Назад
Company hidden
3 дня назад

Security Architect (Crypto Wallet)

Формат работы
remote (только Serbia)
Тип работы
fulltime
Английский
c1
Страна
Serbia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Architect (Crypto Wallet) (Mobile Security/Cryptography): Owning security and privacy assurance for a self-custody crypto wallet across mobile devices, backend services, and third-party integrations with an accent on applied cryptography, digital-asset security, and secure SDLC controls. Focus on defending the self-custody boundary, designing recovery and fraud controls, hardening the signing path, and driving audit remediation for a production wallet.

Location: Remote from Serbia; consistent working-day overlap with US Central Time required.

Company

hirify.global is an AI-focused technology company with more than 250 people across the US and Europe, delivering software solutions for enterprise clients.

What you will do

  • Own the security and privacy assurance of a self-custody crypto wallet across mobile, backend, cloud, and third-party integrations.
  • Extend threat models and review the signing path, recovery flows, device integrity controls, biometric gating, anti-tamper protections, and certificate pinning.
  • Design recovery-guard, fraud-prevention, AML and sanctions-screening controls for wallet transactions.
  • Define audit records, privacy boundaries, field-level encryption, data retention, and deletion policies, including US-only data residency.
  • Own SAST, secret scanning, SCA, license scanning, SBOM generation, and dependency policies in the build pipeline.
  • Prepare audit-ready releases, manage remediation of security findings, define rollout guardrails, and coordinate incident response and bug-bounty triage.

Requirements

  • Strong experience with iOS and Android security, Secure Enclave, Android Keystore/StrongBox, attestation, biometrics, RASP, reverse engineering, Frida, objection, and MobSF.
  • Review-level knowledge of BIP-32, BIP-39, BIP-44, ECDSA/secp256k1, AES-GCM, KDFs, envelope encryption, KMS, HSMs, and key rotation.
  • Experience with AWS security services, OAuth 2.0, OIDC, JWT/JWKS, WebAuthn, API authorization, session binding, and secure service-to-service design.
  • Knowledge of EVM and Bitcoin transactions, ERC-20, ERC-4337, smart-account wallets, phishing and drainer patterns, and RPC/indexer trust assumptions.
  • Experience with secure SDLC, threat modeling, security reviews, compliance-related engineering, incident response, and audit collaboration.
  • English at C1 level and consistent overlap with US Central Time required.

Nice to have

  • Experience with a non-custodial wallet SDK or comparable open-source kit.
  • Smart-contract auditing, penetration-testing certification, financial app-store review, or bug-bounty triage experience.

Culture & Benefits

  • Remote flexibility with autonomy over where and how work is performed.
  • Competitive compensation with medical, wellness, and learning benefits.
  • English classes, professional development, well-being support, and career progression opportunities.
  • Supportive collaboration, responsive teammates, regular meetups, and technical talks.
  • AI tools are used to complement and enhance engineering work.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →