
Principal Security Architect – On-Chain, Digital Assets
Posted Sep 17

Posted Sep 17
This is a fully remote position, open to applicants in Hong Kong.
• Oversee comprehensive security architecture for the entire custody stack, encompassing HSM/MPC key management, transaction authorization, signing quorums, address whitelisting, hot/cold wallet segregation, key ceremonies, delegated cold custodians, and secure staking deposit/withdrawal pathways.
• Set crypto-specific baseline standards, privileged-access controls, and secure SDLC requirements within a multi-account AWS environment, collaborating with central InfraSec, AppSec, and IAM teams.
• Identify custody and blockchain detection use cases for the SOC and manage incident response protocols for crypto-specific scenarios, such as key compromise, unauthorized transactions, and on-chain incidents.
• Perform threat modeling and security evaluations across internal ledger mechanics, balance idempotency, withdrawal sequencing, and smart contract integrations to ensure the integrity of transaction money paths.
• Lead security assessments and continuous assurance for external custody providers, execution systems, blockchain analytics, Travel Rule tools, and treasury integrations.
• Manage control mapping to align with international regulatory standards, including MiCA, DORA, FCA, and MAS, while collaborating with Global Market Teams during international expansion.
• Report to the central security function and collaborate closely with risk, compliance, product, and engineering teams concerning spot trading, custody, staking, and on-chain services.
• 10+ years of experience in information security, with a demonstrated history as a security architect or technical lead focused on securing digital-asset custody, high-throughput crypto platforms, or regulated financial infrastructure.
• Direct operational experience in securing crypto custody, with extensive domain knowledge in wallet architecture, Multi-Party Computation (MPC), Hardware Security Modules (HSMs), key ceremonies, and signing-policy design.
• Strong foundational knowledge in cloud security (AWS preferred) within a regulated environment, with hands-on experience aligning security controls with licensing requirements (ISO 27001, SOC 2, NIST).
• Proven experience in conducting threat modeling, risk assessments, and incident response, with the capability to convey technical cryptographic risks in terms understandable to business and regulatory stakeholders.
• Established comfort operating within a matrixed security model, working alongside dedicated IAM, AppSec, SOC, and infrastructure security teams instead of managing those central functions directly.
• Nice-to-have: Practical experience with Kubernetes, containers, Infrastructure as Code (Terraform), API security, Python for automation, Web3 dependency supply-chain assurance, or relevant industry certifications (CISSP, CISM, CCSP, CCSSA).
• Nice-to-have: Professional proficiency in spoken and written Mandarin.
• Competitive compensation package.
• Various team-building programs and company events.
Cloudiax
Cisco
Cisco
Skylight
Get handpicked remote jobs straight to your inbox weekly.