdrawal sequencing, and smart contract integrations.

    • Protect the integrity of transaction and funds flows across the platform by identifying and mitigating architectural and operational risks.

    • Direct security assessments and ongoing assurance activities for external custody providers, execution systems, blockchain analytics solutions, Travel Rule tools, and treasury integrations.

    • Map security controls to relevant international regulatory frameworks, including MiCA, DORA, FCA, and MAS requirements.

    • Collaborate with market and regulatory teams to maintain appropriate security and compliance controls as the platform expands internationally.

    • Translate complex cryptographic, infrastructure, and digital-asset risks into clear business and regulatory implications for non-security stakeholders.

    • Requirements

      • 10+ years of professional experience in information security, with a proven track record as a Security Architect, Principal Security Engineer, or technical security lead.

      • Demonstrated experience securing digital-asset custody platforms, high-throughput crypto environments, or regulated financial infrastructure.

      • Deep practical knowledge of crypto custody and wallet architecture, including Multi-Party Computation (MPC), Hardware Security Modules (HSMs), key ceremonies, and signing-policy design.

      • Strong cloud security expertise, preferably within AWS environments and regulated organizations.

      • Practical experience mapping security controls to recognized frameworks and regulatory requirements, including ISO 27001, SOC 2, and NIST.

      • Strong experience conducting threat modeling, security assessments, risk analysis, and incident response.

      • Ability to communicate sophisticated cryptographic and technical security risks clearly to business leaders, product teams, engineers, compliance professionals, and regulators.

      • Proven ability to operate effectively within a matrixed security organization and collaborate with dedicated IAM, AppSec, SOC, and Infrastructure Security functions.

      • Strong understanding of security architecture, secure software development, access controls, operational security, and risk management.

      • Experience working with regulated digital-asset, fintech, financial services, or blockchain environments.

      • Hands-on experience with Kubernetes, containers, Terraform or other Infrastructure as Code technologies, API security, or Python automation is an advantage.

      • Experience with Web3 dependency and software supply-chain security is a plus.

      • Industry certifications such as CISSP, CISM, CCSP, or CCSSA are advantageous.

      • Professional fluency in spoken and written Mandarin is beneficial for regional operations and cross-functional engineering collaboration.

      • Benefits

        • Competitive compensation package.

        • Fully remote working opportunity.

        • International and distributed working environment.

        • Opportunity to work on security architecture for digital-asset custody, blockchain, and on-chain infrastructure.

        • Exposure to complex fintech, cryptocurrency, and regulated financial technology environments.

        • Collaboration with specialized security, engineering, compliance, risk, product, and operations teams.

        • Opportunities to influence security architecture and controls across international markets.

        • Team-building initiatives and company events.

        • Senior-level scope with significant ownership over critical security architecture and risk management.

        • Opportunity to contribute to the development of secure, scalable digital-asset infrastructure.

✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
Principal Security Architect (On-Chain & Digital Assets) at Jobgether — Remote