Jobgether
Principal Security Architect (On-Chain & Digital Assets)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security Architect (On-Chain & Digital Assets) based in United Kingdom.
About the Role
Own security architecture across the custody and on-chain layer of a regulated digital-asset platform operating globally.
You will define and implement security requirements spanning architecture, engineering, operations, and regulatory assurance.
The role covers critical areas including MPC and HSM key management, transaction authorization, wallet security, staking, and blockchain integrations.
You will work closely with dedicated Infrastructure Security, Application Security, IAM, and SOC teams while providing specialized crypto-security leadership.
Your expertise will help protect transaction flows, digital assets, and key management systems against sophisticated operational and cyber risks.
You will also lead threat modeling, security assessments, incident response, and regulatory control mapping across international markets.
This is a hands-on principal-level opportunity for a security architect with deep digital-asset expertise who can translate complex technical risks into resilient controls and clear business outcomes.
Accountabilities
- Own end-to-end security architecture for the custody and on-chain technology stack.
- Define security requirements and controls for HSM and MPC-based key management, transaction authorization, signing quorums, address whitelisting, and hot/cold wallet segregation.
- Establish secure processes for key ceremonies, delegated cold custody, staking deposits and withdrawals, and other critical digital-asset operations.
- Develop crypto-specific security standards, privileged-access controls, and secure SDLC requirements within a multi-account AWS environment.
- Partner with centralized Infrastructure Security, Application Security, IAM, and SOC teams to implement and maintain platform security capabilities.
- Define blockchain and custody-specific detection use cases for the SOC.
- Lead incident response procedures for crypto-specific scenarios, including key compromise, unauthorized transactions, and significant on-chain incidents, in collaboration with Corporate Security.
- Conduct detailed threat modeling and security reviews covering internal ledger mechanisms, balance idempotency, withdrawal sequencing, and smart contract integrations.
- Protect the integrity of transaction and funds flows across the platform by identifying and mitigating architectural and operational risks.
- Direct security assessments and ongoing assurance activities for external custody providers, execution systems, blockchain analytics solutions, Travel Rule tools, and treasury integrations.
- Map security controls to relevant international regulatory frameworks, including MiCA, DORA, FCA, and MAS requirements.
- Collaborate with market and regulatory teams to maintain appropriate security and compliance controls as the platform expands internationally.
- Translate complex cryptographic, infrastructure, and digital-asset risks into clear business and regulatory implications for non-security stakeholders.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Requirements
- 10+ years of professional experience in information security, with a proven track record as a Security Architect, Principal Security Engineer, or technical security lead.
- Demonstrated experience securing digital-asset custody platforms, high-throughput crypto environments, or regulated financial infrastructure.
- Deep practical knowledge of crypto custody and wallet architecture, including Multi-Party Computation (MPC), Hardware Security Modules (HSMs), key ceremonies, and signing-policy design.
- Strong cloud security expertise, preferably within AWS environments and regulated organizations.
- Practical experience mapping security controls to recognized frameworks and regulatory requirements, including ISO 27001, SOC 2, and NIST.
- Strong experience conducting threat modeling, security assessments, risk analysis, and incident response.
- Ability to communicate sophisticated cryptographic and technical security risks clearly to business leaders, product teams, engineers, compliance professionals, and regulators.
- Proven ability to operate effectively within a matrixed security organization and collaborate with dedicated IAM, AppSec, SOC, and Infrastructure Security functions.
- Strong understanding of security architecture, secure software development, access controls, operational security, and risk management.
- Experience working with regulated digital-asset, fintech, financial services, or blockchain environments.
- Hands-on experience with Kubernetes, containers, Terraform or other Infrastructure as Code technologies, API security, or Python automation is an advantage.
- Experience with Web3 dependency and software supply-chain security is a plus.
- Industry certifications such as CISSP, CISM, CCSP, or CCSSA are advantageous.
- Professional fluency in spoken and written Mandarin is beneficial for regional operations and cross-functional engineering collaboration.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Benefits
- Competitive compensation package.
- Fully remote working opportunity.
- International and distributed working environment.
- Opportunity to work on security architecture for digital-asset custody, blockchain, and on-chain infrastructure.
- Exposure to complex fintech, cryptocurrency, and regulated financial technology environments.
- Collaboration with specialized security, engineering, compliance, risk, product, and operations teams.
- Opportunities to influence security architecture and controls across international markets.
- Team-building initiatives and company events.
- Senior-level scope with significant ownership over critical security architecture and risk management.
- Opportunity to contribute to the development of secure, scalable digital-asset infrastructure.
How Jobgether Works
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location