Principal Security Engineer (Crypto / Digital Assets)
Core
Lead end-to-end security for a regulated digital-asset business, owning the custody stack, on-chain services, and regulatory assurance for spot trading and staking.
Role type
Principal Security Engineer (Crypto / Digital Assets)
Builds
MPC key management, transaction authorisation, signing quorums, address whitelisting, withdrawal controls, staking architecture, and on-chain deposit/withdrawal paths.
Domain
Digital assets / Crypto / Regulated finance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
MPC key management, transaction authorisation, signing quorums, address whitelisting, withdrawal controls, hot/cold wallet segregation, key ceremonies, delegated cold custodians, staking architecture, on-chain deposit/withdrawal paths, crypto-specific hardening, SDLC security integration, privileged access governance, secrets governance, threat modelling, risk assessments, incident response, vendor security assessment, regulatory control mapping (MiCA, DORA, FCA), ISO 27001, SOC 2, NIST CSF, GDPR, blockchain security, wallet architecture, cloud security (AWS/Azure/GCP), regulated finance controls
Preferred skills
Kubernetes, containers, API security, infrastructure as code, Python, third-party vendor security assurance, CISSP/CISM/CCSP, smart contract security review, transaction signing flows, business logic security, supply-chain assurance for crypto dependencies, bug bounty scope definition
Technologies
AWS, Azure, GCP, Kubernetes, Python, SAST, DAST, SCA, CI/CD, ISO 27001, SOC 2, NIST CSF, GDPR, MiCA, DORA, FCA
Responsibilities
Own the full custody stack including MPC key management and withdrawal controls; govern hot/cold wallet segregation and key ceremonies; secure staking architecture and on-chain paths; define crypto-specific hardening requirements for AWS environments; embed crypto-specific checks into the SDLC; define custody-specific detection use cases for SOC; own incident response for crypto-specific scenarios; own security assessment of crypto vendor stack; own control mapping against MiCA, DORA, and FCA rules; feed crypto services into group BC/DR mapping; maintain crypto-specific security policy addenda.
Seniority
Principal, hands-on IC with strategic ownership