Principal Security Engineer (Crypto Digital Assets)

Capital.com

Dubai

On-site

AED 500,000 - 900,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive Salary
Work-Life Harmony
Generous Time Off
Employee Referral Program
Health & Pension Benefits
Workation
Volunteer Days

Job summary

Capital.com in the UAE seeks a Principal Security Engineer to own crypto custody security across our digital-asset stack, including on-chain paths, wallets, and key management. You will collaborate with InfraSec, AppSec, IAM, and risk/compliance teams in a regulated environment to ensure robust controls and regulatory alignment.

The role emphasizes hands-on leadership in security architecture, threat modelling, and incident response for crypto-related scenarios, with a focus on safeguarding the

Qualifications

  • 6+ years in information security including senior security engineer/architect roles
  • Direct experience securing crypto custody or regulated platforms with blockchain awareness
  • Cloud security fundamentals in regulated environments (AWS preferred)
  • Knowledge of ISO 27001 SOC 2 NIST; familiarity with licensing conditions

Responsibilities

  • Own full custody stack security controls (MPC, key management, withdrawal controls)
  • Define crypto-specific hardening requirements for custody and exchange in multi-account AWS
  • Embed crypto checks into SDLC (SAST/DAST/SCA, CI/CD gates)
  • Define custody and blockchain detection use cases for SOC monitoring
  • Own incident response for on-chain crypto scenarios and coordinate with CorpSec
  • Vendor security assurance for crypto vendor engagements
  • Maintain crypto security policy mapping to MiCA, DORA and FCA rules

Skills

Info security
Crypto security
Cloud security
Regulated finance
Threat modelling
Matrixed security model

Job description

We are looking for a Principal Security Engineer with deep crypto domain expertise to lead security across our regulated digital-asset business. As we build out spot trading custody staking and on-chain services for our client base security is the foundation the whole business stands on. This role owns it.
You will be the security owner for our crypto platforms custody and on-chain layer end to end: architecture engineering operations and regulatory assurance for the parts of the stack that are unique to digital assets. For platform capabilities already owned by central security teams (cloud application security IAM SOC) youll define the crypto-specific requirements and partner on delivery rather than duplicate ownership. You will work closely with risk compliance product and engineering and report into the central security function.
This is a hands-on senior role for someone who understands that in digital-asset custody a single key-management failure is a firm-ending event and who builds controls accordingly.

Key Responsibilities:
Digital asset and custody security (owned by this role):
  • Own the full custody stack: MPC key management transaction authorisation signing quorums address whitelisting and withdrawal controls
  • Govern hot/cold wallet segregation key ceremonies and delegated cold custodians
  • Secure staking architecture and on-chain deposit/withdrawal paths
Platform cloud and application security (partner with InfraSec AppSec and IAM):
  • Define crypto-specific hardening requirements for the custody and exchange stack within the existing multi-account AWS environment; partner with InfraSec on account segmentation network and data-residency controls
  • Partner with AppSec to embed crypto-specific checks into the SDLC (SAST DAST SCA CI/CD security gates) for custody and exchange services
  • Partner with IAM and IAM Tech on privileged access and secrets governance for crypto signing keys and custody credentials
Threat detection response and testing (partner with SOC CorpSec and AppSec):
  • Define custody- and blockchain-specific detection use cases and feed them into SOCs monitoring and alerting
  • Own incident response for crypto-specific scenarios (key compromise unauthorised transaction on-chain incident); partner with CorpSec on the group-wide IR process forensics and breach notification
  • Contribute custody- and blockchain-specific scenarios into AppSecs pentest and red-team programme
Third-party and vendor security (own crypto vendor risk partner with CorpSec on process):
  • Own security assessment and ongoing assurance of the crypto vendor stack: custody platforms execution systems blockchain analytics Travel Rule and treasury tooling
  • Apply CorpSecs vendor onboarding and contract security process to crypto vendor engagements
Regulatory resilience and governance (own crypto-specific mapping partner with IT Governance):
  • Own control mapping against MiCA and the crypto-specific provisions of DORA and FCA rules; partner with IT Governance on ISO 27001 SOC 2 NIST CSF and GDPR mapping
  • Feed crypto services into the groups BC/DR and important-business-service mapping owned by IT Governance
  • Maintain crypto-specific security policy addenda; support regulatory and IT audits on crypto scope
Required Qualifications:
  • 6 years in information security including recent experience as a senior security engineer security architect or security lead;
  • Direct experience securing crypto digital-asset custody or a regulated financial platform; strong understanding of blockchain security wallet architecture and key management;
  • Working knowledge of cloud security fundamentals (AWS preferred Azure/GCP acceptable) in a regulated environment;
  • Practical knowledge of security in regulated finance and how controls map to licence conditions (ISO 27001 SOC 2 NIST);
  • Experience running threat modelling risk assessments and incident response;
  • Comfortable operating in a matrixed security model - partnering with dedicated IAM AppSec SOC and infrastructure security teams rather than owning those functions outright.
Nice to have:
  • Hands-on Kubernetes containers API security and infrastructure as code;
  • Python proficiency for automation and scripting;
  • Experience running third-party / vendor security assurance;
  • Recognised certifications: CISSP CISM CCSP or equivalent;
  • Hands-on experience with MPC - based custody key ceremonies and signing-policy design;
  • Familiarity with MiCA DORA FCA crypto rules or comparable digital-asset regimes;
  • Background in secure SDLC and DevSecOps (OWASP secure-by-design);
  • Experience with smart contract security review: threat modelling commissioning and managing external audits and driving findings through to resolution;
  • Experience designing transaction signing and approval flows so that what a user or operator authorises is provably what gets signed and broadcast;
  • Experience reviewing business logic in the money path - withdrawal sequencing balance idempotency internal ledger integrity - where the flaw sits in the logic rather than the cryptography;
  • Familiarity with supply-chain assurance for crypto-specific dependencies: wallet SDKs chain libraries node clients and signing tooling including pinning provenance and upgrade discipline;
  • Experience defining bug bounty scope for crypto assets and triaging and calibrating severity for on-chain findings.
Soft Skills:
  • Strong analytical and problem-solving skills;
  • Able to translate technical risk into business and regulatory impact;
  • Able to explain security risks and mitigations to non-security teams and to regulators;
  • Cross-functional collaboration with risk compliance product and engineering teams;
  • Clear documentation and communication skills.
What You Will Get in Return:
  • Competitive Salary:We believe great work deserves great pay. Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.
  • Work-Life Harmony:Join a company that genuinely cares about you because your life outside of work matters just as much as your time on the clock. #LI-Hybrid
  • Generous Time Off:Need a breather Our annual leave policy lets you recharge and enjoy life outside of work without a worry.
  • Employee Referral Program:Love working here Share the love. Bring your talented friends on board and get rewarded for growing our team.
  • Comprehensive Health & Pension Benefits:From medical insurance to pension plans weve got your back. Plus location-specific benefits and perks.
  • Workation Wonderland:Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply).
  • Volunteer Days:Take two additional paid days each year to support causes you care about and give back to the community.

Be a key player at the forefront of the digital assets movement propelling your career to new heights. Join a dynamic and rapidly expanding company that values and rewards talent initiative and creativity. Work alongside one of the most brilliant teams in the industry. We may use artificial intelligence (AI) tools to support parts of the hiring process such as reviewing applications analyzing resumes or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed please contact us.

Required Experience:

Staff IC

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Engineer (Crypto / Digital Assets)
Principal Security Engineer (Crypto / Digital Assets)

Capital Com SV Investments Limited • Dubai

On-site
AED 700,000 - 1,000,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+4
Senior Security Specialist (Crypto / Digital Assets)
Senior Security Specialist (Crypto / Digital Assets)

Capital.com • Dubai

On-site
AED 600,000 - 1,200,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+3
Crypto Security Lead – Digital Assets & Custody
Crypto Security Lead – Digital Assets & Custody

Capital Com SV Investments Limited • Dubai

On-site
AED 700,000 - 1,000,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+4
Technical Analyst - Cryptography & Key Management Specialist
Technical Analyst - Cryptography & Key Management Specialist

Dicetek LLC • Abu Dhabi

On-site
AED 120,000 - 150,000
Principal Crypto Security Architect (Custody & On-Chain)
Principal Crypto Security Architect (Custody & On-Chain)

Capital.com • Dubai

On-site
AED 500,000 - 900,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+4
Staff Engineer — Custody Platform (The Vault)
Staff Engineer — Custody Platform (The Vault)

The Vault • Dubai

On-site
AED 550,000 - 750,000
Head of Compliance / MLRO (SCA)
Head of Compliance / MLRO (SCA)

Capital.com • Dubai

On-site
Work-Life Harmony
Annual Performance Bonus
Generous Time Off
+3
Crypto Custody Security Architect
Crypto Custody Security Architect

Capital.com • Dubai

On-site
AED 600,000 - 1,200,000
Competitive Salary
Work-Life Harmony
Generous Time Off
+3
Senior Engineering Manager, Fortary Platform
Senior Engineering Manager, Fortary Platform

Jobgether • United Arab Emirates

On-site
AED 450,000 - 750,000
Group Head of Security
Group Head of Security

CFI Financial Group • Dubai

On-site
AED 600,000 - 900,000