Blockchain

Crypto Security Engineer

6.0/10

Blockchain

Not specified
Office / on-site
mid
28 days ago
cryptosecurityweb3PythonTypeScriptKotlinKMS/HSMLeast PrivilegeApplication SecurityBlockchain On-ChainSecrets ManagementPlatform Security

AI Summary

The vacancy is well-defined in tasks and requirements but lacks salary transparency and company links.

Check Match โ€” Just drop your CV

See your fit for Crypto Security Engineer in seconds.

Description

WHAT YOU WILL DO

  • โ€ขPartner with Trading, Middle Office and Quant (Institutional FinOps) teams to map out inventory trading systems, data flows, third-party integrations and custody/settlement touchpoints.
  • โ€ขConduct deep-dive assessments mapping critical assets and workflows to identify structural vulnerabilities. You will be responsible for defining the Target State and drafting the strategic Risk Treatment Plans (RTP) required to meet institutional-grade standards (e.g., CCSS, NIST, DORA).
  • โ€ขAct as the primary security liaison for Senior Management and third-party vendors. You will translate complex technical gaps into actionable business risk summaries, drive vendor evaluations for core security infrastructure, and manage the project lifecycle for high-impact posture uplifts.
  • โ€ขImplement and maintain monitoring for FinOps-specific security signals such as abnormal order patterns, signature misuse, unusual settlements. You will integrate these signals into our SIEM/SOAR for real-time response.
  • โ€ขSupport secrets and key-management hygiene. You will ensure app/service keys are stored in KMS/Vault, scoped to least privilege and rotated automatically to prevent credential leakage.
  • โ€ขAssist product security in triage of SAST/SCA findings for FinOps-related repositories. You will help implement CI checks and remediation playbooks.
  • โ€ขParticipate in incident exercises, post-incident reviews and remediation tracking for trading incidents.
  • โ€ขDocument controls and produce concise risk summaries for FinOps leads and the Security.

NICE TO HAVE

  • โ€ขFamiliarity with trading systems or financial operations (market-making, execution, settlement) or close collaboration background with trading/quant teams.
  • โ€ขExposure to blockchain on-chain concepts (wallets, addresses, transactions) but no requirement to audit contracts.
  • โ€ขFamiliarity with SOC operations, and post-incident forensic analysis.
  • โ€ขFamiliarity with SOC2, ISO 27001, or financial audit requirements.
  • โ€ขAny relevant industry certification.

Requirements

WHAT YOU WILL NEED

  • โ€ข5+ years in security engineering, platform security, or application security experience.
  • โ€ขProven expertise in Threat Modeling. Ability to perform structured reviews (e.g., STRIDE) of complex data flows and operational processes.
  • โ€ขExperience with observability and detection tooling (SIEM, logs, metrics) and ability to write basic detection rules.
  • โ€ขPractical experience with KMS/HSM, secrets management platforms (Vault, 1Password, AWS/GCP KMS), IAM patterns and least-privilege.
  • โ€ขExceptional ability to translate "Technical Debt" into Business Risk for C-suite stakeholders (CFO, CTO, Head of Trading).
  • โ€ขAbility to raise, read and audit Pull Requests in at least one language used in our stack (TypeScript, Java/Kotlin, Python).
  • โ€ขExperience conducting technical due diligence and scoping for third-party security integrations.
Loading similar jobs...