Back

Principal Security Engineer (Crypto / Digital Assets)

TechnologySecurity - CorpSec

About the role

We are looking for a Principal Security Engineer with deep crypto domain expertise to lead security across our regulated digital-asset business. As we build out spot trading, custody, staking and on-chain services for our client base, security is the foundation the whole business stands on. This role owns it.

You will be the security owner for our crypto platform's custody and on-chain layer end to end: architecture, engineering, operations and regulatory assurance for the parts of the stack that are unique to digital assets. For platform capabilities already owned by central security teams (cloud, application security, IAM, SOC), you'll define the crypto-specific

requirements

and partner on delivery rather than duplicate ownership. You will work closely with risk, compliance, product and engineering, and report into the central security function.

This is a hands-on senior role for someone who understands that in digital-asset custody, a single key-management failure is a firm-ending event, and who builds controls accordingly.

Responsibilities

Key

Responsibilities

Digital asset and custody security (owned by this role)

  • Own the full custody stack: MPC key management, transaction authorisation, signing quorums, address whitelisting and withdrawal controls
  • Govern hot/cold wallet segregation, key ceremonies and delegated cold custodians
  • Secure staking architecture and on-chain deposit/withdrawal paths

Platform, cloud and application security (partner with InfraSec, AppSec and IAM):

  • Define crypto-specific hardening

requirements

for the custody and exchange stack within the existing multi-account AWS environment; partner with InfraSec on account segmentation, network and data-residency controls

  • Partner with AppSec to embed crypto-specific checks into the SDLC (SAST, DAST, SCA, CI/CD security gates) for custody and exchange services
  • Partner with IAM and IAM Tech on privileged access and secrets governance for crypto signing keys and custody credentials

Threat detection, response and testing (partner with SOC, CorpSec and AppSec):

  • Define custody- and blockchain-specific detection use cases and feed them into SOC's monitoring and alerting
  • Own incident response for crypto-specific scenarios (key compromise, unauthorised transaction, on-chain incident); partner with CorpSec on the group-wide IR process, forensics and breach notification
  • Contribute custody- and blockchain-specific scenarios into AppSec's pentest and red-team programme

Third-party and vendor security (own crypto vendor risk, partner with CorpSec on process):

  • Own security assessment and ongoing assurance of the crypto vendor stack: custody platforms, execution systems, blockchain analytics, Travel Rule and treasury tooling
  • Apply CorpSec's vendor onboarding and contract security process to crypto vendor engagements

Regulatory, resilience and governance (own crypto-specific mapping, partner with IT Governance):

  • Own control mapping against MiCA and the crypto-specific provisions of DORA and FCA rules; partner with IT Governance on ISO 27001, SOC 2, NIST CSF and GDPR mapping
  • F…

Requirements

Required

Qualifications

  • 6+ years in information security, including recent experience as a senior security engineer, security architect, or security lead;
  • Direct experience securing crypto, digital-asset custody, or a regulated financial platform; strong understanding of blockchain security, wallet architecture and key management;
  • Working knowledge of cloud security fundamentals (AWS preferred, Azure/GCP acceptable) in a regulated environment;
  • Practical knowledge of security in regulated finance and how controls map to licence conditions (ISO 27001, SOC 2, NIST);
  • Experience running threat modelling, risk assessments and incident response;
  • Comfortable operating in a matrixed security model - partnering with dedicated IAM, AppSec, SOC and infrastructure security teams rather than owning those functions outright.

Soft Skills

  • Strong analytical and problem-solving skills;
  • Able to translate technical risk into business and regulatory impact;
  • Able to explain security risks and mitigations to non-security teams and to regulators;
  • Cross-functional collaboration with risk, compliance, product and engineering teams;
  • Clear documentation and communication skills.

Benefits & compensation

Be a key player at the forefront of the digital assets movement, propelling your career to new heights. Join a dynamic and rapidly expanding company that values and rewards talent, initiative and creativity. Work alongside one of the most brilliant teams in the industry.

View all