3 дня назад
Security Architect (Crypto Wallet)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Architect (Crypto Wallet) (Mobile Security/Cryptography): Owning security and privacy assurance for a self-custody crypto wallet across mobile devices, backend services, and third-party integrations with an accent on threat modeling, applied cryptography, and digital-asset security. Focus on reviewing the signing path, designing recovery and fraud controls, enforcing AML and sanctions gates, preparing audit-ready releases, and driving remediation of critical findings.
Location: Remote flexibility with the role based in Poland; consistent working-day overlap with US Central Time is required.
Company
is an AI and software engineering company with more than 250 employees across the US and Europe, building real-world systems for enterprise clients.
What you will do
- Own and extend the threat model for the self-custody crypto wallet across devices, backend services, and third-party integrations.
- Review and protect the mobile signing path, including secure key handling, device attestation, jailbreak and root detection, anti-tamper controls, certificate pinning, and biometric gating.
- Design recovery, fraud-prevention, AML, sanctions-screening, phishing-detection, and drainer-risk controls for wallet transactions.
- Define audit records, privacy boundaries, encryption, data retention, deletion policies, and US-only data residency for sensitive information.
- Own security controls in the build pipeline, including SAST, secret scanning, SCA, licence scanning, SBOM generation, and dependency policies.
- Prepare audit-ready builds, manage the remediation register, co-sign milestone exit checklists, support the independent auditor, and participate in Severity 1 incident response and bug-bounty triage.
Requirements
- Strong experience with mobile and application security across iOS and Android, including Secure Enclave, Keystore or StrongBox, biometric APIs, attestation, RASP, and reverse-engineering tools.
- Review-level applied cryptography knowledge covering BIP-32, BIP-39, BIP-44, ECDSA over secp256k1, AES-GCM, KDFs, envelope encryption, KMS, HSMs, and key rotation.
- Experience with AWS security services, OAuth 2.0, OIDC, JWT, JWKS, WebAuthn, session and device binding, API authorization, and secure service-to-service design.
- Knowledge of digital-asset security, including EVM and Bitcoin transactions, ERC-20 approvals, ERC-4337, smart-account wallets, address poisoning, drainer patterns, RPC providers, and indexers.
- Experience with secure SDLC, supply-chain security, compliance-related engineering, incident response, threat modeling, and security reviews.
- English at C1 level and consistent overlap with US Central Time are required.
Nice to have
- Experience with a non-custodial wallet SDK or comparable open-source wallet kit.
- Smart-contract audit experience or penetration-testing certification.
- Experience with financial-application app-store reviews or bug-bounty triage.
Culture & Benefits
- Remote flexibility with autonomy over where and how work is performed.
- Competitive compensation with medical, wellness, and learning benefits.
- English classes, professional development, and well-being support.
- Ownership opportunities and clear career progression.
- Supportive collaboration, responsive teammates, regular meetups, and technical talks.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
zerohash
9 дней назад
Security Architect (Blockchain)
5 дней назад
Security Architect (Cybersecurity)
80 000GBP
Bleap
23 часа назад
Security Engineer (Web3)
10 дней назад
Security Architecture Consultant (Cryptography & Quantum Security)
5 дней назад
Senior Product Security Engineer / Architect (Web3)
6 дней назад