Overview
Role Purpose: Own private-key security, signing controls, and end-to-end key lifecycle governance for the Digital Asset Custody platform. The role ensures institutional-grade cryptographic controls aligned with regulatory, audit, and security requirements.
Key Responsibilities
- Define and maintain key generation, storage, rotation, backup, and recovery procedures
- Configure and manage MPC and/or HSM quorum rules, approval workflows, and segregation of duties
- Implement and enforce signing controls across custody transaction flows
- Support security audits, penetration tests, and regulatory reviews related to key management
- Participate in incident response activities involving key compromise, recovery, or control failures
- Ensure cryptographic controls are embedded by design across custody operations
Core Competencies (Trading / Investments Equivalent)
- Applied cryptography in regulated financial environments
- Custody key lifecycle governance (institutional asset protection equivalent to trade authorization controls)
- Strong security-by-design mindset with operational and regulatory awareness
Technologies / Platforms (incl. shortlisted)
- HSMs (CloudHSM and/or on-premise HSM solutions)
- MPC frameworks for distributed key custody and signing
- Ripple Custody governance engine
- Supporting security, access control, and audit tooling
Skillset / Experience
- Proven experience in institutional digital asset custody key management
- Deep understanding of blockchain signing models, private-key cryptography, and transaction authorization
- Hands-on experience with HSM and/or MPC-based custody architectures
- Strong exposure to audits, regulators, and security governance processes
- Ability to work closely with security, compliance, product, and platform teams in a regulated environment