Назад
Company hidden
4 часа назад

Senior Product Security Engineer / Architect (Web3)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Switzerland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer / Architect (Web3) (digital asset infrastructure and fintech): Raising product security across digital asset products by reviewing application code, cryptographic workflows, smart contracts, HSM integrations, and cloud infrastructure with an accent on threat modeling, secure architecture, and automated security guardrails. Focus on designing cryptographic and confidential-computing controls, identifying complex attack paths, and building enforcement across CI/CD, software supply chains, Kubernetes, and deployment platforms.

Location: Lausanne, Switzerland (hybrid)

Company

hirify.global is a FINMA-regulated Swiss securities firm providing digital asset trading, financial services, and infrastructure solutions for banks, corporations, and private companies.

What you will do

  • Own product security for hirify.global-PROTECT, hirify.global-CAPITAL, hirify.global-EXPLORER, and hirify.global-NETWORK.
  • Contribute to security architecture for HSMs, confidential computing, MPC, and cryptographic systems.
  • Review application code, cryptographic workflows, smart contracts, HSM integrations, and enclave-based components.
  • Model threats, review designs before release, lead penetration tests, reproduce findings, and validate remediation.
  • Build security automation and guardrails across CI/CD pipelines, software supply chains, Kubernetes environments, and deployment platforms.
  • Support incident response, vulnerability management, audits, RFPs, regulatory discussions, and security investigations.

Requirements

  • Master’s or PhD in computer science, IT security engineering, cryptography, or equivalent practical experience.
  • 7+ years of experience in application security, product security, offensive security, or security engineering.
  • Security code review experience in at least two of Go, C/C++, TypeScript, and Python.
  • Strong foundations in applied cryptography, including PKI, TLS, X.509, AES, RSA, ECDSA, EdDSA, key management, and signing workflows.
  • Experience with HSM technologies, PKCS#11 environments, Kubernetes and container security, cloud IAM, workload identity, secrets management, and policy-as-code.
  • Fluent written and spoken English required.

Nice to have

  • Blockchain and smart contract security, MPC, threshold signatures, fuzzing, or secure software testing.
  • Experience with Thales/Luna HSM, AWS CloudHSM, Azure Managed HSM, Intel SGX, AMD SEV-SNP, AWS Nitro Enclaves, or Azure Confidential Computing.
  • Knowledge of FINMA, DORA, MiCA, ISO 27001, SOC 2, or FIPS 140-3.
  • Public security research, CVEs, bug bounty work, or open-source security contributions.
  • Experience with RFPs, security questionnaires, and customer due diligence.

Culture & Benefits

  • Work at the intersection of digital assets and finance with experienced security and technology specialists.
  • Hybrid remote work and flexible working hours.
  • Fast-paced learning environment with an entrepreneurial and team-oriented culture.
  • State-of-the-art technology and IT infrastructure.
  • Team events and growth opportunities in a developing company.

Hiring process

  • Target start date: Q1 2027; early applications are welcome.
  • Applications through agencies are not considered.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →