About the company
The World's Leading Cryptocurrency Platform
Job Summary
Responsibilities
šConduct, design, and implement testing of security controls covering identity management, key management, and infrastructure (network and cloud) configurations. šSupport client assurance activities, including responding to Requests for Proposals (RFPs), Requests for Information (RFIs), and Due Diligence Questionnaires (DDQs). šIdentify and analyze trends in client inquiries and provide feedback to internal teams to improve documentation and control readiness. šPerform security due diligence and ongoing monitoring for Web3/blockchain vendors, including assessing their control maturity, reviewing SOC reports and security documentation, and identifying residual risks. šFacilitate external audit activities, including coordination of walkthroughs, evidence collection, and response tracking. šIdentify and analyze gaps in current and new processes, then develop and track remediation recommendations to completion (e.g., onboarding flow). šDevelop and maintain understanding of applicable financial regulatory security requirements and ensure alignment of controls. šResearch and share information security best practices, emerging threats, and mitigation strategies with internal teams. šEvaluate and propose next-generation security tools, automation, and technologies to enhance overall security posture. šReview blockchain network or protocol upgrades for their potential security impact on the platform.
Requirements
šAt least 8 years of relevant experience in security assurance, audit, compliance, or cloud security engineering. šDemonstrated experience testing and validating security controls across IAM, key management, and network/cloud environments. šStrong understanding of Identity and Access Management (IAM) principles. šKnowledge of cryptographic key management, HSMs, and KMS systems. šSolid grasp of cloud and network security architecture and configuration. šProven experience supporting SOC 1, SOC 2, ISO 27001, PCI DSS, or similar external audits and assessments. šExposure to major cloud platforms (AWS, GCP, Azure) and infrastructure-as-code. šExperience in preparing client assurance materials, RFP/RFI/DDQ responses, and evidence documentation.
If youāre passionate about blockchain and decentralized technologies, explore more opportunities in web3 and cryptocurrency careers.





