Principal Security Engineer (Crypto / Digital Assets)
Summary
Leads end-to-end security for a regulated crypto exchange and custody platform, including key management, cloud security, threat detection, and regulatory compliance.
We are looking for a Principal Security Engineer with deep crypto domain expertise to lead security across our regulated digital-asset business. As we build out spot trading, custody, staking and on-chain services for our client base, security is the foundation the whole business stands on. This role owns it.
You will be the security owner for our crypto platform's custody and on-chain layer end to end: architecture, engineering, operations and regulatory assurance for the parts of the stack that are unique to digital assets. For platform capabilities already owned by central security teams (cloud, application security, IAM, SOC), you'll define the crypto-specific requirements and partner on delivery rather than duplicate ownership. You will work closely with risk, compliance, product and engineering, and report into the central security function.
This is a hands-on senior role for someone who understands that in digital-asset custody, a single key-management failure is a firm-ending event, and who builds controls accordingly.
Key Responsibilities:
Required Qualifications:
- 6+ years in information security, including recent experience as a senior security engineer, security architect, or security lead;
- Direct experience securing crypto, digital-asset custody, or a regulated financial platform; strong understanding of blockchain security, wallet architecture and key management;
- Working knowledge of cloud security fundamentals (AWS preferred, Azure/GCP acceptable) in a regulated environment;
- Practical knowledge of security in regulated finance and how controls map to licence conditions (ISO 27001, SOC 2, NIST);
- Experience running threat modelling, risk assessments and incident response;
- Comfortable operating in a matrixed security model - partnering with dedicated IAM, AppSec, SOC and infrastructure security teams rather than owning those functions outright.
Nice to have:
- Hands-on Kubernetes, containers, API security and infrastructure as code;
- Python proficiency for automation and scripting;
- Experience running third-party / vendor security assurance;
- Recognised certifications: CISSP, CISM, CCSP, or equivalent;
- Hands-on experience with MPC - based custody, key ceremonies and signing-policy design;
- Familiarity with MiCA, DORA, FCA crypto rules, or comparable digital-asset regimes;
- Background in secure SDLC and DevSecOps (OWASP, secure-by-design);
- Experience with smart contract security review: threat modelling, commissioning and managing external audits, and driving findings through to resolution;
- Experience designing transaction signing and approval flows, so that what a user or operator authorises is provably what gets signed and broadcast;
- Experience reviewing business logic in the money path - withdrawal sequencing, balance idempotency, internal ledger integrity - where the flaw sits in the logic rather than the cryptography;
- Familiarity with supply-chain assurance for crypto-specific dependencies: wallet SDKs, chain libraries, node clients and signing tooling, including pinning, provenance and upgrade discipline;
- Experience defining bug bounty scope for crypto assets, and triaging and calibrating severity for on-chain findings.
Soft Skills:
- Strong analytical and problem-solving skills;
- Able to translate technical risk into business and regulatory impact;
- Able to explain security risks and mitigations to non-security teams and to regulators;
- Cross-functional collaboration with risk, compliance, product and engineering teams;
- Clear documentation and communication skills.
What You Will Get in Return:
- Competitive Salary: We believe great work deserves great pay. Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.
- Work-Life Harmony: Join a company that genuinely cares about you, because your life outside of work matters just as much as your time on the clock. #LI-Hybrid
- Generous Time Off: Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.
- Employee Referral Program: Love working here? Share the love. Bring your talented friends on board and get rewarded for growing our team.
- Comprehensive Health & Pension Benefits: From medical insurance to pension plans, we’ve got your back. Plus location-specific benefits and perks.
- Workation Wonderland: Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply).
- Volunteer Days: Take two additional paid days each year to support causes you care about and give back to the community.
