Security Architect (f/m/d)

ITRex Group
Remote

About The Position

We are looking for a Security Architect to be the single technical owner of security and privacy assurance for a self-custody crypto wallet during its first delivery phase. Keys are generated, stored and used on the user's own device, in code that has already been distributed through the app stores - a defect on the signing path can't be fixed server-side or pulled back from devices that already hold the build. Security work here is preventive and continuous, not a hardening phase before launch. You will report to the Project Manager / Delivery Lead, work daily alongside the wallet SDK integration, backend, mobile and DevOps engineers and QA, co-sign the exit checklist of every milestone, and act as the technical counterpart to the independent auditor engaged by the client.

Requirements

  • Mobile and application security: iOS and Android threat models, iOS Secure Enclave and Android Keystore / StrongBox, biometric APIs, platform attestation, RASP and anti-tamper, certificate pinning, and hands-on mobile reverse engineering (Frida, objection, MobSF)
  • Applied cryptography at review-level depth: BIP-32 / BIP-39 / BIP-44, ECDSA over secp256k1, AES-GCM, modern KDFs, envelope encryption, KMS and HSM operation, key rotation
  • Backend and cloud security: AWS security services (IAM, KMS, VPC, CloudTrail, GuardDuty), OAuth 2.0 / OIDC / JWT / JWKS, WebAuthn, session and device binding, API authorisation, rate limiting, and secure service-to-service design
  • Secure SDLC and supply chain: threat modelling, secure code review, SAST / DAST / SCA, SBOM formats, secret scanning, and CI/CD hardening
  • Digital-asset security: EVM and Bitcoin transaction structure, ERC-20 approval semantics, ERC-4337 account abstraction and paymaster abuse, smart-account wallets, address-poisoning and drainer patterns, and the trust assumptions of RPC providers and indexers
  • Compliance-adjacent engineering: sanctions and address-screening flows, KYC/CDD data handling, the Travel Rule data model, audit logging, retention design, and US privacy requirements; working familiarity with ISO/IEC 27001, SOC 2 and NIST CSF
  • Incident response: detection, severity triage, on-call practice and postmortem discipline
  • Strong written communication for auditors, counsel and non-technical stakeholders; English at C1 level; a working day with consistent overlap with US Central Time

Nice To Haves

  • Prior work with a non-custodial wallet SDK, ideally an existing wallet SDK or a comparable open-source kit
  • Smart-contract audit background
  • Penetration-testing certification
  • Experience with app-store review for financial applications
  • Bug-bounty triage experience

Responsibilities

  • Own and extend the threat model across device, backend and every third-party integration, finalised before the audit-ready build
  • Defend the self-custody boundary: no private keys, no plaintext seed phrases and no user funds ever reachable from the server side
  • Design the split recovery backup and the recovery-guard controls: new-device verification, secondary authentication, cooling-off delay, rate limiting, alerts and fraud logging
  • Carry out a line-by-line internal security review of the signing path and drive mobile hardening: device integrity attestation, jailbreak / root detection, anti-tamper, certificate pinning, and biometric gating both at app open and at transaction approval
  • Implement the fail-closed AML / sanctions screening gate on the send path, and the pre-signing phishing and drainer risk scan on destination addresses and calldata
  • Specify the append-only audit record for every verification, screening and decision, and enforce privacy boundaries: PII segregation, field-level encryption, US-only residency, and retention and deletion by data category
  • Own SAST, secret scanning, SCA and licence scanning in the build pipeline, produce an SBOM for every release candidate, and set dependency policy for the signing and address-handling path
  • Co-sign the exit checklist of every milestone with the Delivery Lead, act as technical counterpart to the independent auditor, and own the remediation register for all findings
  • Prepare the audit-ready build, triage and drive remediation of Severity 1 / Severity 2 findings, and define the rollout guardrail metrics and minimum-version policy
  • Participate in the Severity 1 on-call rotation and produce a written postmortem within five business days of resolution
  • Define the bug-bounty scope and severity-to-reward schedule, and triage, reproduce and coordinate remediation of confirmed findings

Benefits

  • Medical
  • Wellness
  • Learning
  • English classes
  • Professional development
  • Well-being support
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service