Remote job
Verified remotePrincipal Security Engineer
Mlabs
via Arbeitnow
Similar jobs by email. Free, unsubscribe anytime.
Free, unsubscribe anytime. Double opt-in.
At a glance
- Tech stack
- Multi-Party Computationthreshold signaturesHSMRustTypeScriptAWSInfrastructure as CodeCI pipelines
- Seniority:
- Lead
- Benefits
- Competitive executive-level compensation package
- Flexible, remote-first work environment
- Comprehensive health, wellness, and benefits coverage
- Generous paid time off (PTO) and personal Leave policy
- Professional development budget
Seeking a Principal Security Engineer to lead product security for a core banking platform for digital assets. This role is for senior security engineers with deep experience in key management, applied cryptography, threat modeling, supply-chain security and compliance for financial systems.
- Lead product security architecture
- Harden key management, signing workflows and auth
- Support SOC 2, ISO 27001 and ISO 22301 compliance
- Remote-first role with executive-level compensation
Automatically generated
Job description
Location: Remote - US or EU
Remote | Full-time
Compensation: $160K - $240K
Our client operates a core banking platform designed specifically for digital assets, enabling fintechs and systemically important financial institutions to build, operate, and scale onchain infrastructure. The platform secures over €100B in assets and powers critical operations—including key management, transaction processing, treasury, and compliance—for over 400 global institutions.
Our client is seeking a Principal Security Engineer to lead product security across the entire ecosystem. In this role, security is built directly into the system's architecture rather than applied as a secondary control. The ideal candidate will take ownership of hardening key management, signing workflows, authentication systems, policy enforcement, and multi-chain integrations.
Beyond core product security and vulnerability management, this position plays a pivotal role in shaping the long-term architectural vision of a platform trusted by tier-one financial institutions. As an organization committed to technical excellence, our client also encourages contribution to the broader security community through research, publications, and industry events.
Key Responsibilities
- Architectural Leadership: Lead product security architecture, ensuring security principles are embedded into core platform design and development cycles.
- Core Infrastructure Security: Analyze and secure key management systems, transaction pipelines, and signing workflows across modern distributed networks.
- Threat Modeling & Review: Perform system-level threat modeling for new product features, protocols, and multi-chain integrations.
- Cryptographic & Auth Security: Design and evaluate security-sensitive components, including authentication protocols, authorization frameworks, and applied cryptographic workflows.
- Defense-in-Depth: Define, implement, and maintain multi-layered security controls across the application, infrastructure, and protocol layers.
- Supply Chain & Environment Security: Own and expand end-to-end software supply-chain security, spanning dependency scanning in CI pipelines to local developer environments.
- Infrastructure as Code (IaC): Enforce security configurations into version-controlled repositories to prevent configuration drift and enhance auditability.
- Risk Research & Mitigation: Investigate emerging security risks related to blockchain protocols, institutional custody models, and novel cryptographic techniques.
- Compliance & Audits: Support ongoing SOC 2, ISO 27001, and ISO 22301 compliance frameworks alongside expanding control surfaces.
- Technical Enablement & Incident Response: Provide day-to-day guidance to engineering teams to make secure patterns accessible, while supporting incident response and root-cause analysis when necessary.
- External Representation: Participate in security architecture reviews with tier-one banking partners, external auditors, and enterprise clients.
- Industry Thought Leadership: Contribute to technical research, whitepapers, and conference presentations to advance the digital asset security field.
Requirements
- Experience: 10+ years in security engineering, product security, or security architecture roles.
- Domain Expertise: Demonstrated track record of securing financial infrastructure, institutional blockchain platforms, or both.
- Cryptographic Systems: Deep understanding of cryptographic protocols, wallet architectures, and key management frameworks. Direct experience with Multi-Party Computation (MPC), threshold signatures, or HSM-backed solutions is strongly preferred.
- Threat Modeling: Extensive experience performing comprehensive system-level threat models and architecture reviews.
- Infrastructure & Networks: Solid foundational knowledge of distributed systems, networking protocols, and cloud computing platforms (primarily AWS).
- Supply Chain & IaC: Hands-on experience implementing software supply-chain defenses and managing security configurations via code to prevent drift.
- Compliance & Frameworks: Familiarity with maintaining live audit cycles for frameworks such as SOC 2, ISO 27001, ISO 22301, and the NIST Cybersecurity Framework.
- Development Skills: Professional familiarity with modern backend languages such as Rust or TypeScript.
- Communication: Exceptional ability to communicate complex security concepts effectively to both internal engineering teams and external enterprise stakeholders.
Benefits
- Competitive executive-level compensation package.
- Flexible, remote-first work environment.
- Comprehensive health, wellness, and benefits coverage tailored to regional standards.
- Generous paid time off (PTO) and personal Leave policy.
- Professional development budget for security research, certifications, and industry conferences.
- Exposure to cutting-edge cryptographic engineering alongside leading global financial institutions.
Interview Process …
This role is provided by an external source. Applications are handled on the source website.
