Security Architect (f/m/d)

Brak informacji o wynagrodzeniu
SeniorFull-time
#437383·Dodano 5 dni temu·0
Źródło: ITRex Group
Aplikuj teraz

Tech Stack / Keywords

FridaMobSFECDSAAES-GCMKMSHSMIAMCloudTrailGuardDutyOAuth 2.0

Firma i stanowisko

ITRex is an AI-focused company with over 250 employees across the US and Europe, building real-world systems for clients such as Procter & Gamble and Shutterstock.

Wymagania

  • Expertise in mobile and application security including iOS Secure Enclave, Android Keystore/StrongBox, biometric APIs, platform attestation, RASP, anti-tamper, certificate pinning, and mobile reverse engineering tools like Frida, objection, MobSF.
  • Applied cryptography knowledge covering BIP-32/BIP-39/BIP-44, ECDSA over secp256k1, AES-GCM, modern KDFs, envelope encryption, KMS and HSM operations, key rotation.
  • Backend and cloud security experience with AWS security services (IAM, KMS, VPC, CloudTrail, GuardDuty), OAuth 2.0/OIDC/JWT/JWKS, WebAuthn, session and device binding, API authorization, rate limiting, and secure service-to-service design.
  • Secure SDLC and supply chain skills including threat modelling, secure code review, SAST/DAST/SCA, SBOM formats, secret scanning, and CI/CD hardening.
  • Digital-asset security: knowledge of EVM and Bitcoin transaction structures, ERC-20, ERC-4337, smart-account wallets, address-poisoning/drainer patterns, RPC provider and indexer trust assumptions.
  • Compliance-adjacent engineering including sanctions/address-screening flows, KYC/CDD data handling, Travel Rule data model, audit logging, retention design, knowledge of ISO/IEC 27001, SOC 2, and NIST CSF.
  • Incident response capabilities including detection, severity triage, on-call practice, and postmortem discipline.
  • Strong written communication skills for auditors, counsel, and non-technical stakeholders.
  • English language proficiency at C1 level.

Nice to have:

  • Prior experience with non-custodial wallet SDKs.
  • Smart-contract audit background.
  • Penetration-testing certification.
  • Experience with app-store review for financial applications.
  • Bug-bounty triage experience.

Obowiązki

  • Own and extend the threat model across device, backend, and third-party integrations before the audit-ready build.
  • Defend the self-custody boundary to ensure no private keys or user funds are accessible server-side.
  • Design split recovery backup and recovery-guard controls including new-device verification, secondary authentication, cooling-off delay, rate limiting, alerts, and fraud logging.
  • Conduct line-by-line internal security review of the signing path and drive mobile hardening (device integrity attestation, jailbreak/root detection, anti-tamper, certificate pinning, biometric gating at app open and transaction approval).
  • Implement a fail-closed AML/sanctions screening gate on the send path and perform pre-signing phishing and drainer risk scans on destination addresses and calldata.
  • Specify append-only audit records for verifications and enforce privacy boundaries like PII segregation, field-level encryption, US-only residency, and data retention and deletion policies.
  • Manage SAST, secret scanning, SCA, license scanning in the build pipeline, produce SBOMs for release candidates, and set dependency policies for signing and address-handling paths.
  • Co-sign milestone exit checklists with Delivery Lead, act as technical counterpart to independent auditor, and maintain the remediation register.
  • Prepare audit-ready builds, triage and manage remediation of Severity 1 and 2 findings, and define rollout guardrail metrics and minimum-version policies.
  • Participate in Severity 1 on-call rotation and produce written postmortems within five business days of resolution.
  • Define bug-bounty scope and severity-to-reward schedule; triage, reproduce, and coordinate remediation of confirmed findings.

Benefity

  • Remote flexibility allowing work where and how you work best.
  • Competitive salary and benefits including medical, wellness, and learning.
  • Ownership opportunities encouraging smart risks.
  • Use of AI tools to enhance work efficiency.
  • Learning investments like English classes, professional development, and well-being support.
  • Clear career progression paths.
  • Responsive and supportive team environment.
  • Regular meetups, tech talks, and strong human connections beyond work.
Elastyczne godziny
Opieka zdrowotna
Dofinansowanie szkoleń
Kursy językowe
ITRex Group

ITRex Group

2 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz