Назад
Company hidden
3 дня назад

Security Architect (Crypto Wallet)

Формат работы
remote (только Georgia)
Тип работы
fulltime
Английский
c1
Страна
Georgia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Architect (Crypto Wallet): Owning security and privacy assurance for a self-custody crypto wallet across mobile devices, backend services, and third-party integrations with an accent on applied cryptography, mobile hardening, digital-asset security, and compliance controls. Focus on protecting the signing path, designing recovery and fraud controls, enforcing fail-closed screening, preparing audit-ready releases, and driving remediation of critical findings.

Location: Remote, Georgia; consistent overlap with US Central Time required

Company

hirify.global is an AI-focused technology company with more than 250 people across the US and Europe, building real-world software solutions for enterprise clients.

What you will do

  • Own the security and privacy assurance program for a self-custody crypto wallet across mobile devices, backend services, and third-party integrations.
  • Maintain the threat model and defend the self-custody boundary by ensuring private keys, plaintext seed phrases, and user funds remain inaccessible from the server side.
  • Design recovery, verification, authentication, cooling-off, rate-limiting, alerting, and fraud-logging controls.
  • Review the signing path and implement mobile security controls including attestation, jailbreak/root detection, anti-tamper protections, certificate pinning, and biometric gating.
  • Implement AML and sanctions screening, phishing and drainer risk checks, audit records, privacy boundaries, retention controls, and US-only data residency.
  • Own security tooling and release assurance, including SAST, secret scanning, SCA, licence scanning, SBOM generation, audit remediation, incident response, and bug-bounty triage.

Requirements

  • Experience with iOS and Android security, Secure Enclave, Android Keystore/StrongBox, biometric APIs, platform attestation, RASP, anti-tamper controls, certificate pinning, and mobile reverse engineering using Frida, objection, or MobSF.
  • Review-level knowledge of BIP-32, BIP-39, BIP-44, ECDSA over secp256k1, AES-GCM, KDFs, envelope encryption, KMS, HSMs, and key rotation.
  • Experience with AWS security services, OAuth 2.0, OIDC, JWT, JWKS, WebAuthn, API authorization, rate limiting, and secure service-to-service design.
  • Knowledge of secure SDLC, threat modeling, secure code review, SAST/DAST/SCA, SBOMs, secret scanning, CI/CD hardening, and digital-asset security.
  • Familiarity with compliance engineering, sanctions and address screening, KYC/CDD data, the Travel Rule, audit logging, US privacy requirements, ISO/IEC 27001, SOC 2, and NIST CSF.
  • English at C1 level and availability for consistent overlap with US Central Time; strong written communication with auditors, counsel, and non-technical stakeholders.

Nice to have

  • Experience with a non-custodial wallet SDK or comparable open-source kit.
  • Smart-contract auditing, penetration-testing certification, financial app-store review, or bug-bounty triage experience.

Culture & Benefits

  • Remote flexibility with autonomy over where and how work is performed.
  • Competitive compensation with medical, wellness, and learning benefits.
  • English classes, professional development, well-being support, and career progression opportunities.
  • Collaborative culture with responsive teammates, regular meetups, and technical talks.
  • AI tools are used to enhance productivity and complement professional expertise.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →