Skip to content
NewFull-timeRemotePosted today

Principal Security Engineer

Mlabs · Remote

#dfns#remote

About the role

Location: Remote - US or EU Remote | Full-time Compensation: $160K - $240K Our client operates a core banking platform designed specifically for digital assets, enabling fintechs and systemically important financial institutions to build, operate, and scale onchain infrastructure. The platform secures over €100B in assets and powers critical operations—including key management, transaction processing, treasury, and compliance—for over 400 global institutions. Our client is seeking a Principal Security Engineer to lead product security across the entire ecosystem. In this role, security is built directly into the system's architecture rather than applied as a secondary control. The ideal candidate will take ownership of hardening key management, signing workflows, authentication systems, policy enforcement, and multi-chain integrations. Beyond core product security and vulnerability management, this position plays a pivotal role in shaping the long-term architectural vision of a platform trusted by tier-one financial institutions. As an organization committed to technical excellence, our client also encourages contribution to the broader security community through research, publications, and industry events. Key Responsibilities • Architectural Leadership: Lead product security architecture, ensuring security principles are embedded into core platform design and development cycles. • Core Infrastructure Security: Analyze and secure key management systems, transaction pipelines, and signing workflows across modern distributed networks. • Threat Modeling & Review: Perform system-level threat modeling for new product features, protocols, and multi-chain integrations. • Cryptographic & Auth Security: Design and evaluate security-sensitive components, including authentication protocols, authorization frameworks, and applied cryptographic workflows. • Defense-in-Depth: Define, implement, and maintain multi-layered security controls across the application, infrastructure, and protocol layers. • Supply Chain & Environment Security: Own and expand end-to-end software supply-chain security, spanning dependency scanning in CI pipelines to local developer environments. • Infrastructure as Code (IaC): Enforce security configurations into version-controlled repositories to prevent configuration drift and enhance auditability. • Risk Research & Mitigation: Investigate emerging security risks related to blockchain protocols, institutional custody models, and novel cryptographic techniques. • Compliance & Audits: Support ongoing SOC 2, ISO 27001, and ISO 22301 compliance frameworks alongside expanding control surfaces. • Technical Enablement & Incident Response: Provide day-to-day guidance to engineering teams to make secure patterns accessible, while supporting incident response and root-cause analysis when necessary. • External Representation: Participate in security architecture reviews with tier-one banking partners, external auditors, and enterprise clients. • Industry Thought Leadership: Contribute to technical research, whitepapers, and conference presentations to advance the digital asset security field. Requirements • Experience: 10+ years in security engineering, product security, or security architecture roles. • Domain Expertise: Demonstrated track record of securing financial infrastructure, institutional blockchain platforms, or both. • Cryptographic Systems: Deep understanding of cryptographic protocols, wallet architectures, and key management frameworks. Direct experience with Multi-Party Computation (MPC), threshold signatures, or HSM-backed solutions is strongly preferred. • Threat Modeling: Extensive experience performing comprehensive system-level threat models and architecture reviews. • Infrastructure & Networks: Solid foundational knowledge of distributed systems, networking protocols, and cloud computing platforms (primarily AWS). • Supply Chain & IaC: Hands-on experience implementing software supply-chain defenses and managing security configurations via code to prevent drift. • Compliance & Frameworks: Familiarity with maintaining live audit cycles for frameworks such as SOC 2, ISO 27001, ISO 22301, and the NIST Cybersecurity Framework. • Development Skills: Professional familiarity with modern backend languages such as Rust or TypeScript. • Communication: Exceptional ability to communicate complex security concepts effectively to both internal engineering teams and external enterprise stakeholders. Benefits • Competitive executive-level compensation package. • Flexible, remote-first work environment. • Comprehensive health, wellness, and benefits coverage tailored to regional standards. • Generous paid time off (PTO) and personal Leave policy. • Professional development budget for security research, certifications, and industry conferences. • Exposure to cutting-edge cryptographic engineering alongside leading global financial institutions.  Interview Process The selection process for this position consists of the following structured phases: • Initial Screening Call (30 mins): Introductory discussion with the Co-CEO to align on background, expectations, and role scope. • Cognitive & Skills Assessment (45 mins): A series of brief, timed assessments via TestGorilla evaluating: • Critical Thinking • Verbal Reasoning • Attention to Detail (Textual) • Numerical Reasoning • Problem Solving • (Note: Practice questions are provided prior to each timed 10-minute section). • Take-Home Technical Exercise: A practical assignment designed to assess technical problem-solving and architectural design capabilities. • Group Technical Interview (120 mins): A multi-part panel review covering: • Threat modeling exercise • Infrastructure security review • Cultural alignment assessment • Final Leadership Interview: A concluding conversation prior to the formal offer stage. Due to the high volume of applications we anticipate, we regret that we are unable to provide individual feedback to all …

Apply for this role

Apply right here on 9180 — we'll forward your application to Mlabs. No external redirects, no lost candidates.

1 · About you
Your work

2 · Your work

🔒 Never shown to anyone — used only in anonymous, aggregate Bangalore pay benchmarks.

One link is enough — your best work, or a résumé the team can open.

Your pitch

3 · Your pitch

Free · forwarded straight to the hiring team.

Originally listed on Arbeitnow. View the original posting ↗

More roles like this

All jobs →