4 дня назад
Principal Security Architect (On-Chain & Digital Assets)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Security Architect (On-Chain & Digital Assets) (Crypto Custody/Blockchain): Owning end-to-end security architecture for regulated digital-asset custody and on-chain services with an accent on MPC/HSM key management, transaction authorization, wallet segregation, and regulatory controls. Focus on threat modeling money-path integrity, managing crypto-specific incident response, assessing custody and blockchain vendors, and mapping controls to MiCA, DORA, FCA, and MAS requirements.
Location: Hong Kong / APAC; Workplace: Remote
Company
Group provides exchange, payments, custody, wallet, blockchain integration, trading, and white-label infrastructure solutions for corporate clients worldwide.
What you will do
- Lead end-to-end security architecture for the custody stack, including HSM/MPC key management, signing quorums, transaction authorization, wallet segregation, key ceremonies, and staking flows.
- Define crypto-specific security baselines, privileged-access controls, and secure SDLC requirements across a multi-account AWS environment.
- Develop custody and blockchain detection use cases and manage incident response for key compromise, unauthorized transactions, and on-chain incidents.
- Conduct threat modeling and security reviews for internal ledgers, balance idempotency, withdrawal sequencing, and smart contract integrations.
- Assess external custody providers, execution systems, blockchain analytics, Travel Rule tools, and treasury integrations.
- Map security controls to MiCA, DORA, FCA, MAS, ISO 27001, SOC 2, and NIST requirements during international expansion.
Requirements
- 10+ years of information security experience as a security architect or technical lead in digital-asset custody, high-throughput crypto platforms, or regulated financial infrastructure.
- Direct experience securing crypto custody, including wallet architecture, MPC, HSMs, key ceremonies, and signing-policy design.
- Strong cloud security fundamentals, preferably AWS, in regulated environments.
- Experience with threat modeling, risk assessments, and incident response, including communication of cryptographic risk to business teams and regulators.
- Ability to collaborate with dedicated IAM, AppSec, SOC, and infrastructure security teams in a matrixed security model.
Nice to have
- Kubernetes, containers, Terraform, API security, Python automation, or Web3 dependency supply-chain assurance experience.
- Industry certifications such as CISSP, CISM, CCSP, or CCSSA.
- Professional fluency in spoken and written Mandarin.
Culture & Benefits
- Remote workplace arrangement.
- Competitive compensation package.
- Team-building programs and company events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →