3 дня назад
Security Architect (Crypto Wallet)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Architect (Crypto Wallet): Owning security and privacy assurance for a self-custody crypto wallet across mobile devices, backend services, and third-party integrations with an accent on threat modeling, applied cryptography, and digital-asset security. Focus on protecting the signing path, designing recovery and fraud controls, enforcing AML and sanctions screening, and driving audit remediation for a release that cannot be fixed server-side after distribution.
Location: Cyprus; remote flexibility with consistent overlap with US Central Time.
Company
is an AI-focused technology company of more than 250 people across the US and Europe, building real-world systems for enterprise clients.
What you will do
- Own the threat model and security and privacy assurance for a self-custody crypto wallet across mobile, backend, devices, and third-party integrations.
- Review and protect the signing path, including key handling, device integrity, jailbreak or root detection, anti-tamper controls, certificate pinning, and biometric gating.
- Design split-recovery backup and recovery-guard controls, including new-device verification, secondary authentication, cooling-off delays, rate limiting, alerts, and fraud logging.
- Implement AML and sanctions screening, phishing and drainer risk scanning, append-only audit records, privacy boundaries, and retention controls.
- Own SAST, secret scanning, SCA, license scanning, SBOM production, dependency policy, and release guardrails.
- Coordinate independent audit activities, remediation of Severity 1 and Severity 2 findings, incident response, postmortems, and bug-bounty triage.
Requirements
- Experience with iOS and Android security, Secure Enclave, Android Keystore or StrongBox, biometric APIs, platform attestation, RASP, anti-tamper, certificate pinning, and mobile reverse engineering using tools such as Frida, objection, or MobSF.
- Review-level knowledge of applied cryptography, including BIP-32, BIP-39, BIP-44, ECDSA over secp256k1, AES-GCM, KDFs, envelope encryption, KMS, HSMs, and key rotation.
- Experience with AWS security services, OAuth 2.0, OIDC, JWT, JWKS, WebAuthn, session and device binding, API authorization, rate limiting, and secure service-to-service design.
- Knowledge of secure SDLC, threat modeling, secure code review, SAST, DAST, SCA, SBOM formats, secret scanning, and CI/CD hardening.
- Understanding of EVM and Bitcoin transactions, ERC-20 approvals, ERC-4337, smart-account wallets, address poisoning, drainer patterns, RPC providers, and indexers.
- English at C1 level and consistent overlap with US Central Time required.
Nice to have
- Experience with a non-custodial wallet SDK or comparable open-source kit.
- Smart-contract audit experience.
- Penetration-testing certification.
- Experience with app-store review for financial applications.
- Bug-bounty triage experience.
Culture & Benefits
- Remote flexibility and trust-based work arrangements.
- Competitive compensation with medical, wellness, and learning benefits.
- English classes, professional development, and well-being support.
- Ownership opportunities and career progression.
- AI tools to support day-to-day work.
- Responsive collaboration, regular meetups, and technical talks.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Bleap
23 часа назад
Security Engineer (Web3)
zerohash
9 дней назад
Security Architect (Blockchain)
10 дней назад
Security Architecture Consultant (Cryptography & Quantum Security)
9 дней назад
Head of Information Security (AI)
6 дней назад
Head of Security (Fintech)
5 дней назад
Security Architect (Cybersecurity)
80 000GBP