Job description
We are looking for a Senior Security Specialist with deep crypto domain expertise to lead security across our regulated digital-asset business. As we build out spot trading, custody, staking and on-chain services for our client base, security is the foundation the whole business stands on. This role owns it.
You will be the security owner for our crypto platform end to end: architecture, engineering, operations and regulatory assurance. You’ll secure a greenfield, cloud-native exchange and custody stack, protect client digital assets and private key material, and make sure our controls stand up to regulators across multiple jurisdictions. You will work closely with risk, compliance, product and engineering, and report into the central security function.
This is a hands-on senior role for someone who understands that in digital-asset custody, a single key-management failure is a firm-ending event, and who builds controls accordingly.
Key Responsibilities:
-
Digital asset and custody security:
- Own the full custody stack: MPC/HSM key management, transaction authorisation, signing quorums, address whitelisting and withdrawal controls;
- Govern hot/cold wallet segregation, key ceremonies and delegated cold custodians;
- Secure staking architecture and on-chain deposit/withdrawal paths.
Platform, cloud and application security:
- Design and run cloud security across a multi-account AWS environment: account segmentation, SCPs, network and data-residency controls;
- Secure the Kubernetes platform, event-streaming layer and database architecture;
- Embed DevSecOps into the SDLC: SAST, DAST, SCA, secrets management and CI/CD security gates; own IAM, privileged access and secrets governance.
Threat detection, response and testing:
- Stand up and run threat detection, monitoring and alerting across the estate;
- Own incident response end to end: playbooks, forensics, breach notification and post-incident review;
- Run vulnerability management, pen testing and red-teaming, including custody- and blockchain-specific scenarios.
Third-party and vendor security:
- Own security assessment and ongoing assurance of the vendor stack: custody platforms, execution systems, blockchain analytics, Travel Rule and treasury tooling;
- Set security requirements for vendor onboarding, contracts and outsourcing arrangements.
Regulatory, resilience and governance:
- Map controls against MiCA, DORA, FCA, GDPR and recognised standards (ISO 27001, SOC 2, NIST CSF);
- Own operational resilience from a security angle: BC, DR and important business service mapping;
- Maintain the security policy suite and control framework; support regulatory and IT audits.
AI security:
- Secure LLM integrations, RAG pipelines and AI-enabled automation against prompt injection, data leakage and over-permissioned agents.
Required Qualifications:
- 6+ years in information security, including recent experience as a senior security engineer, security architect, or security lead;
- Direct experience securing crypto, digital-asset custody, or a regulated financial platform; strong understanding of blockchain security, wallet architecture and key management;
- Strong cloud security background on AWS (Azure or GCP also useful); hands-on with Kubernetes, containers, API security and infrastructure as code;
- Practical knowledge of security in regulated finance and how controls map to licence conditions (ISO 27001, SOC 2, NIST);
- Experience running threat modelling, risk assessments, incident response and third-party security assurance;
- Python proficiency for automation and scripting.
Preferred Qualifications:
- Recognised certifications: CISSP, CISM, CCSP, or equivalent;
- Hands-on experience with MPC or HSM-based custody, key ceremonies and signing-policy design;
- Familiarity with MiCA, DORA, FCA crypto rules, or comparable digital-asset regimes;
- Experience with blockchain analytics and Travel Rule tooling;
- Exposure to AI security, RAG architectures and ML pipelines;
- Background in secure SDLC and DevSecOps (OWASP, secure-by-design).
Soft Skills:
- Strong analytical and problem-solving skills;
- Able to translate technical risk into business and regulatory impact;
- Able to explain security risks and mitigations to non-security teams and to regulators;
- Cross-functional collaboration with risk, compliance, product and engineering teams;
- Clear documentation and communication skills.
What You Will Get in Return:
- Competitive Salary: We believe great work deserves great pay. Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.
- Work-Life Harmony: Join a company that genuinely cares about you, because your life outside of work matters just as much as your time on the clock. #LI-Hybrid
- Generous Time Off: Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.
- Employee Referral Program: Love working here? Share the love. Bring your talented friends on board and get rewarded for growing our team.
- Comprehensive Health & Pension Benefits: From medical insurance to pension plans, we’ve got your back. Plus location-specific benefits and perks.
- Workation Wonderland: Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply).
- Volunteer Days: Take two additional paid days each year to support causes you care about and give back to the community.
وصف الوظيفة
نحن نبحث عن أخصائي أمني أول يمتلك خبرة عميقة في مجال التشفير لقيادة الأمن عبر أعمال الأصول الرقمية المنظمة الخاصة بنا. مع تطلعنا لبناء تبادل وطني وآمن وتخزين وتخزين وتوكنات وخدمات على السلسلة لشريحة عملائنا، الأمن هو الأساس الذي يقوم عليه العمل ككل. هذا الدور هو المسؤول عنه.
ستكون مالك الأمن لمنصة التشفير لدينا من البداية إلى النهاية: الهندسة والمعمار والأنشطة والاطمئنان التنظيمي. ستؤمن منصة تبادل ووحدة تخزين مع سحابة حاسوبية جديدة، وتحمي أصول العملاء الرقمية ومواد المفاتيح الخاصة، وتتأكد من أن ضوابطنا تفي بمتطلبات الجهات التنظيمية عبر ولايات قضائية متعددة. ستعمل عن كثب مع المخاطر والامتثال والمنتج والهندسة، وتقرير إلى وظيفة الأمن المركزية.
هذا دور عملي رفيع المستوى لشخص يفهم أنه في حفظ الأصول الرقمية، فشل واحد في إدارة المفاتيح يمكن أن ينهى الشركة، ومن يبني ضوابط وفقاً لذلك.
المسؤوليات الرئيسية:
-
أمن الأصول الرقمية والحفظ:
- امتلاك كامل طبقة الحفظ: إدارة المفاتيح MPC/HSM، تفويض المعاملات، شهادات التوقيع، قائمة العناوين البيضاء وضوابط السحب؛
- تنظيم فصل المحفظة الساخنة والباردة، مراسم المفاتيح والوكلاء الباردة المفوضين؛
- تصميم بنية التخزين الآمن والتوجيهات على السلسلة للودائع /السحب.
Platform, cloud and application security:
- تصميم وتشغيل أمان السحابة عبر بيئة AWS متعددة الحسابات: تقسيم الحسابات، SCPs، ضوابط الشبكة والبيانات المقيدة جغرافياً؛
- تأمين منصة Kubernetes وطبقة تدفق الأحداث وبنية قاعدة البيانات؛
- دمج DevSecOps ضمن دورة حياة التطوير: SAST وDAST وSCA وإدارة الأسرار وبوابات أمان CI/CD؛ امتلاك IAM والوصول المحمي وحوكمة الأسرار.
Threat detection, response and testing:
- إعداد وتشغيل كشف التهديدات والمراقبة والتنبيه عبر المنشأة؛
- امتلاك الاستجابة للحوادث من البداية للنهاية: دفاتر التشغيل والتحقيق والإخطار بالانتهاك ومراجعة ما بعد الحادث؛
- إدارة الثغرات، اختبار الاختراق والتنظيم الحمر، بما في ذلك سيناريوهات الحفظ والسلسلة الخاصة.
Third-party and vendor security:
- امتلاك تقييم الأمن والضمان المستمر لمكدسات الموردين: منصات الحفظ وأنظمة التنفيذ والتحليلات السلسلية وأدوات Travel Rule والخزينة؛
- وضع متطلبات الأمن لاستقبال الموردين والعقود والترتيبات الخارجية.
Regulatory, resilience and governance:
- رسم الخرائط للضوابط مقابل MiCA وDORA وFCA وGDPR والمعايير المعترف بها (ISO 27001 وSOC 2 وNIST CSF)؛
- امتلاك المرونة التشغيلية من زاوية الأمان: استمرارية الأعمال والتعافي ورسم خدمات الأعمال المهمة؛
- الحفاظ على حزمة سياسات الأمن وإطار الضبط؛ دعم التدقيق التنظيمي وتكنولوجيا المعلومات.
AI security:
- تأمين تكاملات LLM وخطوط RAG والأتمتة المدعومة بالذكاء الاصطناعي ضد حقن المطالبات، تسريب البيانات وعموم الإذن المفرط.
المؤهلات المطلوبة:
- 6+ سنوات في أمان المعلومات، بما في ذلك خبرة حديثة كمهندس أمني أول أو معماري أمني أو قائد أمني؛
- خبرة مباشرة في تأمين التشفير، حفظ الأصول الرقمية، أو منصة مالية منظمة؛ فهم قوي لأمان blockchain، هيكل المحافظ وإدارة المفاتيح؛
- خلفية أمان سحابي قوية على AWS (Azure أو GCP مفيد أيضاً); خبرة عملية مع Kubernetes والحاويات وأمان API والبنية التحتية كرمز؛
- معرفة عملية بالأمان في المالية المنظمة وكيفية توافق الضوابط مع شروط الرخصة (ISO 27001 وSOC 2 وNIST);
- خبرة في تشغيل نمذجة التهديدات، تقييمات المخاطر، الاستجابة للحوادث وضمان أمان الطرف الثالث؛
- إتقان Python للأتمتة والبرمجة النصية.
المؤهلات المفضلة:
- شهادات معترف بها: CISSP وCISM وCCSP أو ما يعادلها؛
- خبرة عملية مع الحفظ المرتكز على MPC أو HSM، مراسم المفاتيح وتصميم سياسة التوقيع؛
- معرفة بـMiCA وDORA وقواعد crypto لـ FCA، أو أنظمة أصول رقمية مماثلة؛
- خبرة في التحليلات blockchain وأدوات Travel Rule؛
- اطلاع على أمان AI وهندسة RAG وخطوط أنابيب ML؛
- خلفية في SDLC آمن وDevSecOps (OWASP، تصميم آمن من البداية).
المهارات الشخصية:
- مهارات تحليلية قوية وحل المشكلات؛
- القدرة على ترجمة الخطر التقني إلى تأثير أعمالي وتنظيمي؛
- القدرة على شرح مخاطر الأمن وتدابير التخفيف لفرق غير أمنية وللجهات التنظيمية؛
- التعاون متعدد الوظائف مع فرق المخاطر والامتثال والمنتج والهندسة؛
- مهارات توثيق واتصال واضحة.
ما ستجنيه في المقابل:
- راتب تنافسي: نؤمن أن العمل الجاد يستحق أجراً ممتازاً. ستُكافأ بمهاراتك ومواهبك براتب يشعرونك بالتقدير والتحفيز.
- التوازن بين العمل والحياة: انضم إلى شركة تهتم بك حقاً، فحياتك خارج العمل مهمّة كما وقتك على الساعة. #LI-Hybrid
- إجازات سخية: هل تحتاج لراحة؟ تسمح لك سياسة الإجازة السنوية لدينا بإعادة الشحن والاستمتاع بالحياة خارج العمل بدون قلق.
- برنامج إحالة الموظفين: تحب العمل هنا؟ شارك الحب. جلب أصدقائك الموهوبين إلى الفريق واحصل على مكافأة لتنمية فريقنا.
- مزايا صحية ومعاشات شاملة: من التأمين الطبي إلى خطط المعاشات، نحن ندعمك. إضافة مزايا محدودة حسب الموقع.
- عالم العمل المريح: عش أحلامك الرقمية بالعمل من أي مكان خلال 30 يوماً إضافية (قد تنطبق بعض القيود).
- أيام التطوع: خذ يومين إضافيين مدفوعين كل عام لدعم القضايا التي تهتم بها وتقديم العطاء للمجتمع.