Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
описание
Capital.com operates a regulated digital-asset business offering spot trading, custody, staking and on-chain services to clients.
задачи
Own the full custody stack, including MPC key management, transaction authorisation, signing quorums, address whitelisting and withdrawal controls
Govern hot/cold wallet segregation, key ceremonies and delegated cold custodians
Secure staking architecture and on-chain deposit and withdrawal paths
Define crypto-specific hardening requirements for the custody and exchange stack in the multi-account AWS environment, partnering with InfraSec on account segmentation, network and data-residency controls
Partner with AppSec to embed crypto-specific checks into the SDLC for custody and exchange services
Partner with IAM and IAM Tech on privileged access and secrets governance for crypto signing keys and custody credentials
Define custody- and blockchain-specific detection use cases and feed them into SOC monitoring and alerting
Own incident response for crypto-specific scenarios and partner with CorpSec on group-wide incident response, forensics and breach notification
Contribute custody- and blockchain-specific scenarios to AppSec’s penetration-testing and red-team programme
Own security assessment and ongoing assurance of the crypto vendor stack
Apply CorpSec’s vendor onboarding and contract security process to crypto vendor engagements
Own control mapping against MiCA and crypto-specific provisions of DORA and FCA rules; partner with IT Governance on ISO 27001, SOC 2, NIST CSF and GDPR mapping
Feed crypto services into the group’s BC/DR and important-business-service mapping owned by IT Governance
Maintain crypto-specific security policy addenda and support regulatory and IT audits on crypto scope
требования
6+ Years in information security, including recent experience as a senior security engineer, security architect or security lead
Direct experience securing crypto, digital-asset custody or a regulated financial platform
Strong understanding of blockchain security, wallet architecture and key management
Working knowledge of cloud security fundamentals in a regulated environment; AWS preferred, Azure or GCP acceptable
Practical knowledge of security in regulated finance and how controls map to licence conditions, including ISO 27001, SOC 2 and NIST
Experience running threat modelling, risk assessments and incident response
Comfortable working in a matrixed security model, partnering with dedicated IAM, AppSec, SOC and infrastructure security teams rather than owning those functions
Strong analytical and problem-solving skills
Able to translate technical risk into business and regulatory impact
Able to explain security risks and mitigations to non-security teams and regulators
Cross-functional collaboration with risk, compliance, product and engineering teams
Clear documentation and communication skills
Будет плюсом: hands-on Kubernetes, containers, API security and infrastructure as code; Python proficiency for automation and scripting; experience running third-party/vendor security assurance; CISSP, CISM, CCSP or equivalent certifications; hands-on experience with MPC-based custody, key ceremonies and signing-policy design; familiarity with MiCA, DORA, FCA crypto rules or comparable digital-asset regimes; background in secure SDLC and DevSecOps; smart contract security review, including threat modelling, commissioning and managing external audits, and driving findings through to resolution; designing transaction signing and approval flows that prove what a user or operator authorises is what gets signed and broadcast; reviewing business logic in the money path; supply-chain assurance for crypto-specific dependencies; defining bug bounty scope for crypto assets and triaging and calibrating severity for on-chain findings
условия
Competitive salary; amount not specified
Annual leave
Employee referral rewards
Medical insurance and pension plans, plus location-specific benefits and perks
30 Extra days to work remotely from anywhere in the world, with some restrictions