Key Responsibilities:
Digital asset and custody security (owned by this role):
- Own the full custody stack: MPC key management, transaction authorisation, signing quorums, address whitelisting and withdrawal controls
- Govern hot/cold wallet segregation, key ceremonies and delegated cold custodians
- Secure staking architecture and on-chain deposit/withdrawal paths
Platform, cloud and application security (partner with InfraSec, AppSec and IAM):
- Define crypto-specific hardening requirements for the custody and exchange stack within the existing multi-account AWS environment; partner with InfraSec on account segmentation, network and data-residency controls
- Partner with AppSec to embed crypto-specific checks into the SDLC (SAST, DAST, SCA, CI/CD security gates) for custody and exchange services
- Partner with IAM and IAM Tech on privileged access and secrets governance for crypto signing keys and custody credentials
Threat detection, response and testing (partner with SOC, CorpSec and AppSec):
- Define custody- and blockchain-specific detection use cases and feed them into SOC's monitoring and alerting
- Own incident response for crypto-specific scenarios (key compromise, unauthorised transaction, on-chain incident); partner with CorpSec on the group-wide IR process, forensics and breach notification
- Contribute custody- and blockchain-specific scenarios into AppSec's pentest and red-team programme
Third-party and vendor security (own crypto vendor risk, partner with CorpSec on process):
- Own security assessment and ongoing assurance of the crypto vendor stack: custody platforms, execution systems, blockchain analytics, Travel Rule and treasury tooling
- Apply CorpSec's vendor onboarding and contract security process to crypto vendor engagements
Regulatory, resilience and governance (own crypto-specific mapping, partner with IT Governance):
- Own control mapping against MiCA and the crypto-specific provisions of DORA and FCA rules; partner with IT Governance on ISO 27001, SOC 2, NIST CSF and GDPR mapping
- Feed crypto services into the group's BC/DR and important-business-service mapping owned by IT Governance
- Maintain crypto-specific security policy addenda; support regulatory and IT audits on crypto scope
Required Qualifications:
- 6+ years in information security, including recent experience as a senior security engineer, security architect, or security lead;
- Direct experience securing crypto, digital-asset custody, or a regulated financial platform; strong understanding of blockchain security, wallet architecture and key management;
- Working knowledge of cloud security fundamentals (AWS preferred, Azure/GCP acceptable) in a regulated environment;
- Practical knowledge of security in regulated finance and how controls map to licence conditions (ISO 27001, SOC 2, NIST);
- Experience running threat modelling, risk assessments and incident response;
- Comfortable operating in a matrixed security model - partnering with dedicated IAM, AppSec, SOC and infrastructure security teams rather than owning those functions outright
Nice to have:
- Hands-on Kubernetes, containers, API security and infrastructure as code;
- Python proficiency for automation and scripting;
- Experience running third-party / vendor security assurance;
- Recognised certifications: CISSP, CISM, CCSP, or equivalent;
- Hands-on experience with MPC - based custody, key ceremonies and signing-policy design;
- Familiarity with MiCA, DORA, FCA crypto rules, or comparable digital-asset regimes;
- Background in secure SDLC and DevSecOps (OWASP, secure-by-design);
- Experience with smart contract security review: threat modelling, commissioning and managing external audits, and driving findings through to resolution;
- Experience designing transaction signing and approval flows, so that what a user or operator authorises is provably what gets signed and broadcast;
- Experience reviewing business logic in the money path - withdrawal sequencing, balance idempotency, internal ledger integrity - where the flaw sits in the logic rather than the cryptography;
- Familiarity with supply-chain assurance for crypto-specific dependencies: wallet SDKs, chain libraries, node clients and signing tooling, including pinning, provenance and upgrade discipline;
- Experience defining bug bounty scope for crypto assets, and triaging and calibrating severity for on-chain findings