Security Architect for Self‑Custody Crypto Wallet
ITRex Group
Job description
About the role
We are seeking a Security Architect to own security and privacy assurance for a self‑custody crypto wallet during its first delivery phase. The wallet runs on users’ devices, with keys generated, stored and used locally, meaning any defect in the signing path cannot be fixed after release. You will work closely with SDK, backend, mobile and DevOps teams and act as the technical counterpart to the independent auditor.
Key responsibilities
- Be the single technical owner of security and privacy assurance for the wallet.
- Co‑sign the exit checklist for every milestone and ensure compliance with audit requirements.
- Collaborate daily with wallet SDK integration, backend, mobile, DevOps engineers and QA.
- Conduct threat modelling, security reviews and continuous hardening of mobile, backend and cloud components.
- Define and enforce secure SDLC practices, supply‑chain security and CI/CD hardening.
- Support incident detection, triage, on‑call response and post‑mortem analysis.
- Liaise with the independent auditor and provide clear written communication for auditors, counsel and non‑technical stakeholders.
Required profile
- Extensive experience in mobile and application security (iOS, Android).
- Deep knowledge of applied cryptography and key management.
- Strong background in backend and cloud security, especially AWS.
- Proven expertise in secure SDLC, threat modelling and supply‑chain security.
- Familiarity with digital‑asset security, blockchain transaction structures and smart‑wallet patterns.
- Understanding of compliance frameworks (ISO/IEC 27001, SOC 2, NIST CSF) and US privacy requirements.
- Excellent written communication in English (C1 level).
Required skills
- iOS Secure Enclave
- Android Keystore / StrongBox
- Biometric APIs
- Platform attestation
- RASP
- Anti‑tamper techniques
- Certificate pinning
- Frida
- objection
- MobSF
- BIP‑32
- BIP‑39
- BIP‑44
- ECDSA secp256k1
- AES‑GCM
- Modern KDFs
- Envelope encryption
- KMS
- HSM operation
- Key rotation
- AWS IAM
- AWS KMS
- AWS VPC
- AWS CloudTrail
- AWS GuardDuty
- OAuth 2.0
- OIDC
- JWT
- JWKS
- WebAuthn
- Session and device binding
- API authorisation
- Rate limiting
- Secure service‑to‑service design
- Threat modelling
- Secure code review
- SAST
- DAST
- SCA
- SBOM formats
- Secret scanning
- CI/CD hardening
- EVM
- Bitcoin transaction structure
- ERC‑20 approval semantics
- ERC‑4337 account abstraction
- Smart‑account wallets
- Address‑poisoning detection
- ISO/IEC 27001
- SOC 2
- NIST CSF
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Serbia.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 7 hours ago
Expires 1 month from now
5 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
ITRex Group