
Security Architect
Posted Sep 16

Posted Sep 16
This is a fully remote position, open to applicants in Poland, +4 more countries.
• Take ownership of and enhance the threat model across devices, backend systems, and all third-party integrations prior to the audit-ready build.
• Safeguard the self-custody boundary by ensuring that private keys, plaintext seed phrases, and user funds are inaccessible from server-side operations.
• Create split recovery backup mechanisms and recovery-guard controls, which include new-device verification, secondary authentication, cooling-off periods, rate limiting, alerts, and fraud logging.
• Perform an in-depth, line-by-line internal security review of the signing process.
• Promote mobile hardening through integrity attestation, jailbreak/root detection, anti-tamper measures, certificate pinning, and biometric authentication.
• Implement a fail-closed AML/sanctions screening gate on the sending path.
• Conduct pre-signing phishing and risk assessments for destination addresses and calldata.
• Define append-only audit logs for all verifications, screenings, and decisions made.
• Enforce privacy boundaries, including PII segregation, field-level encryption, US-only residency requirements, and retention/deletion policies by data category.
• Manage SAST, secret scanning, SCA, and license scanning throughout the build pipeline.
• Generate a Software Bill of Materials (SBOM) for each release candidate and establish a dependency policy for signing and address-handling protocols.
• Co-sign each milestone exit checklist alongside the Delivery Lead.
• Serve as the technical liaison for the independent auditor and maintain the remediation register.
• Prepare the audit-ready build, address Severity 1/Severity 2 findings, and establish rollout guardrail metrics and minimum version policies.
• Participate in the Severity 1 on-call rotation and create a written postmortem within five business days of resolution.
• Define the scope of the bug bounty program and the reward schedule based on severity.
• Triage, reproduce, and coordinate the remediation of confirmed findings.
• Experience with threat models for iOS and Android platforms.
• Proficiency in iOS Secure Enclave and Android Keystore / StrongBox.
• Familiarity with biometric APIs, platform attestation, RASP, anti-tamper techniques, and certificate pinning.
• Practical experience in mobile reverse engineering using tools such as Frida, objection, and MobSF.
• Knowledge of applied cryptography, including BIP-32 / BIP-39 / BIP-44, ECDSA over secp256k1, AES-GCM, modern KDFs, envelope encryption, KMS, HSM operations, and key rotation.
• Experience in backend and cloud security, particularly with AWS security services, IAM, KMS, VPC, CloudTrail, GuardDuty, OAuth 2.0, OIDC, JWT, JWKS, WebAuthn, session and device binding, API authorization, rate limiting, and secure service-to-service design.
• Understanding of secure SDLC and supply-chain principles, including threat modeling, secure code reviews, SAST, DAST, SCA, SBOM formats, secret scanning, and CI/CD hardening.
• Knowledge of digital asset security, including EVM and Bitcoin transaction structures, ERC-20 approval semantics, ERC-4337 account abstraction and paymaster abuse, smart-account wallets, address-poisoning and drainer patterns, and RPC provider and indexer trust assumptions.
• Familiarity with sanctions and address-screening processes, KYC/CDD data management, the Travel Rule data model, audit logging, retention design, US privacy regulations, ISO/IEC 27001, SOC 2, and NIST CSF.
• Experience in incident response, including detection, severity triage, on-call practices, and postmortem analysis.
• Strong written communication skills for effective engagement with auditors, legal counsel, and non-technical stakeholders.
• Proficiency in English at a C1 level.
• Availability for consistent overlap with US Central Time during working hours.
• Remote flexibility: Work in the environment and manner that suits you best - we trust you to deliver results.
• Competitive salary along with meaningful benefits (medical, wellness, learning opportunities).
• English classes.
• Opportunities for professional development.
• Support for well-being.
• Career advancement possibilities.
• Regular team meetups.
• Engaging tech talks.
Intelance
OX Security
Cloudiax
Cisco
Get handpicked remote jobs straight to your inbox weekly.