Security Architect (f/m/d)
Brak informacji o wynagrodzeniu
SeniorFull-time
#437383·Dodano 5 dni temu·0
Źródło: ITRex GroupTech Stack / Keywords
FridaMobSFECDSAAES-GCMKMSHSMIAMCloudTrailGuardDutyOAuth 2.0
Firma i stanowisko
ITRex is an AI-focused company with over 250 employees across the US and Europe, building real-world systems for clients such as Procter & Gamble and Shutterstock.
Wymagania
- Expertise in mobile and application security including iOS Secure Enclave, Android Keystore/StrongBox, biometric APIs, platform attestation, RASP, anti-tamper, certificate pinning, and mobile reverse engineering tools like Frida, objection, MobSF.
- Applied cryptography knowledge covering BIP-32/BIP-39/BIP-44, ECDSA over secp256k1, AES-GCM, modern KDFs, envelope encryption, KMS and HSM operations, key rotation.
- Backend and cloud security experience with AWS security services (IAM, KMS, VPC, CloudTrail, GuardDuty), OAuth 2.0/OIDC/JWT/JWKS, WebAuthn, session and device binding, API authorization, rate limiting, and secure service-to-service design.
- Secure SDLC and supply chain skills including threat modelling, secure code review, SAST/DAST/SCA, SBOM formats, secret scanning, and CI/CD hardening.
- Digital-asset security: knowledge of EVM and Bitcoin transaction structures, ERC-20, ERC-4337, smart-account wallets, address-poisoning/drainer patterns, RPC provider and indexer trust assumptions.
- Compliance-adjacent engineering including sanctions/address-screening flows, KYC/CDD data handling, Travel Rule data model, audit logging, retention design, knowledge of ISO/IEC 27001, SOC 2, and NIST CSF.
- Incident response capabilities including detection, severity triage, on-call practice, and postmortem discipline.
- Strong written communication skills for auditors, counsel, and non-technical stakeholders.
- English language proficiency at C1 level.
Nice to have:
- Prior experience with non-custodial wallet SDKs.
- Smart-contract audit background.
- Penetration-testing certification.
- Experience with app-store review for financial applications.
- Bug-bounty triage experience.
Obowiązki
- Own and extend the threat model across device, backend, and third-party integrations before the audit-ready build.
- Defend the self-custody boundary to ensure no private keys or user funds are accessible server-side.
- Design split recovery backup and recovery-guard controls including new-device verification, secondary authentication, cooling-off delay, rate limiting, alerts, and fraud logging.
- Conduct line-by-line internal security review of the signing path and drive mobile hardening (device integrity attestation, jailbreak/root detection, anti-tamper, certificate pinning, biometric gating at app open and transaction approval).
- Implement a fail-closed AML/sanctions screening gate on the send path and perform pre-signing phishing and drainer risk scans on destination addresses and calldata.
- Specify append-only audit records for verifications and enforce privacy boundaries like PII segregation, field-level encryption, US-only residency, and data retention and deletion policies.
- Manage SAST, secret scanning, SCA, license scanning in the build pipeline, produce SBOMs for release candidates, and set dependency policies for signing and address-handling paths.
- Co-sign milestone exit checklists with Delivery Lead, act as technical counterpart to independent auditor, and maintain the remediation register.
- Prepare audit-ready builds, triage and manage remediation of Severity 1 and 2 findings, and define rollout guardrail metrics and minimum-version policies.
- Participate in Severity 1 on-call rotation and produce written postmortems within five business days of resolution.
- Define bug-bounty scope and severity-to-reward schedule; triage, reproduce, and coordinate remediation of confirmed findings.
Benefity
- Remote flexibility allowing work where and how you work best.
- Competitive salary and benefits including medical, wellness, and learning.
- Ownership opportunities encouraging smart risks.
- Use of AI tools to enhance work efficiency.
- Learning investments like English classes, professional development, and well-being support.
- Clear career progression paths.
- Responsive and supportive team environment.
- Regular meetups, tech talks, and strong human connections beyond work.
Elastyczne godziny
Opieka zdrowotna
Dofinansowanie szkoleń
Kursy językowe
ITRex Group
2 aktywne oferty