Principal Security Architect (On-Chain & Digital Assets)

BTSE

Brussel Hoofdstad

Hybrid

EUR 140,000 - 200,000

Full time

11 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive compensation package
Team-building programs
Company events

Job summary

BTSE is seeking a Principal Security Architect to own the security of our custody and on-chain layer for a regulated digital-asset platform. This hands-on role spans architecture, engineering, operations, and regulatory assurance, reporting to the central security function.

You will define crypto-specific requirements and partner with InfraSec, AppSec, IAM, and SOC teams. You will shape the security posture across risk, compliance, product, and engineering as we build out spot trading, custody,

Qualifications

  • 10+ years in information security, with a track record as a security architect or technical lead securing digital-asset custody or regulated financial infrastructure.
  • Direct operational experience securing crypto custody, with deep domain expertise in wallet architecture, MPC, HSMs, key ceremonies, and signing-policy design.
  • Strong cloud security fundamentals (AWS preferred) in a regulated environment, mapping security controls to ISO 27001, SOC 2, NIST.
  • Experience running threat modeling, risk assessments, and incident response, translating crypto risk for non-security teams and regulators.
  • Proven ability to work in a matrixed security model with IAM, AppSec, SOC, and infrastructure security teams.

Responsibilities

  • Lead end-to-end security architecture for the full custody stack: HSM/MPC key management, transaction authorization, signing quorums, address whitelisting, wallet segregation, and key ceremonies.
  • Establish crypto-specific baseline standards and secure SDLC requirements within a multi-account AWS environment in collaboration with InfraSec, AppSec, and IAM teams.
  • Define custody and blockchain detection use cases for the SOC and manage incident response procedures for crypto-specific scenarios.
  • Conduct threat modeling and security reviews of ledger mechanics, idempotency, withdrawal sequencing, and smart contracts integrations.
  • Direct security assessments for external custody providers, execution systems, blockchain analytics, Travel Rule tools, and treasury integrations.
  • Own control mapping against international regulatory standards (MiCA, DORA, FCA, MAS) and collaborate with Global Market Teams for expansion.

Skills

Security architecture
Threat modeling
Incident response
Cloud security
Regulatory compliance

Tools

Kubernetes
Terraform
AWS
APIs security
Python
Web3 security

Job description

About BTSE

BTSE Group is a global leader in fintech and blockchain technology, anchored by three core business pillars: Exchange, Payments, and Infrastructure Development. Serving over 100 corporate clients worldwide, we provide white-label exchange and payment solutions. Our offerings encompass everything from exchange infrastructure hosting and development to custody, wallets, payments, blockchain integration, trading, and more. We are looking for talented professionals in marketing, operations, customer support, and other departments. The roles offered may be on-site, remote, or hybrid, in collaboration with our local partner.

About The Opportunity

We are looking for a Principal Security Architect with deep crypto domain expertise to own security for the custody and on-chain layer of our regulated digital-asset platform end to end, spanning architecture, engineering, operations and regulatory assurance. Reporting into the central security function, you will define crypto-specific requirements and partner with dedicated InfraSec, AppSec, IAM and SOC teams on the platform capabilities they already own, rather than duplicating those functions. You will work closely with risk, compliance, product and engineering as we build out spot trading, custody, staking and on-chain services. This is a hands-on senior role for someone who understands that in digital-asset custody a single key-management failure is a firm-ending event, and who builds controls accordingly.

Responsibilities
  • Lead end-to-end security architecture for the full custody stack: HSM/MPC key management, transaction authorization, signing quorums, address whitelisting, hot/cold wallet segregation, key ceremonies, delegated cold custodians, and secure staking deposit/withdrawal paths.
  • Establish crypto-specific baseline standards, privileged-access controls, and secure SDLC requirements within our multi-account AWS environment, partnering with central InfraSec, AppSec, and IAM teams on delivery.
  • Define custody and blockchain detection use cases for the SOC, and directly manage incident response procedures for crypto-specific scenarios (key compromise, unauthorized transactions, on-chain incidents) alongside Corporate Security.
  • Conduct rigorous threat modeling and security reviews across internal ledger mechanics, balance idempotency, withdrawal sequencing, and smart contract integrations to guarantee transaction money-path integrity.
  • Direct security assessments and ongoing assurance for external custody providers, execution systems, blockchain analytics, Travel Rule tools, and treasury integrations using group vendor security processes.
  • Own control mapping against international regulatory standards (MiCA, DORA, FCA, MAS) and collaborate with Global Market Teams to maintain compliance during international expansion.
Responsibilities
  • 10+ years in information security, with a proven track record as a security architect or technical lead securing digital-asset custody, high-throughput crypto platforms, or regulated financial infrastructure.
  • Direct operational experience securing crypto custody, with deep domain expertise in wallet architecture, Multi-Party Computation (MPC), Hardware Security Modules (HSMs), key ceremonies, and signing-policy design.
  • Strong cloud security fundamentals (AWS preferred) in a regulated environment, with practical experience mapping security controls to licensing conditions (ISO 27001, SOC 2, NIST).
  • Demonstrated experience running threat modeling, risk assessments, and incident response, with the ability to translate technical cryptographic risk into clear business and regulatory impact for non-security teams and regulators.
  • Proven comfort operating in a matrixed security model, collaborating with dedicated IAM, AppSec, SOC, and infrastructure security teams rather than owning those central functions outright.
Nice-to-Haves
  • Hands-on experience with Kubernetes, containers, Infrastructure as Code (Terraform), API security, Python for automation, Web3 dependency supply-chain assurance, or industry certifications (CISSP, CISM, CCSP, CCSSA).
  • Professional fluency in spoken and written Mandarin to support regional market operations and cross-functional engineering collaboration.
Perks & Benefits
  • Competitive compensation package
  • Various team-building programs and company events
  • And many more!

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analysing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgement. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Crypto Security Architect – On-Chain & Digital Assets
Lead Crypto Security Architect – On-Chain & Digital Assets

BTSE • Brussel Hoofdstad

Hybrid
EUR 140,000 - 200,000
Competitive compensation package
Team-building programs
Company events
Head of Technology & Security – EU
Head of Technology & Security – EU

OSL • Brussel

On-site
EUR 180,000 - 240,000
Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP
Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP

Salt • Brussel Hoofdstad

Hybrid
EUR 90,000 - 140,000
Technology Growth Hacker
Technology Growth Hacker

Euroclear • Belgium

On-site
EUR 70,000 - 90,000
Competitive salary
Comprehensive benefits
Learning and development opportunities
Head of Organization Development
Head of Organization Development

Bybit • Brussel Hoofdstad

On-site
EUR 120,000 - 180,000
Study Growth Fund
Internal Events
Global Collaboration
+2
Enterprise Architect - Data & AI Capabilities Lead
Enterprise Architect - Data & AI Capabilities Lead

Euroclear • Brussel

Hybrid
EUR 120,000 - 180,000
Hybrid working model
International environment
Learning & development
Cryptography & Key Management Security Engineer
Cryptography & Key Management Security Engineer

Capco • Brussel Hoofdstad

On-site
EUR 90,000 - 130,000
IT Security Engineer
IT Security Engineer

Keytrade Bank • Brussel

On-site
EUR 70,000 - 110,000
Hybrid work 50/50 office/home
Agile environment
Green surroundings
+2
Cybersecurity Consultant
Cybersecurity Consultant

Ppt Consulting • Brussel

Hybrid
EUR 70,000 - 110,000
Company car or flexible mobility plan
Structured yearly salary increases and
Bonuses
+2
Senior Operations Security Engineer
Senior Operations Security Engineer

Dstny • Brussel Hoofdstad

Remote
EUR 70,000 - 95,000
AI-first tooling environment
Scale to millions of users
Autonomy and ownership