Назад
Company hidden
3 дня назад

Security Architect (Crypto Wallet)

Формат работы
remote (только Armenia)
Тип работы
fulltime
Английский
c1
Страна
Armenia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Architect (Crypto Wallet): Owning security and privacy assurance for a self-custody crypto wallet with an accent on mobile security, applied cryptography, cloud security, and digital-asset protection. Focus on defending the self-custody boundary, securing the signing and recovery paths, implementing AML and phishing controls, and driving audit remediation across the delivery lifecycle.

Location: Armenia; remote flexibility with consistent overlap with US Central Time.

Company

hirify.global is an AI-focused software engineering company building real-world systems for enterprise clients, with more than 250 employees across the US and Europe.

What you will do

  • Own and extend the threat model for a self-custody crypto wallet across mobile devices, backend services, and third-party integrations.
  • Protect the self-custody boundary by ensuring private keys, plaintext seed phrases, and user funds remain inaccessible from the server side.
  • Design recovery, verification, authentication, cooling-off, rate-limiting, alerting, and fraud-logging controls.
  • Review and harden the mobile signing path with device attestation, jailbreak and root detection, anti-tamper controls, certificate pinning, and biometric gating.
  • Implement AML and sanctions screening, phishing and drainer risk checks, audit logging, privacy boundaries, and data retention controls.
  • Own security automation, audit readiness, remediation tracking, release guardrails, incident response, and bug-bounty triage.

Requirements

  • Strong experience with iOS and Android security, Secure Enclave, Android Keystore or StrongBox, biometric APIs, attestation, RASP, anti-tamper controls, and mobile reverse engineering.
  • Review-level applied cryptography knowledge, including BIP-32, BIP-39, BIP-44, ECDSA over secp256k1, AES-GCM, KDFs, envelope encryption, KMS, HSMs, and key rotation.
  • Experience with AWS security services, OAuth 2.0, OIDC, JWT, JWKS, WebAuthn, API authorization, rate limiting, and secure service-to-service design.
  • Knowledge of secure SDLC, threat modeling, secure code review, SAST, DAST, SCA, SBOMs, secret scanning, CI/CD hardening, and dependency policies.
  • Understanding of digital-asset security, EVM and Bitcoin transactions, ERC-20 approvals, ERC-4337, smart-account wallets, drainer patterns, and RPC or indexer trust assumptions.
  • English at C1 level and consistent working-day overlap with US Central Time are required.

Nice to have

  • Experience with a non-custodial wallet SDK or comparable open-source kit.
  • Smart-contract auditing, penetration-testing certification, or financial app-store review experience.
  • Bug-bounty triage experience.

Culture & Benefits

  • Remote flexibility and autonomy in how work is organized.
  • Competitive compensation with medical, wellness, and learning benefits.
  • English classes, professional development, and well-being support.
  • Ownership opportunities and defined career progression.
  • Supportive collaboration, technical talks, meetups, and responsive teammates.

Hiring process

  • Work with the Project Manager or Delivery Lead and collaborate daily with SDK, backend, mobile, DevOps, and QA engineers.
  • Act as the technical counterpart to the client's independent auditor and co-sign milestone exit checklists.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →