Skip to content

Open nowPosted 63 days ago

Principal Security Engineer (Crypto / Digital Assets)

capital46 open roles

Where
Dubai
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal Security Engineer (Crypto / Digital Assets)capital · Dubai
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on capital's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.4% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.5%1 day
  2. 3.5%3 days
  3. 7.4%7 days
  4. 13.2%14 days
  5. 34.6%30 days
This job: posted 63 days ago

The posting

We are looking for a Principal Security Engineer with deep crypto domain expertise to lead security across our regulated digital-asset business. As we build out spot trading, custody, staking and on-chain services for our client base, security is the foundation the whole business stands on. This role owns it.

You will be the security owner for our crypto platform's custody and on-chain layer end to end: architecture, engineering, operations and regulatory assurance for the parts of the stack that are unique to digital assets. For platform capabilities already owned by central security teams (cloud, application security, IAM, SOC), you'll define the crypto-specific requirements and partner on delivery rather than duplicate ownership. You will work closely with risk, compliance, product and engineering, and report into the central security function.

This is a hands-on senior role for someone who understands that in digital-asset custody, a single key-management failure is a firm-ending event, and who builds controls accordingly.

Key Responsibilities:

  • Own the full custody stack: MPC key management, transaction authorisation, signing quorums, address whitelisting and withdrawal controls
  • Govern hot/cold wallet segregation, key ceremonies and delegated cold custodians
  • Secure staking architecture and on-chain deposit/withdrawal paths
  • Define crypto-specific hardening requirements for the custody and exchange stack within the existing multi-account AWS environment; partner with InfraSec on account segmentation, network and data-residency controls
  • Partner with AppSec to embed crypto-specific checks into the SDLC (SAST, DAST, SCA, CI/CD security gates) for custody and exchange services
  • Partner with IAM and IAM Tech on privileged access and secrets governance for crypto signing keys and custody credentials
  • Define custody- and blockchain-specific detection use cases and feed them into SOC's monitoring and alerting
  • Own incident response for crypto-specific scenarios (key compromise, unauthorised transaction, on-chain incident); partner with CorpSec on the group-wide IR process, forensics and breach notification
  • Contribute custody- and blockchain-specific scenarios into AppSec's pentest and red-team programme
  • Own security assessment and ongoing assurance of the crypto vendor stack: custody platforms, execution systems, blockchain analytics, Travel Rule and treasury tooling
  • Apply CorpSec's vendor onboarding and contract security process to crypto vendor engagements
  • Own control mapping against MiCA and the crypto-specific provisions of DORA and FCA rules; partner with IT Governance on ISO 27001, SOC 2, NIST CSF and GDPR mapping
  • Feed crypto services into the group's BC/DR and important-business-service mapping owned by IT Governance
  • Maintain crypto-specific security policy addenda; support regulatory and IT audits on crypto scope

Required Qualifications:

  • 6+ years in information security, including recent experience as a senior security engineer, security architect, or security lead;
  • Direct experience securing crypto, digital-asset custody, or a regulated financial platform; strong understanding of blockchain security, wallet architecture and key management;
  • Working knowledge of cloud security fundamentals (AWS preferred, Azure/GCP acceptable) in a regulated environment;
  • Practical knowledge of security in regulated finance and how controls map to licence conditions (ISO 27001, SOC 2, NIST);
  • Experience running threat modelling, risk assessments and incident response;
  • Comfortable operating in a matrixed security model - partnering with dedicated IAM, AppSec, SOC and infrastructure security teams rather than owning those functions outright.

Nice to have:

  • Hands-on Kubernetes, containers, API security and infrastructure as code;
  • Python proficiency for automation and scripting;
  • Experience running third-party / vendor security assurance;
  • Recognised certifications: CISSP, CISM, CCSP, or equivalent;
  • Hands-on experience with MPC - based custody, key ceremonies and signing-policy design;
  • Familiarity with MiCA, DORA, FCA crypto rules, or comparable digital-asset regimes;
  • Background in secure SDLC and DevSecOps (OWASP, secure-by-design);
  • Experience with smart contract security review: threat modelling, commissioning and managing external audits, and driving findings through to resolution;
  • Experience designing transaction signing and approval flows, so that what a user or operator authorises is provably what gets signed and broadcast;
  • Experience reviewing business logic in the money path - withdrawal sequencing, balance idempotency, internal ledger integrity - where the flaw sits in the logic rather than the cryptography;
  • Familiarity with supply-chain assurance for crypto-specific dependencies: wallet SDKs, chain libraries, node clients and signing tooling, including pinning, provenance and upgrade discipline;
  • Experience defining bug bounty scope for crypto assets, and triaging and calibrating severity for on-chain findings.

Soft Skills:

  • Strong analytical and problem-solving skills;
  • Able to translate technical risk into business and regulatory impact;
  • Able to explain security risks and mitigations to non-security teams and to regulators;
  • Cross-functional collaboration with risk, compliance, product and engineering teams;
  • Clear documentation and communication skills.

What You Will Get in Return:

  • Competitive Salary: We believe great work deserves great pay. Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.
  • Work-Life Harmony: Join a company that genuinely cares about you, because your life outside of work matters just as much as your time on the clock. #LI-Hybrid
  • Generous Time Off: Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.
  • Employee Referral Program: Love working here? Share the love. Bring your talented friends on board and get rewarded for growing our team.
  • Comprehensive Health & Pension Benefits: From medical insurance to pension plans, we’ve got your back. Plus location-specific benefits and perks.
  • Workation Wonderland: Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply).
  • Volunteer Days: Take two additional paid days each year to support causes you care about and give back to the community.

Be a key player at the forefront of the digital assets movement, propelling your career to new heights. Join a dynamic and rapidly expanding company that values and rewards talent, initiative and creativity. Work alongside one of the most brilliant teams in the industry.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against capital's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on capital's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    capital's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.