Description
The Principal Security Engineer is a senior individual contributor responsible for defining, building, and operating security programs for high-risk financial technology and crypto infrastructure products. This role leads security architecture and hands-on technical security work across application security, product security, infrastructure security, incident response, vulnerability management, threat modeling, secure software development, and security automation.
Key responsibilities include leading security architecture reviews for embedded wallet systems, conducting advanced threat modeling for web, mobile, cloud, wallet, blockchain, and cryptographic systems, identifying and validating vulnerabilities across applications, infrastructure, APIs, CI/CD pipelines, third-party integrations, and production services.
The Principal Security Engineer is expected to operate independently on ambiguous, high-impact security problems; design scalable security controls; review complex architectures; identify exploitable vulnerabilities; build security tooling; guide engineering teams; and represent security judgment in critical product and platform decisions.
Minimum requirements include 10 years of professional experience in software security, application security, product security, infrastructure security, security engineering, vulnerability research, incident response, or closely related technical security roles, with experience securing production software systems, cloud infrastructure, web applications, APIs, authentication systems, or financial technology platforms.
Preferred qualifications include experience securing cryptocurrency, blockchain, wallet, custody, payment, financial technology, or high-value transaction systems, experience with bug bounty programs, responsible disclosure, penetration testing, red-team findings, or vulnerability research, and experience reviewing cryptographic protocols, transaction signing systems, embedded wallets, smart-contract-adjacent systems, or developer SDKs.